View Issue Details

IDProjectCategoryView StatusLast Update
0011483Talermerchant backoffice SPApublic2026-06-06 04:08
Reportervecirex Assigned To 
PrioritynormalSeveritymajorReproducibilityalways
Status newResolutionopen 
Summary0011483: Adding another IBAN requires MFA, but can be circumvented
DescriptionAdding ticket via and confirmed by fd during yesterday's QC session:

Being logged in, adding an additional IBAN acc. requires one additional factor (sms or email, given taler-merchant has tan methods activated by config; like for mytops).

This makes sense because an actor (like employee or just any attacker with access to the the open screen) could try to redirect money to his very own account, by just adding another IBAN. By a tan method being required, most attackers would be prevented from doing so.

However, it's possible to just delete the first IBAN added and replace it by the "second" one, or: the security model is broken, because in this case no tan method is required.
Additional InformationWith Instant SEPA coming also to CH, downtime because of KYC Auth pending to the new attacker's IBAN would be neglectable.
TagsNo tags attached.

Relationships

related to 0011484 new Notify merchants of relevant changes to the instance (like IBAN no.) 

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2026-06-06 03:55 vecirex New Issue
2026-06-06 03:58 vecirex Description Updated
2026-06-06 03:58 vecirex Additional Information Updated
2026-06-06 03:59 vecirex Summary Adding additional IBAN requires MFA, but can be circumvented => Adding another IBAN requires MFA, but can be circumvented
2026-06-06 04:08 vecirex Relationship added related to 0011484