Why are banks still getting authentication so wrong?
331–340 of 375 posts
Re: Why are banks still getting authentication so wrong?
#332Some banks do it properly. For example, my local credit union does Google Authenticator (actually TOTP, but they call it Google Authenticator). I use it with Authy on F-Droid.
Please do not use Authy, lacks essential features and it was bought by a bad actor.
Re: Why are banks still getting authentication so wrong?
#333Part of the reason I have the cellphone plan I do, despite knowing I'll get an esim any time I travel is so I have the option to get SMS 2FA while traveling if I need to access something.
Re: Why are banks still getting authentication so wrong?
#334Can we get rid of the password expiration too? Requiring that users change their perfectly secure password every 6 months is absurd and gives the impression of security when in reality it only makes things worse.
One hundred percent. I’d be interested to see how many people resort to having weaker passwords just to try to remember the new password every 6 months. I know many folks are proud of their password ‘system’ of using the same word and adding different numbers every time they need to change it. Not helpful.
I keep a long list of strong passwords and some 50 pins in my head, at least I think I do.
I know a guy who regularly gets locked out of things. It's a terrifying process. Everything unravels.
Re: Why are banks still getting authentication so wrong?
#335Earlier quoted context omitted.
This is fine for services you can easily access on a phone or computer. My employer requires I change my laptop password every 60 days, it stores the last 2 years of passwords to prevent reuse. I am not opening up LastPass and plugging in a 32 character random string every time I want to start my computer up. My password at any given point is either a few random words and a number, or a short (8-12 character) alphanu…
The only solution to this problem is to put your password on a post-it note in the most obvious place possible? Are we sure the CISO is the idiot in this story? This sounds like malicious negligence. I sure hope nothing that actually matters is on your system.
Re: Why are banks still getting authentication so wrong?
#336I don't care how many times I am violently buried on this site for mentioning the word -- but cryptocurrency makes traditional banking obsolete. Or should have.
> but cryptocurrency makes traditional banking obsolete.
Most banks we interact with were obsolete before crypto.
When working there I had a lot of "why" questions until someone explained me "You need to think about banks basically as an extension of the state".
From a tech POV it is exactly what we usually hear: there is a ~50 year old legacy core banking system that nobody really understand but keep working almost miraculously. Everything else beyond that is trash.
Cryptocurrencies pop up in a weird way and obliviously did not delivered since.
In 2025, it is still hard and costly to transact on Bitcoin or Ethereum. If it wasn't govs would have unleashed the fury on crypto.
> Or should have.
Yes our banking system is failing society and preventing progress since at least 2008.
Crypto was our chance to move beyond but it didn't happen. Bitcoin price is probably just reflect the fact that our banking system is at risk of collapsing any time soon and crypto might be (part of) the solution.
> I don't care how many times I am violently buried on this site for mentioning the word
Yes crypto shouldn't be taboo on HN. It is a potential solution for what most people need urgently (more than AI) so it should be discussed.
Re: Why are banks still getting authentication so wrong?
#337Earlier quoted context omitted.
italy has quite an interesting system[0] where multiple identity providers (authorized by the State) can be used to provide identification against the central database. It'll probably be phased out at some point, but it's quite cool. [0] https://www.spid.gov.it/en/citizens/ it integrates with eIDAS too
If it integrates with eIDAS, it doesn't necessarily have to be phased out. A very good pragmatic decision of eIDAS was recognizing that many member countries have different existing eID schemes, and federating them is easier than rolling out a new one from scratch.
Re: Why are banks still getting authentication so wrong?
#338Earlier quoted context omitted.
Maybe try to make a list of 1 or 2 things instead of a mile.
Since we're on the topic of authentication, how about the fact that they are not recoverable? You cannot reset a password on the blockchain, nor can you call the blockchain and prove you are the rightful owner of any inaccessible/stolen funds, nor can you take the blockchain to court to return your funds. You are SOL. Just about any service that banks do are great examples of other things that math itself cannot do f…
The primary things that people use them for, to store money or sometimes distribute it, or act as a system of record, have been made obsolete though.
Re: Why are banks still getting authentication so wrong?
#339When users accidentally deleted these apps or switched devices, they often lost access to their TOTP tokens, leading to a flood of support requests. Banks tried to "fix" that by integrating TOTP directly into their own apps.
This allows bank a sort of token persistence (and user tracking, and being able to send push notifications, wanted or not).
Re: Why are banks still getting authentication so wrong?
#340Earlier quoted context omitted.
Then you make Google/iCloud the point of entry to someone's bank account. That completely changes the threat model for customers, and possibly for worse than SMS. Offline backup codes, when printed, isn't such a bad idea. But when you lose that piece of paper, again, game over. SMS is fantastically resilient to these scenarios. There's a reason banks insist on using it.
SMS isn't resilient to the worker at the local retail store for the phone carrier giving someone else a SIM for my phone number. That's a much bigger threat vector than Google/iCloud/a sync target I manage storing an encrypted version of the TOTP credentials.
[0] and half a year later the bank would finally found out about and block the SIM 'to prevent fraud' at the most inconvenient time. But again, it's solvable with a visit to the office and an ID.