Live data from Hacker News

Why are banks still getting authentication so wrong?

jamal.haba.sh

161–170 of 375 posts

Re: Why are banks still getting authentication so wrong?

#161

Why is there no standardized e-ID in the US? How much money is wasted by different authorities and businesses having to reinvent the same wheel over and over? I have used the same auth for doing my taxes or checking my prescriptions or signing into my bank for 20 years.

From my experience in the US, UK (see https://en.wikipedia.org/wiki/NO2ID ) and Canada there is a cultural aversion to government ID. I believe it's the same in Aus and NZ, so it may be an Anglophone thing.

Re: Why are banks still getting authentication so wrong?

#162
post #144
post #76

Earlier quoted context omitted.

Absolutely not! The moment you have universal state-issued identity, you will be expected to provide it for everything , including tons of stuff that doesn’t require identity. Don’t be a privacy defeatist, the fight isn’t lost yet. Resist every single effort to make it easier for merchants and private entities to strongly identify users. The rows go into databases and they never go away. State-issued identity is one…

The way identity providers are supposed to work is to not necessarily divulge your identity, but properties necessary for the respective service. For example, they can attest that you are an adult and a citizen of $country, but don’t need to disclose any further information. When using an identity provider with a third-party service, the attested attributes are displayed to the user to approve their disclosure. This…

But most sites will just require you to attest your full name. Additionally, they will require a unique ID that the govt might not bother changing between websites.

Real name and central ID requirements are anti privacy and have the tracking problems OP highlighted.

Re: Why are banks still getting authentication so wrong?

#163

You have to think of a Bank's threat model though. Account compromise is one threat, but the use of valid accounts for money laundering is another. In my view the reason they "get it wrong" is because they don't want you to be able to automate transactions, as that makes money laundering easier... Therefore, they don't want to use standard TOTP because that's easy to automate. Requiring SMS based 2FA is harder (but n…

I was surprised that Bank of America still does SMS based 2FA.

Re: Why are banks still getting authentication so wrong?

#164

Earlier quoted context omitted.

Banks are aware that NIST and various other bodies have updated their guidance about password expiration. Even vendors like Microsoft who supply extensively to financial services, have updated their guidance about password policies. At this point — barring edge cases of operating in geographies where regulations haven’t caught up — it’s just inertia, aka “inaction doesn’t get you fired (usually)”.

It's not inertia. In my big corpo's case, it's because the cybersecurity insurer is refusing to follow NIST.

I have been in three different organisations now with this same excuse, and actually called their insurer to clarify. In all cases, the insurer asks the password policy such as expirations. Complete absence of a written policy is a problem. Non expiring passwords was not.

Someone in management took the application form and justified their own belief on security and two of those three companies still tell staff "it's because of our insurerer" even after given the facts.

Re: Why are banks still getting authentication so wrong?

#165

> TOTP Support: Let users use any standard authenticator How many of them allow to generate a code related to specific operation (provide a context for what is being "confirmed")? This is the EU requirement that killed everything but SMS and bank mobile apps.

And I love that requirement. I do banking on my desktop and to confirm the transfers I get a push notification from a third-party application (ItsMe, so not a banking mobile app) with all the information I have entered. I can confirm the transaction from a complete separate device while doing a second check if all details are correct.

The requirement per se is not the biggest problem. Implementation by different banks is. In my country I have several bank accounts.

One bank allows me to install mobile app on up to 5 smartphones, all I need is connect the smartphone to the Internet (e.g. through Wi-Fi).

Another bank allows me to have up to 3 smartphones, but identifies them by phone number, so it forces me to have 3 difrerent SIM cards

Yet another bank will only allow me to have mobile app only on one device. To activate on another device I need to receive SMS code, and if I lose my SIM card I need to show up at a branch in person.

Re: Why are banks still getting authentication so wrong?

#166

> I don’t think anyone considers a bank account “low-risk.” Yet here we are, still relying on SMS as the default, and sometimes only, 2FA option > Passkeys (FIDO2/WebAuthn): Phishing-resistant, device-based login using biometrics. Excellent UX and security. In response to the complaints about SMS MFA, yeah, it has its issues (we don't even support it in our auth software) but it's not totally indefensible. It makes i…

> People really don't understand passkeys Passkey UX is absolutely terrible. It's unclear what is happening, what is being stored where (do you have my passkey? do I? is it in my browser? is it on my phone?), how communication is happening between devices, etc. Also nobody seems to explain what exactly a passkey is . Where's the thing I can point at and say "that's your passkey"?

One of the “features” of a passkey is that you can’t point to it. It’s a fucking nightmare

Re: Why are banks still getting authentication so wrong?

#167

Earlier quoted context omitted.

Our hotel franchise requires us to change the password every month. We can't use the last 6-8 passwords.

Password manager ftw

This is fine for services you can easily access on a phone or computer.

My employer requires I change my laptop password every 60 days, it stores the last 2 years of passwords to prevent reuse.

I am not opening up LastPass and plugging in a 32 character random string every time I want to start my computer up. My password at any given point is either a few random words and a number, or a short (8-12 character) alphanumeric string without symbols. But you know what it always is? On a post-it note stuck to the inside of my laptop.

My employer is consciously choosing to make my laptop less secure because the CISO is an idiot.

Re: Why are banks still getting authentication so wrong?

#168
As far as I can tell, the reason why any given login is needlessly complex is that some product manager somewhere has outdated info in their head that says stuff like "passwords need 4 different character classes" and "everybody uses SMS for 2FA, we need to use that". Powerless devs then mindlessly implement what they're asked to implement.

Re: Why are banks still getting authentication so wrong?

#169
post #29

Identity providing is a natural monopoly and should be provided by the state in same manner as a passport is provided. We can discuss the implementation but in Denmark and quite a few other countries, the login problem in online government services and banking is solved by a single state run identity provider (MitID) and hopefully the EU will be succesful with their EIDAS initiative and provide a solution that works…

In the U.S., identity providing is not a role the government fills. Not everyone has to have a passport, for example. A passport is merely a purpose-specific tool for crossing borders, not general identity.

In Norway our BankID system, which is similar to what the Danes have, is owned by the banks, and is a run by a private company. While I personally think that in principle it should be run by the government. It works well enough, and it is imo. proof that it does not have to be run by the government.

Re: Why are banks still getting authentication so wrong?

#170

Also, they still expect you to authenticate when they phone you. No, I'm not going to tell you my birthday when you phone me. No wonder so many people get scammed, when banks are training people on how to get scammed.

My rule is simple: if you contact me, you are the one that had to authenticate. Otherwise you are probably a scammer. Although, I haven’t had many instances of communications from my bank where I cared about them authenticating. Like, if they tell me there is a problem, I can go check it out through the app, website, or whatever the user-initiated channel is. When I feel like it.

I stick to this except when I make some unusual credit card purchase and immediately get called to verify it. I don't like it, but usually I need to make the purchase. If someone had the feed of risk denied CC purchases, they could gather a lot of personal information. Probably there is lower hanging fruit for fraud.
Post reply on HN