Live data from Hacker News

Why are banks still getting authentication so wrong?

jamal.haba.sh

331–340 of 375 posts

Re: Why are banks still getting authentication so wrong?

#331
There’s an additional dimension to this: the elderly are hopelessly confused by 2FA and how inconsistently it’s used or applied. 3D Secure auto has pretty much blocked my parents from making online purchases, and I spent a frustrating hour on the phone the other evening just talking them through a failed attempt to the find right authenticator app their bank in the Play Store in a sea of spoofs.

Re: Why are banks still getting authentication so wrong?

#332

Some banks do it properly. For example, my local credit union does Google Authenticator (actually TOTP, but they call it Google Authenticator). I use it with Authy on F-Droid.

Please do not use Authy, lacks essential features and it was bought by a bad actor.

Well that's a mistake. I'm using aegis but a neuron crossed and wrote the wrong word, and I can't edit my original post now

Re: Why are banks still getting authentication so wrong?

#333
Canadian banks are just horribly, terrifyingly stuck in the past for their security. For many years there was at least one Canadian bank where your online banking password was your phone password. So it had to be exactly 6 characters, and you could just as easily type in the word, or even the T-9 numbers related to them. The bank when I gave them this feedback didn't seem to understand why that was so terrible and just said, "Your money's covered if your account is hacked."

Part of the reason I have the cellphone plan I do, despite knowing I'll get an esim any time I travel is so I have the option to get SMS 2FA while traveling if I need to access something.

Re: Why are banks still getting authentication so wrong?

#334
post #25

Can we get rid of the password expiration too? Requiring that users change their perfectly secure password every 6 months is absurd and gives the impression of security when in reality it only makes things worse.

One hundred percent. I’d be interested to see how many people resort to having weaker passwords just to try to remember the new password every 6 months. I know many folks are proud of their password ‘system’ of using the same word and adding different numbers every time they need to change it. Not helpful.

If the website gets one of those it works. If they get multiple example of the password systeem in action, how hard would it be to guess elsewhere? You might not even remember that you've used one variation before.

I keep a long list of strong passwords and some 50 pins in my head, at least I think I do.

I know a guy who regularly gets locked out of things. It's a terrifying process. Everything unravels.

Re: Why are banks still getting authentication so wrong?

#335
post #167

Earlier quoted context omitted.

This is fine for services you can easily access on a phone or computer. My employer requires I change my laptop password every 60 days, it stores the last 2 years of passwords to prevent reuse. I am not opening up LastPass and plugging in a 32 character random string every time I want to start my computer up. My password at any given point is either a few random words and a number, or a short (8-12 character) alphanu…

The only solution to this problem is to put your password on a post-it note in the most obvious place possible? Are we sure the CISO is the idiot in this story? This sounds like malicious negligence. I sure hope nothing that actually matters is on your system.

Their job is onthere! Losing the job is much worse than losing the data. You need to secure that too!

Re: Why are banks still getting authentication so wrong?

#336
post #65

I don't care how many times I am violently buried on this site for mentioning the word -- but cryptocurrency makes traditional banking obsolete. Or should have.

After almost two decades my guess is we can start to look back at the whole cryptocurrency thing a bit more clearly.

> but cryptocurrency makes traditional banking obsolete.

Most banks we interact with were obsolete before crypto.

When working there I had a lot of "why" questions until someone explained me "You need to think about banks basically as an extension of the state".

From a tech POV it is exactly what we usually hear: there is a ~50 year old legacy core banking system that nobody really understand but keep working almost miraculously. Everything else beyond that is trash.

Cryptocurrencies pop up in a weird way and obliviously did not delivered since.

In 2025, it is still hard and costly to transact on Bitcoin or Ethereum. If it wasn't govs would have unleashed the fury on crypto.

> Or should have.

Yes our banking system is failing society and preventing progress since at least 2008.

Crypto was our chance to move beyond but it didn't happen. Bitcoin price is probably just reflect the fact that our banking system is at risk of collapsing any time soon and crypto might be (part of) the solution.

> I don't care how many times I am violently buried on this site for mentioning the word

Yes crypto shouldn't be taboo on HN. It is a potential solution for what most people need urgently (more than AI) so it should be discussed.

Re: Why are banks still getting authentication so wrong?

#337
post #265

Earlier quoted context omitted.

italy has quite an interesting system[0] where multiple identity providers (authorized by the State) can be used to provide identification against the central database. It'll probably be phased out at some point, but it's quite cool. [0] https://www.spid.gov.it/en/citizens/ it integrates with eIDAS too

If it integrates with eIDAS, it doesn't necessarily have to be phased out. A very good pragmatic decision of eIDAS was recognizing that many member countries have different existing eID schemes, and federating them is easier than rolling out a new one from scratch.

it doesn't, but there is already a competing system based on the national id card, which is just simpler to explain to people ("you log in with your ID card" vs "you log in with a third party identity provider where you need to create an account"), and the people who championed the old system are no longer around.

Re: Why are banks still getting authentication so wrong?

#338
post #292

Earlier quoted context omitted.

Maybe try to make a list of 1 or 2 things instead of a mile.

Since we're on the topic of authentication, how about the fact that they are not recoverable? You cannot reset a password on the blockchain, nor can you call the blockchain and prove you are the rightful owner of any inaccessible/stolen funds, nor can you take the blockchain to court to return your funds. You are SOL. Just about any service that banks do are great examples of other things that math itself cannot do f…

Hm. There are some things that banks do then that math can't do. But advanced cryptocurrencies have smart contracts that allow DeFi systems to handle many typical banking functions.

The primary things that people use them for, to store money or sometimes distribute it, or act as a system of record, have been made obsolete though.

Re: Why are banks still getting authentication so wrong?

#339
The main reason banks adopt in-app TOTP is that most third-party TOTP apps historically didn’t offer cloud backups. And some third-party TOTP apps could leak the tokens because the banks don't own their code.

When users accidentally deleted these apps or switched devices, they often lost access to their TOTP tokens, leading to a flood of support requests. Banks tried to "fix" that by integrating TOTP directly into their own apps.

This allows bank a sort of token persistence (and user tracking, and being able to send push notifications, wanted or not).

Re: Why are banks still getting authentication so wrong?

#340
post #137
post #122

Earlier quoted context omitted.

Then you make Google/iCloud the point of entry to someone's bank account. That completely changes the threat model for customers, and possibly for worse than SMS. Offline backup codes, when printed, isn't such a bad idea. But when you lose that piece of paper, again, game over. SMS is fantastically resilient to these scenarios. There's a reason banks insist on using it.

SMS isn't resilient to the worker at the local retail store for the phone carrier giving someone else a SIM for my phone number. That's a much bigger threat vector than Google/iCloud/a sync target I manage storing an encrypted version of the TOTP credentials.

If I lose my phone I can go to the office of my carrier, present my ID and receive a new SIM with the old number[0]. If Apple/Google decide what I'm not their customer anymore then I have literally zero ways to recover anything from them.

[0] and half a year later the bank would finally found out about and block the SIM 'to prevent fraud' at the most inconvenient time. But again, it's solvable with a visit to the office and an ID.

Post reply on HN