The transfer you intended.
The details you approve.
- 1 Request
- 2 Service review
- 3 Device decision
- 4 Outcome
01
Customer’s browser
02
Bank / FIDO2 RP
This is the bank’s backend service, which normally has no user-facing display. Here, we show the details it receives from the browser and sends directly to the user’s secured phone for review.
03
Customer’s trusted device
Follow a wire from the customer’s browser to the bank and the trusted device. See a matching request, then see an attacker change the amount and account.
- Based on the Chrome Roads bank and Android approval demos. Registration and sign-in are already complete.
- Interactive illustration: no real device, biometric check, payment or phone call is connected. Sample organizations and account details are fictional.
- Mobile app shown. Also available on the Chrome Roads Card’s trusted display.
WHY IT MATTERS
The trusted display makes the difference.
The bank receives what the browser sends. If malware changes it, the trusted device shows those changed terms. The customer must review them: approving the wrong details still authorizes the wrong request.
Explore the insurance call demo About Authentication & Intent Services