Live data from Hacker News

The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

blog.opencore.ch

31–40 of 64 posts

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#31
> Thieves actively exploit this by “shoulder surfing” a victim’s iPhone passcode before stealing the device

If someone is using biometrics how often are they really using their pin that this would at all be a valuable tactic? I very rarely actually need to enter my pin on my phone so this largely seems like a moot point?

Like yeah it is still technically possible but if we really get down to it, if someone were to get learn the pin than passkey is equally worthless since they could also use my phone then to authenticate anything passkey. Fairly surprised that software based passkeys are just skipped here since I doubt most people are using hardware based passkeys, particularly on mobile devices.

I think there is a bigger (not just banking) discussion to be had about what can be done your phone's pin. But with the convenience of biometrics set an actually strong password for your phone instead of a 4 or 6 digit code.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#32
post #2

This is not a compelling argument that 2FA is reduced to 1FA. You need either: something you have (phone) and something you are (face), OR something you have (phone) and something you know (passcode). In either case, there are still two factors. For a criminal to perform shoulder surfing and theft, more things must go right for them than to do either individually.

If your phone is compromised, a single password entry gives hackers full access. How is this not 1FA?

Phone is something they have, password is something they know, once you tell them.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#33

Earlier quoted context omitted.

> something you have (phone) and something you are (face), OR something you have (phone) and something you know (passcode). Thank you for breaking it down like this. The bottom line is that if you don’t have your phone, you can’t access your accounts. That is a massive risk factor - particularly while traveling. That tells me that passkeys and password managers are not a viable security solution.

Exactly, your phone can break or get stolen any time. Plus I just don't want to limit myself to a single device.

Unfortunately in Germany almost all banks force you to use an unmodified phone (so no de-Googled) Android as the 2FA. There are other solutions like code generators but they require extra payment.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#34
post #29

The article starts with this description of 2FA: > an electronic authentication method in which a user is granted access to a website or application only after successfully presenting two or more distinct types of evidence (or factors) to an authentication mechanism. and concludes with (emphasis mine): > For the average user, the smartphone has become a single point of failure, where the theft of one device and one p…

The issue I'm having with this sort of "something you own and something you know/are" two-factor authentication is that it has some potential to cause violence - both can be beaten out of you: https://www.citizen.co.za/network-news/lnn/article/banking-a...

What can't though?

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#35
post #32

Earlier quoted context omitted.

If your phone is compromised, a single password entry gives hackers full access. How is this not 1FA?

Phone is something they have, password is something they know, once you tell them.

Imagine somebody owned your phone remotely. Aren't you immediately screwed? This is something I don't expect from 2FA.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#36
post #34
post #29

Earlier quoted context omitted.

The issue I'm having with this sort of "something you own and something you know/are" two-factor authentication is that it has some potential to cause violence - both can be beaten out of you: https://www.citizen.co.za/network-news/lnn/article/banking-a...

What can't though?

A TAN generator or security key stored in a drawer at home. At least it reduces the opportunities for theft since people don't carry these devices with them all the time as opposed to their phones. Opportunity makes the thief.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#37
post #36
post #34

Earlier quoted context omitted.

What can't though?

A TAN generator or security key stored in a drawer at home. At least it reduces the opportunities for theft since people don't carry these devices with them all the time as opposed to their phones. Opportunity makes the thief.

Yeah I often think the issue with cash and crypto is that it can be easily forced away from an individual by any sufficienty armed and unscrupulous party. Money in a financial institution tends to have an upper limit on what could be forced away in a single act, or at least a single transction cycle.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#38

Earlier quoted context omitted.

> something you have (phone) and something you are (face), OR something you have (phone) and something you know (passcode). Thank you for breaking it down like this. The bottom line is that if you don’t have your phone, you can’t access your accounts. That is a massive risk factor - particularly while traveling. That tells me that passkeys and password managers are not a viable security solution.

Exactly, your phone can break or get stolen any time. Plus I just don't want to limit myself to a single device.

Buy an older iPhone for ~$150. Install financial apps on it and don't use it for anything else. Keep it in a safe place, only carry it around if you must.

If you need to manage non-trivial amounts of money through your phone, having a specific device to do that is a no-brainer.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#39
post #29

The article starts with this description of 2FA: > an electronic authentication method in which a user is granted access to a website or application only after successfully presenting two or more distinct types of evidence (or factors) to an authentication mechanism. and concludes with (emphasis mine): > For the average user, the smartphone has become a single point of failure, where the theft of one device and one p…

The issue I'm having with this sort of "something you own and something you know/are" two-factor authentication is that it has some potential to cause violence - both can be beaten out of you: https://www.citizen.co.za/network-news/lnn/article/banking-a...

This is true with 1FA too. 2FA is more effective at stopping the case where you're hacked and you don't even know it because your password was in a leak.
Post reply on HN