Live data from Hacker News

Why are banks still getting authentication so wrong?

jamal.haba.sh

321–330 of 375 posts

Re: Why are banks still getting authentication so wrong?

#321

Earlier quoted context omitted.

The passcode to call your bank for basic customer service probably shouldn’t be the same passcode that lets people spend money on your account. Even TOTP is better than this.

Why not? Basic customer service lets you do things like transfer money too, so you need something just as secure as a PIN. So why would you want two different security mechanisms? Either it's you or it's not.

In the UK customer service absolutely cannot transfer money

The banking system is so backwards in the US it's actually insane, you've just got used to it

Re: Why are banks still getting authentication so wrong?

#323
post #318

Earlier quoted context omitted.

That's not necessarily possible. Many banks do not have physical locations, and many people do banking business while physically away from a bank. https://en.wikipedia.org/wiki/Direct_bank

We're talking about recovery mechanisms, not day to day regular banking interactions. Ultimately, if there isn't a physical branch you can show up to easily, your access recovery time might be pretty inconvenient. This would be a good thing to consider when selecting a bank.

Online only banking is fairly popular for traditional banking services, and wildly popular when you consider money transmitters, lenders, and investment brokerages.

Whatever the problem you think they have with authentication resets -- much of the financial market seems to have solved the problem well enough without in-person resets to have successful mainstream businesses.

Re: Why are banks still getting authentication so wrong?

#324
Very few organisations get international use cases right. Want to load that public transport app for the city you’re spending three months in? Sorry, only available if your phone is tied to the local App Store. Use an international number as your primary contact number? No chance. &etc &etc

Re: Why are banks still getting authentication so wrong?

#325

Earlier quoted context omitted.

Recently had to call Discover because of unauthorized use of card, apparently to buy Facebook ads of all things. They didn't call me, just locked my account and said I had to call them. I couldn't even pay the balance until I did. Anyway they needed to verify my identity, so they ask me for some info from the back of the card and a phone number that they can send the OTP to. I give them a phone number, it's not even…

Background check for a new employer resulted in me getting an email to my personal account: "Hi, I'm XYZ from XYZ background checks, I'm conducting your pre-employment check, and I just want to confirm that your full name is V, your DOB is W, your place of birth is X, your address is Y and your full SSN is Z... ... and that this is the correct email address for you. Please confirm." Holy hell. Thankfully I reached ou…

Hah, my employer in Sweden recently started using one of these security training companies. They send you emails with some online courses you're supposed to do and then send occasionally phishing attempts etc. and when you fall for one they send you an email what you did wrong.

Out of interest I clicked on the link in one of their "phishing" emails and I was redirected to a link where they essentially told me "never click on links in emails, you never know where they lead to". One week later I get an email "please click on this link to complete the second part of your course". Obviously I never completed their course, they told me never to click on links.

What's even worse is that they don't even use their own domain for the courses, but some random looking domain.

Re: Why are banks still getting authentication so wrong?

#326
post #190

Also, they still expect you to authenticate when they phone you. No, I'm not going to tell you my birthday when you phone me. No wonder so many people get scammed, when banks are training people on how to get scammed.

I had a revelation this year, I have a new bank acc and not familiar with their procedure. First few calls they did to me, they have asked some good questions, aside from my name thy were negative - e.g. did you do X thing in your app, when we both know that I did not. But then last time an operator called and asked my PII question (birthday, address etc.). I got triggered and said "eh, sorry, won't tell you because…

Banking is pretty disfunctional in Sweden. Lots of bank employees seem not to want to work, i.e. they were refusing to open a bank account for me on an EU passport until I asked for written confirmation (which they have to give by law), when suddenly it wasn't a problem anymore (colleague went to the same bank some months later, same employee, was told the same thing, so it's not that they don't know the rules). That said, they do have authentification down. Essentially you use your mobile bank id (an app that you connected via your id card) and when they need to authenticate you they push an notification to your phone that you confirm (using a PIN). Only annoying thing is that mobile bank id only works on android and ios.

Re: Why are banks still getting authentication so wrong?

#327
post #228

Earlier quoted context omitted.

Well, I’m not doing business with a company that trusts any random phone carrier’s identity assertion more than me in determining what is and isn’t my phone number, so I guess it works out nicely. And if a company can’t be bothered to have a fallback verification flow in case I do lose access to my phone number somehow, that doesn’t increase confidence either. I’m a person, not a phone number.

So, if I may ask, do you have a smartphone? What kind and who is your carrier? It seems to me your stance would preclude owning a smartphone?

The parent's gripe is presumably about many bad SMS-based 2FA implementations banning non-post-paid numbers from use.

E.g. Blizzard (assuming they still do this)

If they want to be aggressive about fraudulent activity, fine, but don't restrict perfectly valid phone numbers from being used in their required 2FA scheme.

Re: Why are banks still getting authentication so wrong?

#328

Earlier quoted context omitted.

When calling my bank I have to enter my entire CC number AND my PIN code. Talk about training people to give away sensitive data.

What is the issue? That's literally just your account number and the password. That's what you're supposed to do. That's what security is. That's the sensitive data that ensures it's not a rando calling who stole your card. I'm not sure what alternative you are looking for? You're the one calling them, so it's fine.

It's teaching people to handover their pin code on the phone. It goes against their own security advice of never handing over CC details on the phone

> You're the one calling them, so it's fine.

Again, normalizing handing over complete CC details on the phone makes it much easier for scammers calling to succeed in asking for those details.

Re: Why are banks still getting authentication so wrong?

#329
This is not universally a problem. In switzerland you receive a letter with a qr code, which with your username/password can activate a app which does a 2nd factor authentication, but it also requres to scan an qr code from thd web every time you login.

Setting it up is a pain, also it‘s impossible to transfer to another device without the original barcode.

But it seems pretty convinient for me an very secure. Login with account-id and password, scan a qr-code with the app and verify the login in it.

Still phone communication is very insecure…

Re: Why are banks still getting authentication so wrong?

#330

Can we get rid of the password expiration too? Requiring that users change their perfectly secure password every 6 months is absurd and gives the impression of security when in reality it only makes things worse.

It indicates they are using good security practices that are no longer considered good. They might be living in 2010 which is worrying on its own.
Post reply on HN