Although funds are already being recovered, it has highlighted the opacity of Pix security, which has flown somewhat under the radar due to the closed nature of the system.
Although funds are already being recovered, it has highlighted the opacity of Pix security, which has flown somewhat under the radar due to the closed nature of the system.
> Not much opacity here.
I think a black box implemented by a third party that can steal your funds is the definition of opacity.
> They shoud stop relying on poorly paid outside contractors.
A great deal of financial software is written by poorly paid contractors, but it's rare that one set of credentials can introduce systematic risk to a financial system.
Besides paying decent wages, they should get rid of single points of failure, being them silicon or meat based.
That is not the case, as it appears the attackers were able to use the Pix protocol to transfer funds from accounts not controlled by the attackers.
> There is nothing it can do with incoming valid but fraudulent transactions.
Well, we don't yet know the actual mechanism, but that is the opacity we're talking about.
It's certainly not impossible to ameliorate insider risk and it's definitely not a given that a single set of compromised developer credentials should be able to enact widespread fraudulent transactions across many banks.