Being able to login if you have the bank account number is still a pretty big flaw.
If you are a bank, your security threat model should assume that a hacker has access to somebody's account number and basic personal details.
Particularly for a high profile/value account, you can see how it might be possible to get soundclips of them saying the numbers 1 to 9 (see: https://www.youtube.com/watch?v=xWcldHxHFpo)
Being able to login if you have the bank account number is still a pretty big flaw.
If you are a bank, your security threat model should assume that a hacker has access to somebody's account number and basic personal details.
Particularly for a high profile/value account, you can see how it might be possible to get soundclips of them saying the numbers 1 to 9 (see: https://www.youtube.com/watch?v=xWcldHxHFpo)