Earlier quoted context omitted.
My rule is simple: if you contact me, you are the one that had to authenticate. Otherwise you are probably a scammer. Although, I haven’t had many instances of communications from my bank where I cared about them authenticating. Like, if they tell me there is a problem, I can go check it out through the app, website, or whatever the user-initiated channel is. When I feel like it.
How do you authenticate them? I've never heard of this, I'm very curious.
Why are banks still getting authentication so wrong?
301–310 of 375 posts
Re: Why are banks still getting authentication so wrong?
#302Earlier quoted context omitted.
Why would a bank care about money laundering?
Because the government said so. Why did the government say so -- because the bank is the only place that can see your transactions and has a profile on you and has a dedicated person to call you and ask about that cash withdrawal on the Turkish side of the Syrian border or regular cash deposits of 100k each week in addition to your cop salary. Alternatively you can just not do anything with money laundering and all t…
Re: Why are banks still getting authentication so wrong?
#303Earlier quoted context omitted.
I mean this is basically the ENTIRE US health system
Birthdates are frequently asked in US health settings not as a protection against attack, but as a protection against mistake . They are not worried that someone is going to come in, and steal your appointment. They are worried that someone with the same name as you might show up on the same day and the doctor might treat the wrong patient with the wrong information. This is an completely different risk profile than…
Because I have literally seen this go wrong: “Mr John Smith, you’re here for procedure X, yes?” “Yes” Some other provider overhears: “I thought that was Mr Jones for procedure Y” “Are you Mr smith or Mr Jones?” “Mr Jones” “Then why did you say yes when I asked if you were Mr Smith” “I assumed you knew best”…
People do weird things in healthcare settings
Re: Why are banks still getting authentication so wrong?
#304Earlier quoted context omitted.
> I'd assume fixing this would cost less than what fraud must be costing them today. You'd be wrong there but not for obvious reasons. Ultimately the cost of fraud is passed on to consumers. Banks pass the costs on to merchants, who in turn increase prices. As a merchant increasing friction in the checkout process to reduce fraud does not improve profitability (broadly speaking). So no they had no actual financial in…
In the case of credit card payments this is true, but for checks and other P2P payments, there is no merchant to pass on costs to. For these, it's usually the banks absorbing the losses themselves (or their customers, if they aren't legally required to, but in many cases they are).
It's also pretty much a solved problem, it's expensive to cash a check anywhere but into a checking account in your name. If you write too many bad checks or try to deposit them you'll get banned from... the entire banking sector.
Re: Why are banks still getting authentication so wrong?
#305- TOTP having just relatively-recently become a first class citizen on iOS and Android,
- Not wanting to spend the money needed to educate their customers, many of whom can just barely text, on passkeys, and
- Lacking regulatory pressure to force their hand.
That said, I hate the trend of web services moving to "passwordless" auth schemes that rely solely on email or SMS .
Re: Why are banks still getting authentication so wrong?
#306You have to think of a Bank's threat model though. Account compromise is one threat, but the use of valid accounts for money laundering is another. In my view the reason they "get it wrong" is because they don't want you to be able to automate transactions, as that makes money laundering easier... Therefore, they don't want to use standard TOTP because that's easy to automate. Requiring SMS based 2FA is harder (but n…
Re: Why are banks still getting authentication so wrong?
#307Earlier quoted context omitted.
You have plenty of government id's in the US as well. Driver licenses, tax number, birth certificates ... I think often people mess up the subjects of privacy, freedom and a government provided id. You can have privacy and freedom even if you have a government issued id. And you can have your privacy and freedom taken away from you without the government giving you standardized way of proving your id.
A tax number isn't an identity document (it's an identifier), nor is a birth certificate (since it doesn't have a photo). Driver's licenses (or non-driver IDs) are the US's de facto ID standard.
Re: Why are banks still getting authentication so wrong?
#308Earlier quoted context omitted.
It is such a goddamned tragedy that we’ve come to this. And also an avoidable one: every E2E messaging app (WhatsApp, Android Messages, iMessage) should be able to properly authenticate the caller. But I presume services are asking too much money for this, and nobody wants to hand yet another vital service to Apple/Google/Meta. So instead we all suffer.
Be careful what you wish for. This problem is solved in China — you can contact many government agencies and major companies over WeChat and be sure that you're talking to the real entity, but the downside is that WeChat has a copy of your passport and knows everything about you.
It isn't. China is the best example that draconian identity verification / KYC processes don't stop scammers.
Re: Why are banks still getting authentication so wrong?
#309Identity providing is a natural monopoly and should be provided by the state in same manner as a passport is provided. We can discuss the implementation but in Denmark and quite a few other countries, the login problem in online government services and banking is solved by a single state run identity provider (MitID) and hopefully the EU will be succesful with their EIDAS initiative and provide a solution that works…
italy has quite an interesting system[0] where multiple identity providers (authorized by the State) can be used to provide identification against the central database. It'll probably be phased out at some point, but it's quite cool. [0] https://www.spid.gov.it/en/citizens/ it integrates with eIDAS too
Re: Why are banks still getting authentication so wrong?
#310Earlier quoted context omitted.
Absolutely not! The moment you have universal state-issued identity, you will be expected to provide it for everything , including tons of stuff that doesn’t require identity. Don’t be a privacy defeatist, the fight isn’t lost yet. Resist every single effort to make it easier for merchants and private entities to strongly identify users. The rows go into databases and they never go away. State-issued identity is one…
We have universal ID cards here in Belgium. They have a chip and along with a special card reader usb device you can log in to govt websites related to taxes, pension and basically everything else. If you have a smartphone you can use an app to scan a QR and log in that way. It's super convenient. Where is the privacy problem if you use this system to consult your own civil data ? Privacy is a thing in the EU and it'…
Then, you will simply have to provide full government ID to every business for every transaction. Instant surveillance state (given that they can access all business records).
This is not a world in which you wish to live. It is very important that you be able to transact without ID.