Having a blinding day !
Login to portal with 2FA. (email, password, OTP to mobile)
Open "Live Chat"
FIll in full name, and DoB.
First question in Live Chat :
" Hi please tell me your full name "
#tesco #CallCentre #fail #killmenow
"We are currently experiencing a larger than expected call volume. Your call is important to us and we will be with you shortly."
My #bank are always "experiencing a larger than expected call volume" it's almost as if they haven't employed enough people in their #CallCentre.
Randomly remembered when I worked at a #CallCentre, and there was a LCD text marquee display that reset and showed the IP address so I went in and played with it.
Then someone else went in, set the admin password and put up a snarky message. But the auth was overly simple with no XSRF protection, so I grabbed the temporary HTML cache of the admin page that I still had and used that to post to the display, and it worked. Wish I could have seen their face 😁