@rolandlo @ev @OhMyGod ich kenn die Dinger: Sind #PhotoTAN-Authenticator und im #B2B-Bereich (#EBICS) vorgeschrieben, weil #airgapped…
Nutzt jemand von unseren Lesern das Bank Feature von #datev #unternehmen #online? Ich hätte da ein paar #EBICS Spezialfragen…
Edit: DATEV hat die Hotline dafür abgeschaltet, Bandansage: Buchen sie online einen Termin (kostenpflichtig). Für PreSales finde ich das etwas befremdlich
I wrote a functional #Burpsuite Machine-In-The-Middle #EBICS-Banking extension (actually two extensions so decode/encode can be loaded at different places in the extension list).
Very ugly code, because the complexity of EBICS is a nightmare.
EBICS fun fact: They use a legacy padding algorithm called PKCS1_v1_5. Hello Bleichenbacher's attack. I mean easy peasy lemon squeazy, this is just how BILLION OF EUROS AND SWISS FRANCS and maybe your salary is paid
@chrisheuer @escapadesrpg @TomLarrow also there are sufficient methods like #HBCI for individuals and #EBICS for businesses to facilitate payments securely.
It's just that banks offer them under horrible terms like making customers responsible for every fuckup, whereas if their #WindowsXP-based ATMs get hacked, they'll have to reimburse me for any damages I incured.