View Issue Details

IDProjectCategoryView StatusLast Update
0011483Talermerchant backoffice SPApublic2026-06-07 23:07
Reportervecirex Assigned ToChristian Grothoff  
PrioritynormalSeveritymajorReproducibilityalways
Status resolvedResolutionfixed 
Target Version1.6Fixed in Version1.6 
Summary0011483: Adding another IBAN requires MFA, but can be circumvented
DescriptionAdding ticket via and confirmed by fd during yesterday's QC session:

Being logged in, adding an additional IBAN acc. requires one additional factor (sms or email, given taler-merchant has tan methods activated by config; like for mytops).

This makes sense because an actor (like employee or just any attacker with access to the the open screen) could try to redirect money to his very own account, by just adding another IBAN. By a tan method being required, most attackers would be prevented from doing so.

However, it's possible to just delete the first IBAN added and replace it by the "second" one, or: the security model is broken, because in this case no tan method is required.
Additional InformationWith Instant SEPA coming also to CH, downtime because of KYC Auth pending to the new attacker's IBAN would be neglectable.
TagsNo tags attached.

Relationships

related to 0011484 confirmedChristian Grothoff Notify merchants of relevant changes to the instance (like IBAN no.) 

Activities

Christian Grothoff

2026-06-07 23:07

manager   ~0028802

1030eb67..351e03c2 adds MFA for account deletion.

Issue History

Date Modified Username Field Change
2026-06-06 03:55 vecirex New Issue
2026-06-06 03:58 vecirex Description Updated
2026-06-06 03:58 vecirex Additional Information Updated
2026-06-06 03:59 vecirex Summary Adding additional IBAN requires MFA, but can be circumvented => Adding another IBAN requires MFA, but can be circumvented
2026-06-06 04:08 vecirex Relationship added related to 0011484
2026-06-06 18:25 Christian Grothoff Assigned To => Christian Grothoff
2026-06-06 18:25 Christian Grothoff Status new => confirmed
2026-06-06 18:25 Christian Grothoff Target Version => 1.7
2026-06-07 00:07 Christian Grothoff Status confirmed => assigned
2026-06-07 23:07 Christian Grothoff Status assigned => resolved
2026-06-07 23:07 Christian Grothoff Resolution open => fixed
2026-06-07 23:07 Christian Grothoff Fixed in Version => 1.6
2026-06-07 23:07 Christian Grothoff Note Added: 0028802
2026-06-07 23:07 Christian Grothoff Target Version 1.7 => 1.6