Skip to content

Repeated pin failure locks account #13

@BillHodghead

Description

@BillHodghead

From @bhcrosslake on January 11, 2017 22:26

As a phone user my account pin is protected against someone trying to guess it.

If someone is trying to guess another person's account pin they could try many numbers. We should block attempts after enough retries

Acceptance Criteria:

  • After 3 failed retries, an account is put on hold, where money can be received but not sent.
  • A DFSP agent to release a hold through the operational UI.
  • A DFSP agent can see a list of holds
  • Releasing the hold requires some validation of the user identity.

Copied from original issue: LevelOneProject/Docs#332

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions