Live data from Hacker News

Your Mother’s Maiden Name Is Not a Secret

nytimes.com

151–160 of 274 posts

Re: Your Mother’s Maiden Name Is Not a Secret

#151

Earlier quoted context omitted.

- We don't use 2FA authentication, I guess because there are more cost effective ways of verifying our identity (probably not going to last much longer with all the breaches) - ACH in the USA is free and fast (one business day)... and that's the main way of receiving salary, paying bills, etc. Is Europe really any better in this regard? - No one uses paper checks here either...

> ACH in the USA is free and fast (one business day) One business day is slow. Not as ridiculously slow as the three business day arbitrary bullshit, but still slow. Why aren't the transfers instant? There's no reason for them not to be. > Is Europe really any better in this regard? Oh god yes. Europe has had Giro for a long time. https://en.wikipedia.org/wiki/Giro Every bill comes with a receiving account number, an…

Oh, oh, oh! I forgot another awesome anecdote. When I opened a bank account with First Hawaiian Bank, I got a folder that tried to sell me on a magical mysterious thing called a "MasterCard". You can pay bills with it WITHOUT having to write a check!!! It's NOT a credit card, so you don't need to pass a credit check, BUT IT'S ACCEPTED everywhere anyway! MAGIC!

It's like it's the fucking 70's and the rest of the world doesn't exist when it comes to banking in this country.

Re: Your Mother’s Maiden Name Is Not a Secret

#152

Earlier quoted context omitted.

When you say fraud, do you mean theft or identity fraud? 2FA is extraordinarily relevant when it comes to theft with regard to online banking. The purpose of 2FA is mostly to prevent automated attacks or remote account entry via password resets by email or something similar. I'm not sure if you're aware, but Europe has proper 2FA in the form of a dongle type device, and not this SMS BS many companies in the US use ou…

>2FA is extraordinarily relevant when it comes to theft with regard to online banking If theft through online banking even exists, it's at such a low volume as to be irrelevant. Most online banking interfaces are a read-only view of recent transactions. Some provide the ability to transfer funds between your own linked accounts at the same bank. Fewer still provide bill pay for a specific set of partner institutions,…

uhm. no?! I've paid all my bills and transferred money between friends/family using online banking for the last 20 years. Sweden had full online banking since at least 1997.

Re: Your Mother’s Maiden Name Is Not a Secret

#153
post #74

Earlier quoted context omitted.

CommBank and NAB spear-headed instant transactions. CommBank dropped an absolute mint on it, with a goal of sub-second transactions, with decent fraud protection. After a bunch of talks between the big banks, and VISA and MasterCard, and a little bit to do with the ombudsmen from various government branches, it was decided to share out that architecture, including fraud protection. The fraud protection is actually re…

None of the banks really wanted instant transactions, it's expensive, the RBA essentially forced them to.

Big win for consumers and businesses then.

Re: Your Mother’s Maiden Name Is Not a Secret

#154
post #51
post #4

Does anyone know the cause of the large and long standing difference in banking in US vs Europe? In europe: -for 15 or so years already, web banking has been with 2nd factor authentication (since its inception I assume). In previous decades we would get devices where you need to type numbers from its lcd screen into the webpage login. Today mobile auth apps are taking over. -I have never seen a bank have security que…

Paper cheques do exist in Germany.

They are used in France a lot. I bought my car with one, and my family doctor only accepts cash or checks.

Re: Your Mother’s Maiden Name Is Not a Secret

#156
post #73
post #49

Earlier quoted context omitted.

I also generate them with a password manager. FWIW, I always start with “it’s a long gibberish string” and no one has ever been satisfied with that. I’ve always had to recite it. Anecdotal I know.

I just wrote a mini rust script ( https://github.com/rtaycher/make_password ) to spit out 5 random dictionary words for secure passwords I need to share. Everything else gets auto generated by keepass, i should probably just figure out how to write a keepass plugin

> I should probably just figure out how to write a keepass plugin

KeepassXC already has this feature [1][2]. It can also store and generate OTP codes and works with YubiKeys (similar to Bitwarden Premium).

There's also a popular Python script called xkcdpass [3] which does the same from the command-line.

