Live data from Hacker News

Why are banks still getting authentication so wrong?

jamal.haba.sh

1–10 of 375 posts

Re: Why are banks still getting authentication so wrong?

#2
This past weekend I was struggling to teach my 97-year old neighbor how to login to his RBC Bank account. It was an 11 step process!!! The state of technology in the Canadian banking system is abysmal.

Combine that with our cell providers, and it's a real problem. There's some cell providers like Public Mobile where you can't even opt into roaming. So SMS 2FA is never an option. [1]

[1] https://productioncommunity.publicmobile.ca/t5/Get-Support/T...

Re: Why are banks still getting authentication so wrong?

#3
> Even worse, these apps often become excuses, a reason to avoid implementing the open, interoperable standards that actually make a difference.

Even worse, under the hood, some of these apps use the TOTP standard. The entire extra premise is that the seed is not extractable and cannot be backed up.

Re: Why are banks still getting authentication so wrong?

#5
UBS Switzerland has a decent system. When I first opened the account 15 years ago we had a number pad of codes on paper we entered as the authentication. Then later we got a credit card sized electronic device where we enter a passcode and it gives us a one-time code to enter to login. And now we have an Access app - we go to the website, enter our contract number, point our phone at a QR code on the webpage and authenticate on the app, and the desktop browser logs us in. The access app also is used for logging in with the mobile banking app. It never relied on sms.

Super simple but probably costs some money to develop.

Re: Why are banks still getting authentication so wrong?

#6

This past weekend I was struggling to teach my 97-year old neighbor how to login to his RBC Bank account. It was an 11 step process!!! The state of technology in the Canadian banking system is abysmal. Combine that with our cell providers, and it's a real problem. There's some cell providers like Public Mobile where you can't even opt into roaming. So SMS 2FA is never an option. [1] [1] https://productioncommunity.pu…

Also to pay taxes, you have to type "CRA" into your bank's "Add Payee" searchbox and hope you pick the right result out of 5 different options that all have CRA in the title.

It's mind-boggling that this is the solution we've settled on.

Re: Why are banks still getting authentication so wrong?

#8
It's not just authentication that they get wrong. On several websites (non banks) I can get my entire history, all my logins, all my transactions, since I created my accounts: all the way back to, say, 2013... No problem.

But banking websites only allow to go a few years back. But now with the KYC/AML madness where every real-estate agent, notary, etc. is forced to snitch for the intrusive government, they ask for "proofs of the source of funds" for things that can go back many, many, many years.

"I sold an appartment I bought in 2013"

"Source of funds you used to buy the apartment in 2013 please"

And you're sorry out of luck with traditional banks.

My banks then typically charge 25 EUR per month, per account, to get past history. So say you have 3 accounts, that's 900 EUR per year for your history.

And to add insult to injury, it's all dog slow of course.

Back in the days it wasn't like that: it didn't feel like the Gestapo was watching your every move and asking honest citizens proofs of everything. So I didn't know that for my private account I had to carefully save every single wire transfer for it may be needed 15 years in the future.

Just screw that entire system. Fuck it.

P.S: my mom still have one banking website where geniuses decided that a PIN had to be entered by using the mouse to click on digits that are randomly placed on the screen. Major french bank. In 2025.

Re: Why are banks still getting authentication so wrong?

#9

Some banks do it properly. For example, my local credit union does Google Authenticator (actually TOTP, but they call it Google Authenticator). I use it with Authy on F-Droid.

Please do not use Authy, lacks essential features and it was bought by a bad actor.

Re: Why are banks still getting authentication so wrong?

#10

UBS Switzerland has a decent system. When I first opened the account 15 years ago we had a number pad of codes on paper we entered as the authentication. Then later we got a credit card sized electronic device where we enter a passcode and it gives us a one-time code to enter to login. And now we have an Access app - we go to the website, enter our contract number, point our phone at a QR code on the webpage and auth…

Zurich Kantonalbank (ZKB) has a very similar system, probably because they're also a big bank in Switzerland
Post reply on HN