The transfer you intended.
The details you approve.

  1. 1 Request
  2. 2 Service review
  3. 3 Device decision
  4. 4 Outcome

01

Customer’s browser

02

Bank / FIDO2 RP

This is the bank’s backend service, which normally has no user-facing display. Here, we show the details it receives from the browser and sends directly to the user’s secured phone for review.

03

Customer’s trusted device

Follow a wire from the customer’s browser to the bank and the trusted device. See a matching request, then see an attacker change the amount and account.

WHY IT MATTERS

The trusted display makes the difference.

The bank receives what the browser sends. If malware changes it, the trusted device shows those changed terms. The customer must review them: approving the wrong details still authorizes the wrong request.

Explore the insurance call demo About Authentication & Intent Services