Live data from Hacker News

Why are banks still getting authentication so wrong?

jamal.haba.sh

11–20 of 375 posts

Re: Why are banks still getting authentication so wrong?

#13
So an interesting trick I learned while suffering from the same issue is that roaming usually only applies to outbound data / SMS usage. So when I travel I disable data usage, and set my travel sim to be active and primary, but I can still receive SMS for free.

Re: Why are banks still getting authentication so wrong?

#14

UBS Switzerland has a decent system. When I first opened the account 15 years ago we had a number pad of codes on paper we entered as the authentication. Then later we got a credit card sized electronic device where we enter a passcode and it gives us a one-time code to enter to login. And now we have an Access app - we go to the website, enter our contract number, point our phone at a QR code on the webpage and auth…

Banks in the US sometimes support U2F, but you can never disable SMS. Maybe one day.

Re: Why are banks still getting authentication so wrong?

#17

Some banks do it properly. For example, my local credit union does Google Authenticator (actually TOTP, but they call it Google Authenticator). I use it with Authy on F-Droid.

Best thing that ever happened in this bleak security world is Google Authenticator. I haven’t used that app itself in years, preferring others, but the existence of it and it being non-proprietary, has done a lot to bring over the moderately-security-competent companies to thinking “hey, I guess we should support this.” Obviously that group excludes every American bank, every power utility, etc. They all want to email or text me a freaking code at each login for some reason.

Re: Why are banks still getting authentication so wrong?

#18

Some banks do it properly. For example, my local credit union does Google Authenticator (actually TOTP, but they call it Google Authenticator). I use it with Authy on F-Droid.

Please do not use Authy, lacks essential features and it was bought by a bad actor.

Is there a way off Authy yet?

Re: Why are banks still getting authentication so wrong?

#19

Some banks do it properly. For example, my local credit union does Google Authenticator (actually TOTP, but they call it Google Authenticator). I use it with Authy on F-Droid.

Please do not use Authy, lacks essential features and it was bought by a bad actor.

I recommend KeePassDX from F-Droid for TOTP.

Re: Why are banks still getting authentication so wrong?

#20

Also, they still expect you to authenticate when they phone you. No, I'm not going to tell you my birthday when you phone me. No wonder so many people get scammed, when banks are training people on how to get scammed.

It was a proud day when my bank stopped sending emails with links in them. Of course their outsourced fraud prevention dept still calls and leaves messages with callback numbers, or just asks me for PII. Fuck off.

Send people to the website to find your number, idiots.

Post reply on HN