News Focus
News Focus
icon url

WBCTrader

11/01/17 11:39 AM

#189150 RE: Big Papa bear #189145

No, you would need to do one of either process on a different DEVICE. computer and smartphone for example.


(OOB) refers to authentication processes where authentication methods are conveyed through different networks or channels.

Where authentication factors are conveyed through a single device/channel—for example, entering
credentials via a device that also receives, stores, or generates a software token—a malicious user who has established control of the device has the ability to capture both authentication factors.Transmission of a one-time password (OTP) to a smartphone has traditionally been considered an effective out-of-band method. However, if the same phone is then used to submit the OTP—for example, via a web browser—the effectiveness of the OTP as a secondary factor is effectively nullified.

PCI updated their guidance February 2017

Bolded the important parts.