Live data from Hacker News

Your Mother’s Maiden Name Is Not a Secret

nytimes.com

171–180 of 274 posts

Re: Your Mother’s Maiden Name Is Not a Secret

#171

Earlier quoted context omitted.

I'm using ING DiBa in Germany and they lack a secure 2fa method. There are only two options available: - SMS-TAN, which is vulnerable to SS7 hijacking and name spoofing. - Index-TAN, aka the enumerated paper slip, which is only "pseudo two-factor": If you computer is pwned, it can ask you for the index matching the attacker's desired transaction.

ING DiBa offers banking apps for both iOS and Android, which can also serve as 2FA for online banking via the browser. The main banking app itself isn't all that good but the 2FA feature works fine.

Can't use those with HBCI. Also, I really wouldn't want my Android phone to serve as a single factor authentication method.

Re: Your Mother’s Maiden Name Is Not a Secret

#172
post #43

Earlier quoted context omitted.

...or whose mothers never married at all... Or people who don't even have mothers at all. The assumption is also that your mother's maiden name is different from your own name. Which is a very questionable assumption. We certainly show our cultural biases when coming up with these questions.

> Or people who don't even have mothers at all. That intrigues me. I can imagine not having a living mother, or even a mother who died before/during/after childbirth. But I can't imagine how it is possible for a child to have no mother at all. Is there a situation that you demonstrate ?

Adopted by two fathers.

Re: Your Mother’s Maiden Name Is Not a Secret

#173
post #4

Does anyone know the cause of the large and long standing difference in banking in US vs Europe? In europe: -for 15 or so years already, web banking has been with 2nd factor authentication (since its inception I assume). In previous decades we would get devices where you need to type numbers from its lcd screen into the webpage login. Today mobile auth apps are taking over. -I have never seen a bank have security que…

Mostly correct:

>>...No backup questions at all. I guess you go to the bank's office if you forget it?

True, then use personalId (or passport in case the account is in a different country), change the wee-calculator thing/reset of the phoneId app also requires visit to a bank office. Some banks support national identity system (Estonia, Latvia for instance).

>>"wiring" money between european bank accounts is free

this is not necessary true, and it's not 'european' but eurozone (which is different). The fee is domestic within the EU zone and depends on the bank agreement, e.g. it can 0.5e or even free

Re: Your Mother’s Maiden Name Is Not a Secret

#174

Earlier quoted context omitted.

When you say fraud, do you mean theft or identity fraud? 2FA is extraordinarily relevant when it comes to theft with regard to online banking. The purpose of 2FA is mostly to prevent automated attacks or remote account entry via password resets by email or something similar. I'm not sure if you're aware, but Europe has proper 2FA in the form of a dongle type device, and not this SMS BS many companies in the US use ou…

>2FA is extraordinarily relevant when it comes to theft with regard to online banking If theft through online banking even exists, it's at such a low volume as to be irrelevant. Most online banking interfaces are a read-only view of recent transactions. Some provide the ability to transfer funds between your own linked accounts at the same bank. Fewer still provide bill pay for a specific set of partner institutions,…

Where do you live that online banking is read only? I'm from Romania, so a developing country, and we've had full online banking (transfer money abroad, schedule monthly payments, make savings accounts, etc.) since at least 2007 for all the major banks.

If someone would hack my online banking account they could do quite a few nasty things...

Re: Your Mother’s Maiden Name Is Not a Secret

#175

Earlier quoted context omitted.

True, South Korea is also something special... everyone was required to have internet explorer with activeX for a very long time there to do banking and online shopping

The alternative to that would have been no SSL at all. The US required that all exported crypto would be limited, so South Korea instead built their own crypto. And browsers couldn't implement that themselves (also due to export regulations), so South Korea had to implement it as plugin for the then most-used browsers, which was mostly IE.

The US doesn't limit exported crypto anymore since 2000, and South Korea was still using the ActiveX-based solution as late as last year.

