I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…
In Sweden we have BankID - a two-factor, two-way authentication using public/private encrypted keys that's bound to a smartphone as a signature. The process is user-friendly while keeping security high: - The place where you want to login has to trigger the authentication from their server on every login - and have to be certified for BankID. - You then have to open the app, enter your fingerprint or 6-pin code befor…
Big yikes, that's a no for me.