Live data from Hacker News

Why are banks still getting authentication so wrong?

jamal.haba.sh

341–350 of 375 posts

Re: Why are banks still getting authentication so wrong?

#341

Earlier quoted context omitted.

Background check for a new employer resulted in me getting an email to my personal account: "Hi, I'm XYZ from XYZ background checks, I'm conducting your pre-employment check, and I just want to confirm that your full name is V, your DOB is W, your place of birth is X, your address is Y and your full SSN is Z... ... and that this is the correct email address for you. Please confirm." Holy hell. Thankfully I reached ou…

Hah, my employer in Sweden recently started using one of these security training companies. They send you emails with some online courses you're supposed to do and then send occasionally phishing attempts etc. and when you fall for one they send you an email what you did wrong. Out of interest I clicked on the link in one of their "phishing" emails and I was redirected to a link where they essentially told me "never…

I'm a software dev. When I get phising mails I often click the links to check out what the scam is. I open in a separate browser I don't usually use, so there isn't anything in it for the phising site to gobble up. And yeah I trust that the browser sandbox I good enough, that no one is going to waste a zero day exploit on me in order to break it - hackers also have economic constraints. If I was working on something super sensitive, then I should use a vm, but I'm not so I don't.

I also did this at work, and yeah it was a fake phising mail sent by a security company, and I had to do a quick 20 min online course on email security best practices. Yay. Me and like 3 other dudes, who clearly all also understood it was phising and were just curious about the scam.

Re: Why are banks still getting authentication so wrong?

#343
post #175
post #76

Earlier quoted context omitted.

Absolutely not! The moment you have universal state-issued identity, you will be expected to provide it for everything , including tons of stuff that doesn’t require identity. Don’t be a privacy defeatist, the fight isn’t lost yet. Resist every single effort to make it easier for merchants and private entities to strongly identify users. The rows go into databases and they never go away. State-issued identity is one…

I'm so sick of retail clerks who insist on scanning the barcode of my driver's license. To verify I am 21 you don't need my height, weight, eye color, and home address. You can ascertain that my visually inspecting just the first two digits of my birth year.

Do they actually compare the picture on the driver's license to your face or do they only scan the barcode? In some cases the barcode is on the backside. I've many times seen that they don't even look at the side of the card with the picture. So you can just present a suitable barcode for them to scan. "Verification" indeed...

Re: Why are banks still getting authentication so wrong?

#344
post #341

Earlier quoted context omitted.

Hah, my employer in Sweden recently started using one of these security training companies. They send you emails with some online courses you're supposed to do and then send occasionally phishing attempts etc. and when you fall for one they send you an email what you did wrong. Out of interest I clicked on the link in one of their "phishing" emails and I was redirected to a link where they essentially told me "never…

I'm a software dev. When I get phising mails I often click the links to check out what the scam is. I open in a separate browser I don't usually use, so there isn't anything in it for the phising site to gobble up. And yeah I trust that the browser sandbox I good enough, that no one is going to waste a zero day exploit on me in order to break it - hackers also have economic constraints. If I was working on something…

When they introduced the weird fake phishing mails at my last work place I checked the email headers and just filed it into a separate folder. My coworkers were happy to get rid of the spam as well.

Just shows how bad they are at faking it.

Re: Why are banks still getting authentication so wrong?

#345
post #222

Earlier quoted context omitted.

> When calling my bank I have to enter my entire CC number AND my PIN code. YOU calling THEM is not an issue. That's the secure connection. There's not (afaik) a way to hijack the receiving phone number. The issue is when somebody calls YOU. Faking the originating number of a phone call is easy, happens all of the time. That's the scammer route.

There are absolutely ways to intercept a call from a targeted user that would be viable to use to gain access to a mid to high value user's funds. SS7 call routing and rogue 2G base stations are some potential approaches. In terms of banking security, a good (ideal) architecture would treat the user PIN as a credential which is not transmitted over insecure means. Unfortunately many banks don't do this right, and sti…

While this is true, this is a completely different threat model than most people face.

