Live data from Hacker News

Why are banks still getting authentication so wrong?

jamal.haba.sh

171–180 of 375 posts

Re: Why are banks still getting authentication so wrong?

#171
post #99

i worked on a large platform (YC company, too!) previously on their 2FA implementation. while not ideal, it was decided to keep SMS 2FA because there are still people out there without smart phones or in general the ability to do TOTP. but they still have some means to access the site that wasn't a smartphone i guess. so, it's a bit of a compatibility issue, i guess there will be some portion of the population who wi…

Anything that requires a cellphone bakes in BOTH a single point of failure and cumbersome extra steps. Terrible practice anyway - even though so many people here are in love with both single points of failure and extra steps.

ALLOWING methods X, Y or Z would be better reasoning.

Re: Why are banks still getting authentication so wrong?

#173

Banks are always facing a trade-off between security and regulatory accessibility requirements. A former employer offered ~10 different ways to perform step-up authentication for high risk activities to avoid getting slapped with fines.

Then again "regulatory accessibility" has little to do with usability. You can have an 11 step process which works with a screen reader and is still hell.

Re: Why are banks still getting authentication so wrong?

#174

> I don’t think anyone considers a bank account “low-risk.” Yet here we are, still relying on SMS as the default, and sometimes only, 2FA option > Passkeys (FIDO2/WebAuthn): Phishing-resistant, device-based login using biometrics. Excellent UX and security. In response to the complaints about SMS MFA, yeah, it has its issues (we don't even support it in our auth software) but it's not totally indefensible. It makes i…

I. don't. care. Because we have to cater to the absolute lowest denominator, I now can't use my credit card 90% of the time because I can't receive SMS when I'm traveling aboard? No, not everyone has a fking iPhone and iMessage. Nothing in your comment serves as a defense of most places only having SMS 2FA. Why can Capital One email me every critical account notification, but can't email me 2FA/OTP codes for confirming transactions when I'm on the other side of the world? Why?

It is flatly absurd that my Xbox account can be more secure than most of my bank accounts. I am tired of hearing people justify the utter laziness of US financial institutions. Everything about dealing with money in the US has become increasingly incredibly user hostile. Fidelity won't allow ANY integration with apps like Lunch Money and have some impressive automation detection that blocks headless Chrome usage better than anyone else. I'm completely at their mercy, and cannot sanely manage my money because of them. It's complete god damn garbage.

Re: Why are banks still getting authentication so wrong?

#175
post #76
post #29

Identity providing is a natural monopoly and should be provided by the state in same manner as a passport is provided. We can discuss the implementation but in Denmark and quite a few other countries, the login problem in online government services and banking is solved by a single state run identity provider (MitID) and hopefully the EU will be succesful with their EIDAS initiative and provide a solution that works…

Absolutely not! The moment you have universal state-issued identity, you will be expected to provide it for everything , including tons of stuff that doesn’t require identity. Don’t be a privacy defeatist, the fight isn’t lost yet. Resist every single effort to make it easier for merchants and private entities to strongly identify users. The rows go into databases and they never go away. State-issued identity is one…

I'm so sick of retail clerks who insist on scanning the barcode of my driver's license. To verify I am 21 you don't need my height, weight, eye color, and home address. You can ascertain that my visually inspecting just the first two digits of my birth year.

Re: Why are banks still getting authentication so wrong?

#176

What actual real life person is going to switch their bank account because TOTP isn't supported? That's why banks get authentication wrong. Because they are in the business of banking and banking customers do not care about TOTP.

Me? As in, I've literally changed banks and canceled cards over this.

I can't get SMS when I'm traveling which is 95% of my time. It's such an entirely ignorant US-centric view to assume that everyone has a phone, has SMS plans, has cell service at all, etc.

Re: Why are banks still getting authentication so wrong?

#177

Earlier quoted context omitted.

And I love that requirement. I do banking on my desktop and to confirm the transfers I get a push notification from a third-party application (ItsMe, so not a banking mobile app) with all the information I have entered. I can confirm the transaction from a complete separate device while doing a second check if all details are correct.

The requirement per se is not the biggest problem. Implementation by different banks is. In my country I have several bank accounts. One bank allows me to install mobile app on up to 5 smartphones, all I need is connect the smartphone to the Internet (e.g. through Wi-Fi). Another bank allows me to have up to 3 smartphones, but identifies them by phone number, so it forces me to have 3 difrerent SIM cards Yet another…

Plus the "app" was written by clowns and doesn't really work for any reasonable idea of "work".

Re: Why are banks still getting authentication so wrong?

#178
Pretty much the same thing with Chase. I had to access my account while overseas and had a somewhat similar story.

The mobile app doesn't require a second factor, so I was able to log in there, but I couldn't transfer funds or something on mobile, and buried in a deep section of the settings I found a way to get the OTP via email.

Really disturbing the banks still haven't secured this.

Re: Why are banks still getting authentication so wrong?

#179

> TOTP Support: Let users use any standard authenticator How many of them allow to generate a code related to specific operation (provide a context for what is being "confirmed")? This is the EU requirement that killed everything but SMS and bank mobile apps.

Although to be fair this EU requirement tends in practice to make things yet still more cumbersome - requiring multiple authentications in one online banking session.

Re: Why are banks still getting authentication so wrong?

#180
post #76

Earlier quoted context omitted.

Absolutely not! The moment you have universal state-issued identity, you will be expected to provide it for everything , including tons of stuff that doesn’t require identity. Don’t be a privacy defeatist, the fight isn’t lost yet. Resist every single effort to make it easier for merchants and private entities to strongly identify users. The rows go into databases and they never go away. State-issued identity is one…

> Absolutely not! The moment you have universal state-issued identity, you will be expected to provide it for everything, including tons of stuff that doesn’t require identity. Indeed this has happened in Denmark already where for example DBA (Danish version of ebay) started soft-mandating MitID verification. Soon to be actually mandatory.

At one point I was researching using the Norwegian BankID system to ensure that accounts where real people. The pricing model didn't make that look like a reasonable choice. While I'm not surprised an eBay like service would be fine to pay to combat fraud. For a lot of offerings, paying the cost of using such services will not be worth it.
Post reply on HN