So I came across this app which is supposedly from Guaranty Trust Bank, GTWorld
Looking closely the developer is the same person who developed the GTBank App though the email address used there is @gtbank.com whilst on the GTWorld app it’s @gmail.com
And from what I can see on the sign up screen, you are required to put in your ATM Card pin.
I’m not sure if it is a scam but I’m 100% sure it isn’t legit.
PINs should live in the Secure Element / Trusted Execution Environment (i.e chip) in the card and should be validated against a PIN that’s inputted through a secure PIN pad (e.g in an ATM machine). Interswitch started this rubbish of storing PINs on their server and prompting users to type PINs through an insecure keypad i.e. a phone or computer keyboard. I see it has become the new normal. What a joke.
i use this app today ooo…its 100% legit but i didn’t setup any card on it. i use the same details i use to login on the old mobile banking app to login
@gaphy, @Freshboi_Ekundayo - Quick clarification. I’m not saying the app is not an official GTBank app. In that respect, it can be considered legit and not a scam.
It’s its security protocol that’s “illegitimate” in the non standards-compliant sense.
Bro, me and u know the egg heads in the bank do not know a thing or two about Security compliance, they are after sign ups and not even security, you go to Financial meetings and hear of billions ripped off from banks via POS, App, ATM and Transfers and you wonder why NO BANK has thought it wise to invest in Serious Security Centre redesign and architecture from Network, Software, User and Consumer standpoint.