- Новости о безопасности
- Cybercrime & Digital Threats
- The Risks of Open Banking: Are Banks and their Customers Ready for PSD2?
Download Ready or Not for PSD2: The Risks of Open Banking
September 14 marked the implementation of the European Union’s (EU) Revised Payment Service Directive (PSD2) – otherwise known as Open Banking. PSD2 aims to give the public greater convenience and more control over their banking data. It also gives third-party financial technology (FinTech) companies handling established banks’ additional services the same access to customers’ banking information for data analysis and financial management recommendations, among other provisional services.
Figure 1. With PSD2, new FinTech companies will launch new apps to aggregate banking data from multiple accounts.
PSD2 replaces the 2007 mandate, the Payment Services Directive (PSD) approved in 2015, to highlight specific protection procedures, rights, and obligations of providers and users in an effort to motivate innovation and competition in the financial industry. While it is designed and primarily applicable to EU member states, the effects and implications of the directive go beyond the region. The directive is being hailed as a game changer in the financial industry as it removes the control of customers’ information from established banks, and gives users the right to share their banking data with financial service providers for finance management and other purposes.
To comply with the laws’ security stipulations, banks opened their application programming interfaces (APIs) to FinTech companies after ensuring that the prerequisite security infrastructure is established, and after getting the bank customers’ consent for data access. But a number of concerns regarding readiness have been raised.
This paper explores the current state and potential security risks of banking apps in the advent of PSD2, highlighting the technical infrastructure and the implications of the regulation. We highlight the following:
Sector | Region | Sensitive Information In URL |
A central bank | EU | Username, password |
A central bank | EU | Username, password |
A central bank | Asia | Username, password |
Bank | BE | OAuth client secret |
Bank | CA | Password |
Bank | CN | Client ID, OAuth client secret |
Bank | CN | Client ID, OAuth client secret |
Bank | CR | Username, password |
Bank | CR | Username, password |
Bank | CW | Client ID, OAuth client secret, username, password |
Table 1. 10 of the 52 financial institutions Trend Micro researchers found exposing confidential data in the URL path
For more details on the research, read “Ready or Not for PSD2: The Risks of Open Banking.” The research paper also includes security recommendations for financial institutions, FinTech companies, and their customers.
Like it? Add this infographic to your site:
1. Click on the box below. 2. Press Ctrl+A to select all. 3. Press Ctrl+C to copy. 4. Paste the code into your page (Ctrl+V).
Image will appear the same size as you see above.