[1] https://keepassxc.org/images/screenshots/windows/screen_006....

[2] https://keepassxc.org/

[3] https://github.com/redacted/XKCD-password-generator

Re: Your Mother’s Maiden Name Is Not a Secret

#157
post #4

Does anyone know the cause of the large and long standing difference in banking in US vs Europe? In europe: -for 15 or so years already, web banking has been with 2nd factor authentication (since its inception I assume). In previous decades we would get devices where you need to type numbers from its lcd screen into the webpage login. Today mobile auth apps are taking over. -I have never seen a bank have security que…

I'm pretty sure all UK banks use multi factor now (mostly card readers and mobile apps), but they certainly weren't like that from their inception. I didn't encounter multi factor for at least five years after my first web-based account. They were all terrible combinations of passwords, secret questions and entering three characters from another password. I remember being fascinated by the multi factor token that my Swedish friends had in th the early 2000s. The last UK account that I had without any form of multi factor auth was probably about five years ago.

Bank transfers have always been free. Previously these were called BACS, and took three days. Now they're "faster payments" and are effectively instant. Bills are paid by Direct Debit, which is a pull system, which sounds scary but generally works well.

Re: Your Mother’s Maiden Name Is Not a Secret

#158
post #4

Does anyone know the cause of the large and long standing difference in banking in US vs Europe? In europe: -for 15 or so years already, web banking has been with 2nd factor authentication (since its inception I assume). In previous decades we would get devices where you need to type numbers from its lcd screen into the webpage login. Today mobile auth apps are taking over. -I have never seen a bank have security que…

- We don't use 2FA authentication, I guess because there are more cost effective ways of verifying our identity (probably not going to last much longer with all the breaches) - ACH in the USA is free and fast (one business day)... and that's the main way of receiving salary, paying bills, etc. Is Europe really any better in this regard? - No one uses paper checks here either...

> No one uses paper checks here either...

Source on that one? I've found that people outside of the tech bubble use a paper check at the very least once a year and most likely once a month. I have seen plenty of apartments, renters, even a mortgage company just a few years ago that required payment still in paper checks in the USA.

I'm going to assume your suggestion is anecdotal. It is certainly in decline but it's still widely used.

Check out this article https://www.bloomberg.com/news/articles/2017-07-26/why-can-t...

Re: Your Mother’s Maiden Name Is Not a Secret

#159

Earlier quoted context omitted.

Oh european banks also like to keep the money for a day. Other than that day of interest it's free though :) no 25 dollar wiring fee as seen in US

In Sweden we can transfer money instantly between banks. You essentially register a service tied to your phone number, and people can use that phone number to instantly transfer money to persons or companies without any fees. The service is called Swish [0]. The only requirement is that the receiver has registered the service to his/hers phone number, and that you can authenticate yourself using mobile BankID [1]. [0…

This sounds like the same as Vipps in Norway. Anything up to NOK5000 is free. And it is instant.

It has become a huge hit the last year. As for why I guess it's almost as fast as cash and you can add a little note so you can prove (rarely necessary but sometimes useful) that you paid.

Now a number of companies are also embracing it and I've started to receive invoices on Vipps. If it could be the thing that kills "Avtalegiro") I'd say that would be great.

Re: Your Mother’s Maiden Name Is Not a Secret

#160
post #3

Every time I'm confronted with these types of questions I just roll my eyes and add a 'Mothers maiden name' text entry to my password manager with a 16 digit random string.

OT: Just wondering why so many people are using password managers. When you use a password manager you have one single point of attack and failure. I wouldn't like to give all my credentials to one single entity.

Unfortunately I haven't found a reasonable alternative.

I have to use HUNDREDS of passwords every few weeks. HUNDREDS! Some for work, some for personal. Occasionally a service gets broken into so I can't have all of them be the same password and I can't have a system where I add, say "FB" to the end of the password to denote a service as that makes it pretty vulnerable.

So I am forced to use a password manager. I hate it and I'm terrified it'll get broken into one day. But what alternative do I have? I enable 2 auth on everything that I can but those are a very, very small handful compared to all of the usernames and passwords I have to use.

How do you not use a password manager is my question.

Post reply on HN