Sim Swap Certification - 3 Legged authorization implementation #129
Replies: 4 comments
-
Please share your use cases and scenarios for SIM Swap. Then the community can advise further. |
Beta Was this translation helpful? Give feedback.
-
|
@psidana I guess this discussion should take place in Identity And Consent Management group. Can we transfer it ? |
Beta Was this translation helpful? Give feedback.
-
|
I don't have permission to transfer issues from one WG to another. CC @hdamker Not sure he can. @psidana But as you say, CAMARA (as per Identity & Consent WG) mandates that in cases where personal user data is processed by the API and users can exercise their rights through mechanisms such as opt-in and/or opt-out, the use of 3-legged access tokens becomes mandatory. This measure ensures that the API remains in strict compliance with user privacy preferences and regulatory obligations, and upholds the principles of transparency and user-centric data control. So SIM Swap requires 3-legged access.
This is more of a business discussion than a technical discussion, IMHO. |
Beta Was this translation helpful? Give feedback.
-
|
@jpengar yes, I can ... and done. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
As per CAMARA guidelines for Sim Swap API certification , it is mandatory to implement 3 legged authorization flow - front end or CIBA ., I have below concern in implementing it which is
In the front end flow I have to force my clients to update their mobile app customer journey to which they may or may not agree . They may not be interested to authenticate the end user in MNO system.
In the CIBA flow, it will not add value since in the SIM Swap fraud, an unauthorized user has already compromised the end-user’s SIM to get the OTP SMS, sending another OTP will not add any value.
If you are align with my understanding above then please suggest why is it mandatory to implement it for certification .
Beta Was this translation helpful? Give feedback.
All reactions