Live data from Hacker News

Why are banks still getting authentication so wrong?

jamal.haba.sh

101–110 of 375 posts

Re: Why are banks still getting authentication so wrong?

#101

Also, they still expect you to authenticate when they phone you. No, I'm not going to tell you my birthday when you phone me. No wonder so many people get scammed, when banks are training people on how to get scammed.

Recently had to call Discover because of unauthorized use of card, apparently to buy Facebook ads of all things. They didn't call me, just locked my account and said I had to call them. I couldn't even pay the balance until I did. Anyway they needed to verify my identity, so they ask me for some info from the back of the card and a phone number that they can send the OTP to. I give them a phone number, it's not even…

Background check for a new employer resulted in me getting an email to my personal account:

"Hi, I'm XYZ from XYZ background checks, I'm conducting your pre-employment check, and I just want to confirm that your full name is V, your DOB is W, your place of birth is X, your address is Y and your full SSN is Z...

... and that this is the correct email address for you. Please confirm."

Holy hell. Thankfully I reached out to the employer about this (and the background check company's attempt to reach out to my partner on Facebook for ... something? This wasn't a security check, just a regular employment background) and they were as horrified as me, apologized, and fired their background check provider.

Re: Why are banks still getting authentication so wrong?

#102
The friction of changing bank accounts is high, and few people choose their bank accounts based on how easy the online authentication is. Unless a bank does this meaningfully much worse than their competitors (low bar) they have little incentive to fix it.

If you think TD is bad, try some European countries where there's only a handful of banks...

Re: Why are banks still getting authentication so wrong?

#103
post #76
post #29

Identity providing is a natural monopoly and should be provided by the state in same manner as a passport is provided. We can discuss the implementation but in Denmark and quite a few other countries, the login problem in online government services and banking is solved by a single state run identity provider (MitID) and hopefully the EU will be succesful with their EIDAS initiative and provide a solution that works…

Absolutely not! The moment you have universal state-issued identity, you will be expected to provide it for everything , including tons of stuff that doesn’t require identity. Don’t be a privacy defeatist, the fight isn’t lost yet. Resist every single effort to make it easier for merchants and private entities to strongly identify users. The rows go into databases and they never go away. State-issued identity is one…

We have universal ID cards here in Belgium. They have a chip and along with a special card reader usb device you can log in to govt websites related to taxes, pension and basically everything else.

If you have a smartphone you can use an app to scan a QR and log in that way. It's super convenient.

Where is the privacy problem if you use this system to consult your own civil data ? Privacy is a thing in the EU and it's a complex issue mainly because of these tech behemoths that need to know your shoe size before you can use their todo list app.

> Resist every single effort to make it easier for merchants and private entities to strongly identify users

How is this related to govt issued ID cards ?

Re: Why are banks still getting authentication so wrong?

#104
post #28

Can we get rid of the password expiration too? Requiring that users change their perfectly secure password every 6 months is absurd and gives the impression of security when in reality it only makes things worse.

NIST only changed that recommendation last year. Expect that update to take at least 10 years to percolate through institutions like banks.

And expect people to still implement it in the future, based on documentation from some consultancy that hasn't disseminated the new recommendation internally to their implementation engineers.

Re: Why are banks still getting authentication so wrong?

#105
post #88
post #71

Earlier quoted context omitted.

Precisely nobody is suggesting that there be no recovery mechanism. This criticism is a red herring.

What do you think such a recovery mechanism would look like without SMS?

Password managers, such as KeePassX can generate TOTP codes. And Keepass database is just a file, you can have as many backups of it as you want.

Re: Why are banks still getting authentication so wrong?

#106

Also, they still expect you to authenticate when they phone you. No, I'm not going to tell you my birthday when you phone me. No wonder so many people get scammed, when banks are training people on how to get scammed.

Social Security just tried to authenticate my wife's birthday this way. She told them no, give me your phone #. It googled to SSA in Alabama and she called it up and proceeded from there.

Re: Why are banks still getting authentication so wrong?

#107
post #33

What actual real life person is going to switch their bank account because TOTP isn't supported? That's why banks get authentication wrong. Because they are in the business of banking and banking customers do not care about TOTP.

But banks should have to provide better security or they should be at fault if the account is accessed by a third party due to their weak security.

Ok. They are not though.

Re: Why are banks still getting authentication so wrong?

#108
post #20

Also, they still expect you to authenticate when they phone you. No, I'm not going to tell you my birthday when you phone me. No wonder so many people get scammed, when banks are training people on how to get scammed.

It was a proud day when my bank stopped sending emails with links in them. Of course their outsourced fraud prevention dept still calls and leaves messages with callback numbers, or just asks me for PII. Fuck off. Send people to the website to find your number, idiots.

My bank also promises to never send links. Instead, it sends all of its messages as images without any alt text, and these images sometimes contain links to retype.

Re: Why are banks still getting authentication so wrong?

#109
post #43
post #22

OP's problem sounds like failure to plan. If you are going to suspend your cell plan, you should probably check your authenticator works or have a backup option before you travel to another country. I don't know what the viable alternative is. Passkeys have just as many issues when phones are stolen, lost or broken. You cannot expect consumers to store recovery codes. I do agree support of TOTP authenticators would h…

hardware tokens are the way! Everyone has had a house key their whole lives, and understands how to keep a spare to prevent lock-outs.

I know plenty of people who have lost house keys. I have many Yubikeys and I am responsible with my things, but not everybody is like us.

Re: Why are banks still getting authentication so wrong?

#110
post #66

Earlier quoted context omitted.

In the U.S., identity providing is not a role the government fills. Not everyone has to have a passport, for example. A passport is merely a purpose-specific tool for crossing borders, not general identity.

Federal government or governmemts in general? As far as I get, driver licenses are doing in US what id cards are doing in Europe and are issued by governments too.

While a driver's license does normally fill that role, it's not mandated and not everyone has a driver's license (or even a state issued ID).

Some stuff like voting you can use something like a utility bill. Some stuff will want your birth certificate. Some stuff will want multiple types of documents.

Americans have historically been against mandated government IDs (though mostly with the concept of a federal/national ID).

Post reply on HN