Live data from Hacker News

Why are banks still getting authentication so wrong?

jamal.haba.sh

281–290 of 375 posts

Re: Why are banks still getting authentication so wrong?

#282
post #228

Earlier quoted context omitted.

People get new phones and new phone numbers. Frequently, compared to landline days. The alternative is to be permanently locked out of everything if you get a new phone number.

Well, I’m not doing business with a company that trusts any random phone carrier’s identity assertion more than me in determining what is and isn’t my phone number, so I guess it works out nicely. And if a company can’t be bothered to have a fallback verification flow in case I do lose access to my phone number somehow, that doesn’t increase confidence either. I’m a person, not a phone number.

So, if I may ask, do you have a smartphone? What kind and who is your carrier? It seems to me your stance would preclude owning a smartphone?

Re: Why are banks still getting authentication so wrong?

#283
post #120

Earlier quoted context omitted.

And it is a significant flaw of the US model!

Not if you ask people who specifically don’t want the government tracking everything

The government is already tracking things like your financial investments. Except now, they're doing it in a disconnected and sprawling way, centered around your SSN. Which is insecure.

I'm very paranoid about tracking and privacy, but the reality is that identity verification is just a necessary part of some services. Like opening a brokerage account, or riding a plane. So, if we HAVE to do it, we should have a more secure way of doing it. There's no reason we should be relying on easily-gathered 9 digit numbers.

Re: Why are banks still getting authentication so wrong?

#284
post #263

Earlier quoted context omitted.

You can’t have privacy if everyone uses the government as an SSO. People might be more amenable if SSO wasn’t implemented as these stupid OIDC flows where the govt gets to know every time you login to your bank and what IP you’re using, etc.

> You can’t have privacy if everyone uses the government as an SSO. Why not? Anonymous cryptographic attestation methods (e.g. of only the fact that you are over 18 years old, that you are a permanent resident etc.) exist.

Mozilla's one died a death

Re: Why are banks still getting authentication so wrong?

#285

> I don’t think anyone considers a bank account “low-risk.” Yet here we are, still relying on SMS as the default, and sometimes only, 2FA option > Passkeys (FIDO2/WebAuthn): Phishing-resistant, device-based login using biometrics. Excellent UX and security. In response to the complaints about SMS MFA, yeah, it has its issues (we don't even support it in our auth software) but it's not totally indefensible. It makes i…

I. don't. care. Because we have to cater to the absolute lowest denominator, I now can't use my credit card 90% of the time because I can't receive SMS when I'm traveling aboard? No, not everyone has a fking iPhone and iMessage. Nothing in your comment serves as a defense of most places only having SMS 2FA. Why can Capital One email me every critical account notification, but can't email me 2FA/OTP codes for confirmi…

You need to switch to a carrier that allows international roaming, preferably at no cost. A lot of the budget carriers like Mint don't. Those carriers are really really good, like truly 99% of the way there, but for very specific use-cases they have problems.

Re: Why are banks still getting authentication so wrong?

#286

Earlier quoted context omitted.

If only there was tamper-proof, cryptographically secure chip in everyone's pockets, coupled with a handheld device that can wirelessly "read" that chip.

If it's in your pocket, then you might leave it in your other pants. Better to just have that chip embedded in your palm. You can even fashion it with LEDs that change color with your age. When you reach 30, you can then be told your Last Day has arrived and they are ready for Carrousel. I'm sure we can fold in plenty of other sci-fi tropes all at the same time too

Listen if Jenny Agutter is involved, count me in!

Re: Why are banks still getting authentication so wrong?

#287
post #263

Earlier quoted context omitted.

You can’t have privacy if everyone uses the government as an SSO. People might be more amenable if SSO wasn’t implemented as these stupid OIDC flows where the govt gets to know every time you login to your bank and what IP you’re using, etc.

> You can’t have privacy if everyone uses the government as an SSO. Why not? Anonymous cryptographic attestation methods (e.g. of only the fact that you are over 18 years old, that you are a permanent resident etc.) exist.

It’s technically possible but none of the govt implementations I’ve seen do this.

Re: Why are banks still getting authentication so wrong?

#288
post #182

Earlier quoted context omitted.

You can’t have privacy if everyone uses the government as an SSO. People might be more amenable if SSO wasn’t implemented as these stupid OIDC flows where the govt gets to know every time you login to your bank and what IP you’re using, etc.

But you can if you live in a well functioning democratic society - remember the alternative is not no id but privatized for profit identity providers like Google and Facebook.

A well functioning democratic society is one of the valid states before an autocratic regime. The Nazi party was elected.

Apart from regime changes, being a functional democratic society doesn’t protect you from technical incompetence nor does it limit the ability for people with access to the DB from abusing it.

Re: Why are banks still getting authentication so wrong?

#289

Earlier quoted context omitted.

Not if you ask people who specifically don’t want the government tracking everything

The government is already tracking things like your financial investments. Except now, they're doing it in a disconnected and sprawling way, centered around your SSN. Which is insecure. I'm very paranoid about tracking and privacy, but the reality is that identity verification is just a necessary part of some services. Like opening a brokerage account, or riding a plane. So, if we HAVE to do it, we should have a more…

Riding on a plane doesn’t require centralized identification. Well at least it didn’t until real ID, but flying was perfectly fine without it before.

Re: Why are banks still getting authentication so wrong?

#290
post #264

Earlier quoted context omitted.

Not if you ask people who specifically don’t want the government tracking everything

Ironically, lax to nonexistent data privacy laws and the ubiquitous use of SSNs as globally unique identifiers are achieving exactly the outcome that the lack of government ID verification purportedly achieves.

You don’t need an externally generated globally unique ID verified by the government.
Post reply on HN