What really surprises me is how how often I see this mistake in web development. "No, Bob, you should not increase the user's bank account based on that number passed in from the frontend React app."
What really surprises me is how how often I see this mistake in web development. "No, Bob, you should not increase the user's bank account based on that number passed in from the frontend React app."
It was a convoluted example for examples sake, but I'm pretty much referring to them missing this important check here.
- Generate a transaction number and associate that number with the respective transaction details
- Send this number to the customer's mobile phone with all those details, or other configured device
- the transfer is only authorised if the customer has entered the transaction number
That way, the customer is very likely to have verified the details of the transfer.
This is the standard way online banking has been operating in, I believe, much of Europe since practically forever (although it used to be physical lists before smartphones were popular).