> The idea is good it gives you an extra layer of protection against password theft (link 1, link 2, link 3). That sounds obnoxiously insecure on the back-end. Notoriously, the most broken authentication mechanisms used plaintext (or reversibly encrypted) storage. The answers to the three security questions that the article links to also point this out. Sounds like ING Poland needs to be called out by some security r…
But yes, all of the points raised in the answers [1] are totally valid. The extra security benefit is so small that really not worth the negative impact on usability. System designers should rather focus more on implementing 2FA.