Push Notification Enhancements
Enterprise-grade secure push notifications to address:
- Risk #14: OTP delivered over insecure push channels
- Risk #22: Push approval without contextual info
Features
- No OTP in Payload: Only notification IDs/challenge numbers
- End-to-End Encryption: Encrypted push payloads
- Rich Context: Device, location, IP, timestamp, app info
- Number Matching: Display number in app, user enters in push
- Activity Summary: Recent account activity
- TLS Client Auth: Certificate-based push client auth
- Payload Encryption: AES-256-GCM encryption
- Secure Delivery: No sensitive data in transit