Re: Your Mother’s Maiden Name Is Not a Secret

#176
post #174

Earlier quoted context omitted.

>2FA is extraordinarily relevant when it comes to theft with regard to online banking If theft through online banking even exists, it's at such a low volume as to be irrelevant. Most online banking interfaces are a read-only view of recent transactions. Some provide the ability to transfer funds between your own linked accounts at the same bank. Fewer still provide bill pay for a specific set of partner institutions,…

Where do you live that online banking is read only? I'm from Romania, so a developing country, and we've had full online banking (transfer money abroad, schedule monthly payments, make savings accounts, etc.) since at least 2007 for all the major banks. If someone would hack my online banking account they could do quite a few nasty things...

The context of this thread is puzzlement that the US doesn't have widespread 2FA for online banking, and I'm telling you why.

Re: Your Mother’s Maiden Name Is Not a Secret

#177

Earlier quoted context omitted.

The alternative to that would have been no SSL at all. The US required that all exported crypto would be limited, so South Korea instead built their own crypto. And browsers couldn't implement that themselves (also due to export regulations), so South Korea had to implement it as plugin for the then most-used browsers, which was mostly IE.

The US doesn't limit exported crypto anymore since 2000, and South Korea was still using the ActiveX-based solution as late as last year.

Actually, the US still partially restrict it (I as a German had to file dozens of forms with the US DoD due to that already), but you are correct, TLS up to 1.3 is entirely public worldwide.

But obviously, by 2000, many sites were already using the South Korean crypto, and deprecating it would be just as complicated as deprecating TLS 1.0 or SHA1 TLS Certificates in the US. The browser vendors consider that impossible — the South Korean situation is just as problematic.

Re: Your Mother’s Maiden Name Is Not a Secret

#178
post #147

Earlier quoted context omitted.

>2FA is extraordinarily relevant when it comes to theft with regard to online banking If theft through online banking even exists, it's at such a low volume as to be irrelevant. Most online banking interfaces are a read-only view of recent transactions. Some provide the ability to transfer funds between your own linked accounts at the same bank. Fewer still provide bill pay for a specific set of partner institutions,…

I am not aware of a country in Europe where the online banking interface is not able to transfer money, both domestically and internationally vi e.g. SEPA and other methods - it’s called “online banking”... Phishing and other things were a large attack vector until 2FA mostly did away with it.

The capabilities of European online banking are irrelevant to the security needs of American online banking. Yes, you need 2FA, because your online banking is actually for making transactions.

In the US, it isn't. On the off chance that the capability is there, it's seldom used. You make transactions by telling the other party your account number.

Re: Your Mother’s Maiden Name Is Not a Secret

#179

Earlier quoted context omitted.

>2FA is extraordinarily relevant when it comes to theft with regard to online banking If theft through online banking even exists, it's at such a low volume as to be irrelevant. Most online banking interfaces are a read-only view of recent transactions. Some provide the ability to transfer funds between your own linked accounts at the same bank. Fewer still provide bill pay for a specific set of partner institutions,…

> and a tiny proportion of the most technologically sophisticated banks provide the ability to transfer money to any arbitrary person. In the country where I live all internet banks supports this. And all of course use 2FA. Most if not all banks here let's me do any kind or transactions. Not just viewing my data but transferring money, buying stock, setting up new bank accounts, pension management and everything else…

Well yes, the country where you live needs 2FA on online banking because it actually has transaction capabilities. The US essentially doesn't, so the lack of 2FA isn't a significant problem.

Re: Your Mother’s Maiden Name Is Not a Secret

#180
post #174

Earlier quoted context omitted.

Where do you live that online banking is read only? I'm from Romania, so a developing country, and we've had full online banking (transfer money abroad, schedule monthly payments, make savings accounts, etc.) since at least 2007 for all the major banks. If someone would hack my online banking account they could do quite a few nasty things...

The context of this thread is puzzlement that the US doesn't have widespread 2FA for online banking, and I'm telling you why.

That's just sad if it's widespread in the US.
Post reply on HN