Live data from Hacker News

Why are banks still getting authentication so wrong?

jamal.haba.sh

211–220 of 375 posts

Re: Why are banks still getting authentication so wrong?

#211

Also, they still expect you to authenticate when they phone you. No, I'm not going to tell you my birthday when you phone me. No wonder so many people get scammed, when banks are training people on how to get scammed.

Recently had to call Discover because of unauthorized use of card, apparently to buy Facebook ads of all things. They didn't call me, just locked my account and said I had to call them. I couldn't even pay the balance until I did. Anyway they needed to verify my identity, so they ask me for some info from the back of the card and a phone number that they can send the OTP to. I give them a phone number, it's not even…

> and a phone number that they can send the OTP to. I give them a phone number, it's not even the one on the account, they send the text to it.

This regularly blows my mind.

Presumably it’s some data broker or phone carrier integration, because for me, the answer is usually “sorry, we can’t verify that number, is this a postpaid contract in your name?”

No, it’s not. Oh, that’s a requirement for doing business with you? In that case, I won’t.

Re: Why are banks still getting authentication so wrong?

#212
post #103

Earlier quoted context omitted.

We have universal ID cards here in Belgium. They have a chip and along with a special card reader usb device you can log in to govt websites related to taxes, pension and basically everything else. If you have a smartphone you can use an app to scan a QR and log in that way. It's super convenient. Where is the privacy problem if you use this system to consult your own civil data ? Privacy is a thing in the EU and it'…

If it's easy enough to connect such an ID with arbitrary companies, I don't trust US privacy laws to prevent them from requiring it.

Maybe not having IDs is the reason why US doesn't have privacy protections and everybody can buy all the data anyway for 5 bucks from ad tech and telecoms.

Re: Why are banks still getting authentication so wrong?

#213
post #159
post #43

Earlier quoted context omitted.

hardware tokens are the way! Everyone has had a house key their whole lives, and understands how to keep a spare to prevent lock-outs.

Hardware tokens are a PITA. Sure everyone has a house key because they only have a house at a time. I have 3 bank accounts, a few brokerage accounts, some pension logins on top of the regular stuff. I'm not going to carry 15 hardware tokens with me.

SecurID tokens suck but with FIDO2, you'd only need one key.

Of course, that breaks the UX analogy of the house key.

Re: Why are banks still getting authentication so wrong?

#214

Earlier quoted context omitted.

Same for SSNs

What we need instead is an orb like thing that scans your eyeballs.

If only there was tamper-proof, cryptographically secure chip in everyone's pockets, coupled with a handheld device that can wirelessly "read" that chip.

Re: Why are banks still getting authentication so wrong?

#216

Also, they still expect you to authenticate when they phone you. No, I'm not going to tell you my birthday when you phone me. No wonder so many people get scammed, when banks are training people on how to get scammed.

Businesses that expect me to hand over PII when they call me certainly do get upset when I point out that I have no idea who THEY are, and that THEY called me so the onus is on them to prove who they are (typically they will claim their phone number is enough, or that I should ring the phone number that they provide).

The actual truth is, though, that the security theatre that they put on is about all that can be done when two strangers meet to prove identity.

Hey you do you know a secret that we know about you? Here's a secret about us that you are supposed to know.

Re: Why are banks still getting authentication so wrong?

#217

Why is there no standardized e-ID in the US? How much money is wasted by different authorities and businesses having to reinvent the same wheel over and over? I have used the same auth for doing my taxes or checking my prescriptions or signing into my bank for 20 years.

It is partly cultural, and partly a power struggle between states and the federal government.

Re: Why are banks still getting authentication so wrong?

#218
post #88
post #71

Earlier quoted context omitted.

Precisely nobody is suggesting that there be no recovery mechanism. This criticism is a red herring.

What do you think such a recovery mechanism would look like without SMS?

MFA is more than 2FA. You'll typically mandate several ways to get in, ahead of time. Whether a third logical device or printing out recovery codes. For something as important as a bank, folks will comply.

Re: Why are banks still getting authentication so wrong?

#219
post #29

Identity providing is a natural monopoly and should be provided by the state in same manner as a passport is provided. We can discuss the implementation but in Denmark and quite a few other countries, the login problem in online government services and banking is solved by a single state run identity provider (MitID) and hopefully the EU will be succesful with their EIDAS initiative and provide a solution that works…

This yet another USA defaultism post.

I have developed for several banks in Europe and EIDAS + other national ID based systems are the standard. Some also allow authentication with their own apps, but still having alternate options smartcard with reader or smartcard based national app.

Most seem to favour using apereo CAS for it even though it seems overkill and overly complicated (especially upgrading it, lacking documentation) most of the time.

Re: Why are banks still getting authentication so wrong?

#220
post #181

Earlier quoted context omitted.

In Germany, paying for goods online using Sofort (direct bank payment, not buy now pay later) literally involves typing in the same credentials used to log into online banking, that’s your account number, branch and PIN, followed by scanning a “TAN” similar to a QR code using the bank app. The only thing stopping them taking my data and logging into my banking it seems is the TAN app part, that could easily be phishe…

Is this another incarnation of Sofort? Fortunately nobody is forced to used the former nor the later, you can either pay with card or just make your own SEPA transfer from any bank in Europe.

At least in Lithuania the "nobody is forced to used" is partly true. Sometimes in checkout flow you get links to big-5 banks and thats it, even tho technically entire SEPA should be ok.
Post reply on HN