[plug] Bank "Security" Example

Onno Benschop onno at itmaze.com.au
Thu Jul 31 14:29:44 UTC 2014

Bank uses security tokens and secret questions for online banking and phone
authentication. The battery for the token is running low, so a replacement
is ordered. 10 business days to ship.

Customer is advised that as part of the login sequence they'll now be asked
for their secret account questions instead of the token.

Customer enters their credentials and receives a prompt requesting that
they select new questions and answers.

Note that at this time they've only provided credentials, that is, ID and
Password. They're not yet logged in.

Which Bank?
