@ptech3net What I do is that I include a flag in the endpoint logic that goes to the otp service to tell it it is a partial validation , and the other backend request for what the actual flow will be will see the flag to tell the otp service to do a full validation
@johnoojetunde @durutheguru Congratulations man! I think you developed the reserved account system that I integrated to in 2019? I remember seeing your name on the Skype chat back then if I’m not wrong
@johnoojetunde @durutheguru Congratulations man! I think you developed the reserved account system that I integrated to in 2019? I remember seeing your name on the Skype chat back then if I’m not wrong
This is why you don't roll your own security, even for an MVP.
Security researcher investigates app that only has magic sign-in, and immediately finds that instead of checking the OTP server-side, they send it as a response to the client request.
Allows to take over ANY account.
We are hiring 🔊
We’re looking for a Quality Assurance Engineer and Fixed Income Trader to join our team in Lagos, Nigeria. If you’re passionate about financial markets, trading systems, and delivering excellence in fintech, this is your opportunity to make an impact.
Be part of an innovative team driving performance, precision, and continuous improvement in financial technology.
Apply Now via:
• https://t.co/x0To46uQoN
• https://t.co/foLSBkJkaC
#Payaza #FixedIncome #TradingEngineer #QAEngineer #Fintech #JobOpening #Lagos #Nigeria #Hiring #CareerOpportunity