Closed commjoen closed 8 years ago
Good point, this is common in mobile banking apps. I would make it a L2 requirement?
step-up, do you mean like a Two factor auth system? For banking applications it is common to use unconnected card readers for an enhanced security layer. Usually basic operations are permitted and monetary transactions upto a certain limit. Ano other operation e.g. a new recipient would require a OTP from an UCR.
Both can be possible: you can either re-ask a pin/fingerprint or you can use another factor outside of the app. I will create a PR...
Closing issue as pull request is accepted.
Hi, one thing that could work for L4 applications, is that for certain risky activities, the user should do a step-up authentication (using a mobile pin or a fingerprint, or something else). Should this be part of the MASVS and if so, where should we put it?