For 99% of people, 99% of the time, what they need to worry about is someone calling them suspiciously asking for key information.

The fact that targeted attacks like that exist does not make it a good idea to treat them as ubiquitous. People with the kind of money that would make executing such an attack worthwhile should be expected to take higher precautions than the rest of us with it.

Re: Why are banks still getting authentication so wrong?

#346

Does password requirements with short max length count as getting it wrong? Because I see that all the time. Also a password box that will accept more characters than the max password length.

How about one that accepts any length on create but truncates it in the DB so your password manager saves the long one you typed in when it’s actually cut off at 12 chars? Had that one recently.

That begs the question: are they truncating the password string before hashing it ... or truncating it and saving it plaintext?

I don't understand enforcing a max password length when the password should be stored as a hash.

Re: Why are banks still getting authentication so wrong?

#347

Also, they still expect you to authenticate when they phone you. No, I'm not going to tell you my birthday when you phone me. No wonder so many people get scammed, when banks are training people on how to get scammed.

Recently had to call Discover because of unauthorized use of card, apparently to buy Facebook ads of all things. They didn't call me, just locked my account and said I had to call them. I couldn't even pay the balance until I did. Anyway they needed to verify my identity, so they ask me for some info from the back of the card and a phone number that they can send the OTP to. I give them a phone number, it's not even…

Wells Fargo too. Every other banking institution says never to give an OTP to someone on the phone, but that's exactly how WF verifies you when you call them. The only thing is that they do text the number already on file with them, not a number you give them on the fly, but that's only microscopically more secure.

Re: Why are banks still getting authentication so wrong?

#348
post #259

Earlier quoted context omitted.

Well, a TPM would eliminate this user-hostile auth dance, although that security model is different than a password. Failing to recognize and channel human behavior into positive behaviors and outcomes does suggest a level of ignorance/arrogance outside of extreme situations. There’s probably a type of data one might handle to justify physical access threat models, but incompetence and out of date knowledge from thes…

I think it’s valid to question the wisdom of a CISO using misguided password guidelines. I don’t think it’s valid to respond to guidelines you disagree with by willfully sabatoging security. You relinquish your righteous position on password security when you put your password on a post-it in your laptop.

You call it "willfully [sabotaging] security," I call it "the best alternative that doesn't leave me with a 30% chance of forgetting my password every 60 days."

1Password is smart enough to let me have a secure, non-leaked password of high complexity that I have memorized, then let me go years without resetting it. I started there and the policies have made my laptop progressively less secure over time.

Re: Why are banks still getting authentication so wrong?

#349
post #29

Identity providing is a natural monopoly and should be provided by the state in same manner as a passport is provided. We can discuss the implementation but in Denmark and quite a few other countries, the login problem in online government services and banking is solved by a single state run identity provider (MitID) and hopefully the EU will be succesful with their EIDAS initiative and provide a solution that works…

Hard disagree. If the only the state can give you an identity, then the state can take away your identity.

Re: Why are banks still getting authentication so wrong?

#350
post #47

Earlier quoted context omitted.

This is no excuse for not offering it. And no, SMS must NOT be a backup that’s always available, as the article points out, its availability for use is a security hole. If you can’t access your actual 2FA there should be an option for the bank to have it call that registered number and ask you “Hey this is (Bank). Are you trying to log in right now from Moscow on a Windows 10 PC using Firefox? If so, please call the…

Recovery codes is an option, for one. Since we're talking about a legacy bank here, going to a branch and proving your identity is an option. Worst case, you could always call and speak to a human who will do whatever verification they do if you forgot your password, which is functionally equivalent.

Do TOTP authentication apps typically provide recovery codes option? Can they squash all of the added TOTP codes you have in the app into one code?
Post reply on HN