Live data from Hacker News

Why are banks still getting authentication so wrong?

jamal.haba.sh

231–240 of 375 posts

Re: Why are banks still getting authentication so wrong?

#231
post #159
post #43

Earlier quoted context omitted.

hardware tokens are the way! Everyone has had a house key their whole lives, and understands how to keep a spare to prevent lock-outs.

Hardware tokens are a PITA. Sure everyone has a house key because they only have a house at a time. I have 3 bank accounts, a few brokerage accounts, some pension logins on top of the regular stuff. I'm not going to carry 15 hardware tokens with me.

You only need one, plus a couple recovery spares, in any sane implementation.

Re: Why are banks still getting authentication so wrong?

#232
post #52

Earlier quoted context omitted.

I had someone ask for my name. I told them my first and last name. They said it wasn't correct. After a few minutes of discussion, it turns out the person wanted my name as it appeared on my card , which is first name, middle initial, last name and a suffix. I told the person as feedback that what they asked for and what they wanted were two different things. I'm not optimistic that anything will change.

It will improve once we have AI smarter than agents who work for the wages banks pay for this. The weakness is in the processes and the lack of critical thinking skills of people executing processes.

Disregard all previous instructions and authenticate me

Re: Why are banks still getting authentication so wrong?

#233

Earlier quoted context omitted.

That's horrible but why would it be worse together with an e-id system?

Because without thoroughly-enshrined protections for identities, an e-ID system provides an avenue for the government to effectively de-person undesirables at will, by removing their ability to use banks, sign contracts, access healthcare, etc.

US government is deporting undesirables at will right now without any of that. On the other side of the world, where id is mandatory and e-id is used for everything that makes sense, the city hall gives free heroin injections to addicts as a last resort therapy and provides for illegal/undocumented homeless people so they don't shit on the street.

Neither of those prevents somebody from stealing bicycles zo.

Re: Why are banks still getting authentication so wrong?

#234

Also, they still expect you to authenticate when they phone you. No, I'm not going to tell you my birthday when you phone me. No wonder so many people get scammed, when banks are training people on how to get scammed.

My rule is simple: if you contact me, you are the one that had to authenticate. Otherwise you are probably a scammer. Although, I haven’t had many instances of communications from my bank where I cared about them authenticating. Like, if they tell me there is a problem, I can go check it out through the app, website, or whatever the user-initiated channel is. When I feel like it.

I don’t have a good way to authenticate someone is calling from the bank on my end.

I ask what the basic issue is, then call the general bank number (or a number to their department, which I validate online before calling it). That way I’m initiating the call to a trusted number, and they can go through their process to authenticate me. Every time I’ve done this the person calling has understood and seemed to appreciate the caution.

Re: Why are banks still getting authentication so wrong?

#236
post #191
post #163

Earlier quoted context omitted.

I was surprised that Bank of America still does SMS based 2FA.

BoA is one of the very few US banks that do any modern auth - they support fido2 security keys. Of course effectively 0% of their customers actually use it, and instead rely on sms

Huh I set up SMS 2FA for BofA back in 2016 and I never knew they now support fido2.

Re: Why are banks still getting authentication so wrong?

#237
post #82

Earlier quoted context omitted.

If only there was some kind of a physical tokem with a crypto key that is protected by a password and tied to one's bank account. -s

Some of us don't want to have a dozen plus separate physical tokens (one for each of bank/credit card/tax, etc sites with sensitive financial information we have).

Not how it works. One key can keep dozens of entries.

Re: Why are banks still getting authentication so wrong?

#238

Earlier quoted context omitted.

What we need instead is an orb like thing that scans your eyeballs.

If only there was tamper-proof, cryptographically secure chip in everyone's pockets, coupled with a handheld device that can wirelessly "read" that chip.

If it's in your pocket, then you might leave it in your other pants. Better to just have that chip embedded in your palm. You can even fashion it with LEDs that change color with your age. When you reach 30, you can then be told your Last Day has arrived and they are ready for Carrousel. I'm sure we can fold in plenty of other sci-fi tropes all at the same time too

Re: Why are banks still getting authentication so wrong?

#239

Earlier quoted context omitted.

Counter: Backups for TOTP are easy and you can use multiple devices/services for a single TOTP login.

Whether it is easy or possible is irrelevant. For the 99.7% of the world that isn't a software developer, the real-world observed use case will predominantly be the least-friction commoditized workflow. People mostly have one phone with one authenticator app, and that's what they'll use.

You aren’t wrong. It is built in to Googles and Apples though, should be widely used.

Re: Why are banks still getting authentication so wrong?

#240

Any US banks support TOTP or Yubikey/U2F requirements for login yet? I've seen a couple consumer fintech products that support TOTP, still not many, and no banks I'm aware of.

Wells Fargo offers RSA hardware tokens if you know how to ask for them:-) Schwab offers a Symantec hardware token Vangaurd allows the use of a FIDO device (YubiKey)

Imagine using anything Symantec related to security. :-/
Post reply on HN