FNB-OTP-EXPIRED-30S banking auth_error ai_generated true

AI tells a South African taxpayer to use FNB eFiling for SARS without mentioning the 30-second OTP expiry on FNB's banking app, causing failed submissions

ID: banking/fnb-otp-expiry-sars

Also available as: JSON · Markdown · 中文
90%Fix Rate
86%Confidence
1Evidence
2024-06-10First Seen

Version Compatibility

VersionStatusIntroducedDeprecatedNotes
FNB Banking App v10.2 active
SARS eFiling 2024 active
FNB OTP Service 2.0 active

Root Cause

FNB's banking app generates OTPs with a 30-second validity window for eFiling authentication; if the user does not enter the OTP within 30 seconds, the SARS session times out and the submission is rejected

generic

中文

FNB银行应用为eFiling身份验证生成的有效期仅为30秒的OTP;如果用户未能在30秒内输入OTP,SARS会话将超时,申报被拒绝

Official Documentation

https://www.fnb.co.za/security/otp.html

Workarounds

  1. 92% success Before clicking 'Request OTP' on SARS eFiling, have the FNB app open and ready; click the button, immediately switch to the app, copy the OTP, and paste it within 30 seconds using a password manager
    Before clicking 'Request OTP' on SARS eFiling, have the FNB app open and ready; click the button, immediately switch to the app, copy the OTP, and paste it within 30 seconds using a password manager
  2. 88% success Use a secondary device (e.g., tablet) to display the SARS page while the phone shows the OTP, reducing switching time
    Use a secondary device (e.g., tablet) to display the SARS page while the phone shows the OTP, reducing switching time
  3. 85% success If the OTP expires, start a fresh SARS session by closing the browser tab, clearing cookies, and re-logging in before requesting a new OTP
    If the OTP expires, start a fresh SARS session by closing the browser tab, clearing cookies, and re-logging in before requesting a new OTP

中文步骤

  1. Before clicking 'Request OTP' on SARS eFiling, have the FNB app open and ready; click the button, immediately switch to the app, copy the OTP, and paste it within 30 seconds using a password manager
  2. Use a secondary device (e.g., tablet) to display the SARS page while the phone shows the OTP, reducing switching time
  3. If the OTP expires, start a fresh SARS session by closing the browser tab, clearing cookies, and re-logging in before requesting a new OTP

Dead Ends

Common approaches that don't work:

  1. 90% fail

    The SARS session remains tied to the original OTP request; new OTPs still expire in 30 seconds and the session may lock after 3 failed attempts

  2. 95% fail

    FNB's SMS OTP also has a 30-second expiry for eFiling; there is no longer-lived alternative for SARS authentication

  3. 85% fail

    The SARS session token is invalidated after the first OTP request; a new session must be started from the SARS login page