Live data from Hacker News

Why are banks still getting authentication so wrong?

jamal.haba.sh

311–320 of 375 posts

Re: Why are banks still getting authentication so wrong?

#311

Earlier quoted context omitted.

My rule is simple: if you contact me, you are the one that had to authenticate. Otherwise you are probably a scammer. Although, I haven’t had many instances of communications from my bank where I cared about them authenticating. Like, if they tell me there is a problem, I can go check it out through the app, website, or whatever the user-initiated channel is. When I feel like it.

I don’t have a good way to authenticate someone is calling from the bank on my end. I ask what the basic issue is, then call the general bank number (or a number to their department, which I validate online before calling it). That way I’m initiating the call to a trusted number, and they can go through their process to authenticate me. Every time I’ve done this the person calling has understood and seemed to appreci…

> I don’t have a good way to authenticate someone is calling from the bank on my end.

You could ask them to list your last 3 transactions, and their exact amounts. Easy to cross-reference by looking at your banking website / app.

Re: Why are banks still getting authentication so wrong?

#312

Earlier quoted context omitted.

How do you authenticate them? I've never heard of this, I'm very curious.

I can’t, lol. It is a roundabout way of saying I ignore who organizations claim to be when they contact me.

I don't know what your point is then. I've gotten important calls about fraud that it was certainly in my interest not to ignore. And it's easy to call back to verify it's the bank.

Re: Why are banks still getting authentication so wrong?

#313
> A modern authentication flow in 2025 should be built around strong, user-friendly, standards-based mechanisms: > Passkeys (FIDO2/WebAuthn): Phishing-resistant, device-based login using biometrics.

Maybe I'm missing something, but I heard that using biometrics for authentication was found bad some years ago and other ways for that were required?

Re: Why are banks still getting authentication so wrong?

#314

Also, they still expect you to authenticate when they phone you. No, I'm not going to tell you my birthday when you phone me. No wonder so many people get scammed, when banks are training people on how to get scammed.

Ask for a case number, write it down, hang up, call the number on your card, say you have a case number.

I know to do that. Most don't, but shouldn't need to, the bank should be telling people to do it.

Re: Why are banks still getting authentication so wrong?

#315

Earlier quoted context omitted.

I don’t have a good way to authenticate someone is calling from the bank on my end. I ask what the basic issue is, then call the general bank number (or a number to their department, which I validate online before calling it). That way I’m initiating the call to a trusted number, and they can go through their process to authenticate me. Every time I’ve done this the person calling has understood and seemed to appreci…

> I don’t have a good way to authenticate someone is calling from the bank on my end. You could ask them to list your last 3 transactions, and their exact amounts. Easy to cross-reference by looking at your banking website / app.

Unless the system you use the check that balance is compromised on your end or their end. If you have malware, they can be looking at the same numbers you’re looking at, so that isn’t fool-proof. If your account is already compromised, they may just be phishing for 2fa tokens to initiate some kind of account change, like the kind that would complete their total account takeover, at least until you or the bank notices suspicious activity.

Re: Why are banks still getting authentication so wrong?

#316

Earlier quoted context omitted.

The government is already tracking things like your financial investments. Except now, they're doing it in a disconnected and sprawling way, centered around your SSN. Which is insecure. I'm very paranoid about tracking and privacy, but the reality is that identity verification is just a necessary part of some services. Like opening a brokerage account, or riding a plane. So, if we HAVE to do it, we should have a more…

Riding on a plane doesn’t require centralized identification. Well at least it didn’t until real ID, but flying was perfectly fine without it before.

Actually, it does. They verify who you are before they let you board, even if you don't bring ID documents.

Re: Why are banks still getting authentication so wrong?

#317
post #183

Earlier quoted context omitted.

Birthdates are frequently asked in US health settings not as a protection against attack, but as a protection against mistake . They are not worried that someone is going to come in, and steal your appointment. They are worried that someone with the same name as you might show up on the same day and the doctor might treat the wrong patient with the wrong information. This is an completely different risk profile than…

This is a realer problem than some realize. I have the same name as my father (first and last, , different middle). We live at the same address. It’s a small town so we share a lot of the same doctors. We use the same pharmacy. For just a bit of extra spice are birthdays are only two days apart.

This is how we unintentionally found a relative of my former girlfriend. Went to a small pharmacy to pick up medicine for DF, where the F is a really weird last name. They were like I just filled that, reached back and grabbed it and set it on the counter. I noticed it was the wrong address...

A person she hadn't seen or talked to in 20 years had moved to this town neither of them were from and named their kid the same name.

Re: Why are banks still getting authentication so wrong?

#318
post #119

Earlier quoted context omitted.

Show up in person with ID.

That's not necessarily possible. Many banks do not have physical locations, and many people do banking business while physically away from a bank. https://en.wikipedia.org/wiki/Direct_bank

We're talking about recovery mechanisms, not day to day regular banking interactions. Ultimately, if there isn't a physical branch you can show up to easily, your access recovery time might be pretty inconvenient. This would be a good thing to consider when selecting a bank.

Re: Why are banks still getting authentication so wrong?

#319
post #132
post #119

Earlier quoted context omitted.

Show up in person with ID.

Yes, but remember, the original scenario was person leaving Canada, and trying to use their Canadian bank account from the US. There is nowhere to show up. But, if they could swallow SMS roaming costs temporarily, they could access to their account easily.

> There is nowhere to show up.

There's Canada. And yes, re-enabling a SIM and paying a handful of roaming SMS charges might easily be more convenient than traveling to Canada.

Re: Why are banks still getting authentication so wrong?

#320
post #292

Earlier quoted context omitted.

cryptocurrency makes traditional banking obsolete only if: 1. you don't understand what banks do, or 2. you pretend that cryptocurrencies do things that they don't One could make a list a mile long of things that banks do that cryptocurrencies have no answer for. Banking is not a technology, it is a service.

Maybe try to make a list of 1 or 2 things instead of a mile.

Since we're on the topic of authentication, how about the fact that they are not recoverable? You cannot reset a password on the blockchain, nor can you call the blockchain and prove you are the rightful owner of any inaccessible/stolen funds, nor can you take the blockchain to court to return your funds. You are SOL.

Just about any service that banks do are great examples of other things that math itself cannot do for you. These are all reasons that people still overwhelmingly use banks.

Banks do work to integrate with other societal systems in meatspace, build infrastructure, manage exceptions, comply with legal expectations, provide service, build and maintain partnerships, etc. Cryptographic ledgers don't do any of this, they are inanimate.

Post reply on HN