<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: El Peruano Loko</title>
    <description>The latest articles on DEV Community by El Peruano Loko (@elperuanoloko).</description>
    <link>https://dev.to/elperuanoloko</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4153255%2F248bbc39-6731-4edd-a923-73418c17e8f7.png</url>
      <title>DEV Community: El Peruano Loko</title>
      <link>https://dev.to/elperuanoloko</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/elperuanoloko"/>
    <language>en</language>
    <item>
      <title>We cracked the face-2FA engine behind 150+ banks — forged tokens pass validation</title>
      <dc:creator>El Peruano Loko</dc:creator>
      <pubDate>Thu, 01 Oct 2026 00:52:48 +0000</pubDate>
      <link>https://dev.to/elperuanoloko/we-cracked-the-face-2fa-engine-behind-150-banks-forged-tokens-pass-validation-32in</link>
      <guid>https://dev.to/elperuanoloko/we-cracked-the-face-2fa-engine-behind-150-banks-forged-tokens-pass-validation-32in</guid>
      <description>&lt;p&gt;One facial-biometrics vendor quietly sits behind the 2FA selfie wall of &lt;strong&gt;more than 150 banks in 30+ countries&lt;/strong&gt;. We reversed their public engine, and the results are uncomfortable: &lt;em&gt;every captured 2FA token is decryptable, and tokens we mint offline validate as legit.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The setup
&lt;/h2&gt;

&lt;p&gt;When a bank's online login asks you to take a selfie, it's usually not the bank doing the heavy lifting. A single vendor ships a small widget that runs entirely in the browser: it captures your face, produces an encrypted token, and hands it to the bank's backend.&lt;/p&gt;

&lt;p&gt;Because the widget is a &lt;strong&gt;publicly served wasm engine&lt;/strong&gt;, anyone can download it. We did.&lt;/p&gt;

&lt;h2&gt;
  
  
  What we found (teaser — full spec on request)
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;The token is a pair.&lt;/strong&gt; Every 2FA attempt posts two encrypted blobs — a selfie image and a face-template image. We broke the self-keying scheme: the key is derivable from data already sitting in the clear, seeded from a time value. Both blobs decrypt to the exact bytes the server saw (a JPEG selfie and a PNG template).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Forged blobs read as legit.&lt;/strong&gt; Because the key is derivable, we can mint fresh, structurally-valid token pairs that the server accepts. No camera, no face, no live user — just a well-formed encrypted blob.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Per-tenant isolation is dead.&lt;/strong&gt; The engine ships a license whitelist of 46-character keys embedded in the public wasm — including the vendor's own key and the keys of at least eight other corporate clients. Every tenant runs the same licensed engine.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The anti-fraud check has a master off-switch.&lt;/strong&gt; The current-generation "environment security" module is a case-sensitive keyword blocklist with a single bypass string shipped in the clear.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  The headline deployment
&lt;/h2&gt;

&lt;p&gt;One of the biggest deployments — &lt;strong&gt;Interbank (Peru)&lt;/strong&gt;, on a 2020-era build — has the entire 2FA barrier bypassable &lt;strong&gt;headlessly&lt;/strong&gt;: no browser, no camera, no face, roughly 1-in-100 per attempt. And every biometric token recorded since the integration went live is decryptable.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Upgrading is not a free pass.&lt;/strong&gt; The vendor's current 6.x line still embeds the license whitelist in a public wasm and still accepts a still (non-living) selfie at enrollment. A version bump alone doesn't close the door.&lt;/p&gt;

&lt;h2&gt;
  
  
  What we're selling
&lt;/h2&gt;

&lt;p&gt;The full specification, a headless engine that reproduces the flow against a live tenant, and per-bank recon. We're selling to the vendor, to its bank clients, or to a single operator who wants first refusal.&lt;/p&gt;

&lt;p&gt;Proof, scope, and a decryptable sample of &lt;em&gt;your&lt;/em&gt; bank's token are available on request.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Contact:&lt;/strong&gt; &lt;a href="mailto:elperuanoloko@proton.me"&gt;elperuanoloko@proton.me&lt;/a&gt;&lt;br&gt;
— El Peruano Loko, independent security research&lt;/p&gt;

</description>
      <category>security</category>
      <category>webdev</category>
      <category>encryption</category>
    </item>
  </channel>
</rss>
