Earlier quoted context omitted.
hardware tokens are the way! Everyone has had a house key their whole lives, and understands how to keep a spare to prevent lock-outs.
Hardware tokens are a PITA. Sure everyone has a house key because they only have a house at a time. I have 3 bank accounts, a few brokerage accounts, some pension logins on top of the regular stuff. I'm not going to carry 15 hardware tokens with me.
Why are banks still getting authentication so wrong?
231–240 of 375 posts
Re: Why are banks still getting authentication so wrong?
#232Earlier quoted context omitted.
I had someone ask for my name. I told them my first and last name. They said it wasn't correct. After a few minutes of discussion, it turns out the person wanted my name as it appeared on my card , which is first name, middle initial, last name and a suffix. I told the person as feedback that what they asked for and what they wanted were two different things. I'm not optimistic that anything will change.
It will improve once we have AI smarter than agents who work for the wages banks pay for this. The weakness is in the processes and the lack of critical thinking skills of people executing processes.
Re: Why are banks still getting authentication so wrong?
#233Earlier quoted context omitted.
That's horrible but why would it be worse together with an e-id system?
Because without thoroughly-enshrined protections for identities, an e-ID system provides an avenue for the government to effectively de-person undesirables at will, by removing their ability to use banks, sign contracts, access healthcare, etc.
Neither of those prevents somebody from stealing bicycles zo.
Re: Why are banks still getting authentication so wrong?
#234Also, they still expect you to authenticate when they phone you. No, I'm not going to tell you my birthday when you phone me. No wonder so many people get scammed, when banks are training people on how to get scammed.
My rule is simple: if you contact me, you are the one that had to authenticate. Otherwise you are probably a scammer. Although, I haven’t had many instances of communications from my bank where I cared about them authenticating. Like, if they tell me there is a problem, I can go check it out through the app, website, or whatever the user-initiated channel is. When I feel like it.
I ask what the basic issue is, then call the general bank number (or a number to their department, which I validate online before calling it). That way I’m initiating the call to a trusted number, and they can go through their process to authenticate me. Every time I’ve done this the person calling has understood and seemed to appreciate the caution.
Re: Why are banks still getting authentication so wrong?
#235Re: Why are banks still getting authentication so wrong?
#236Earlier quoted context omitted.
I was surprised that Bank of America still does SMS based 2FA.
BoA is one of the very few US banks that do any modern auth - they support fido2 security keys. Of course effectively 0% of their customers actually use it, and instead rely on sms
Re: Why are banks still getting authentication so wrong?
#237Earlier quoted context omitted.
If only there was some kind of a physical tokem with a crypto key that is protected by a password and tied to one's bank account. -s
Some of us don't want to have a dozen plus separate physical tokens (one for each of bank/credit card/tax, etc sites with sensitive financial information we have).
Re: Why are banks still getting authentication so wrong?
#238Earlier quoted context omitted.
What we need instead is an orb like thing that scans your eyeballs.
If only there was tamper-proof, cryptographically secure chip in everyone's pockets, coupled with a handheld device that can wirelessly "read" that chip.
Re: Why are banks still getting authentication so wrong?
#239Earlier quoted context omitted.
Counter: Backups for TOTP are easy and you can use multiple devices/services for a single TOTP login.
Whether it is easy or possible is irrelevant. For the 99.7% of the world that isn't a software developer, the real-world observed use case will predominantly be the least-friction commoditized workflow. People mostly have one phone with one authenticator app, and that's what they'll use.
Re: Why are banks still getting authentication so wrong?
#240Any US banks support TOTP or Yubikey/U2F requirements for login yet? I've seen a couple consumer fintech products that support TOTP, still not many, and no banks I'm aware of.
Wells Fargo offers RSA hardware tokens if you know how to ask for them:-) Schwab offers a Symantec hardware token Vangaurd allows the use of a FIDO device (YubiKey)