Live data from Hacker News

Why are banks still getting authentication so wrong?

jamal.haba.sh

351–360 of 375 posts

Re: Why are banks still getting authentication so wrong?

#351
This blog post exposes the badness of SMS-based recovery. I think other recovery options such as Yubikey aren't ideal either, as a Yubikey may simply stop working and you're completely locked out. The specific situation the author of the blog post isn't dramatic - he can't receive SMS - personal decision to avoid roaming charges.

But in all seriousness, if there's an authentication recovery standard, it should serve all people including those who are in seriously difficult circumstances (e.g. homeless or ill). The question then is what should recovery look like in those cases.

To me it looks like good old recovery code on paper is the best solution, as it doesn't depend on ever-changing device ports, or hardware malfunction due to lack of use long-term (such as 10-15 years).

I wonder whether authentication apps nowdays address that aspect and make and I kinda doubt so (i.e. can you print out a QR code with all account information in your typical TOTP app?).

Re: Why are banks still getting authentication so wrong?

#352

The friction of changing bank accounts is high, and few people choose their bank accounts based on how easy the online authentication is. Unless a bank does this meaningfully much worse than their competitors (low bar) they have little incentive to fix it. If you think TD is bad, try some European countries where there's only a handful of banks...

According to https://2fa.directory/us/#banking there are 3 banks in the US that support hardware 2FA (without limitations like requiring a Symantec token or only being available to "high risk" clients): BofA, Morgan Stanley, and Mercury.

Of these three, Mercury isn't really a bank, it's a non-bank financial institution (and as the bankruptcy of Synapse shows, putting your money into these services can be risky), Morgan Stanley has zero locations within a 1 hour drive (important for when I need cashiers checks or need to deposit checks that mobile apps can't handle), and BofA's interest rates are laughable.

There's no FDIC-insured bank which has decent savings accounts, physical branches near me, and supports proper hardware 2FA. The best I can get is savings, location, and (the bank's app-based) software 2FA.

There truly is no incentive for the banks to improve, and I don't think anything will unless congress forces their hands (which seems unlikely, given that the average person has never suffered an SMS 2FA-based attack on their finances and thus has no reason to write to congress about it).

Re: Why are banks still getting authentication so wrong?

#353

The friction of changing bank accounts is high, and few people choose their bank accounts based on how easy the online authentication is. Unless a bank does this meaningfully much worse than their competitors (low bar) they have little incentive to fix it. If you think TD is bad, try some European countries where there's only a handful of banks...

According to https://2fa.directory/us/#banking there are 3 banks in the US that support hardware 2FA (without limitations like requiring a Symantec token or only being available to "high risk" clients): BofA, Morgan Stanley, and Mercury. Of these three, Mercury isn't really a bank, it's a non-bank financial institution (and as the bankruptcy of Synapse shows, putting your money into these services can be risky), Morg…

My credit union supports TOTP authenticators, via their web and mobile apps alike. I use Google’s app.

Re: Why are banks still getting authentication so wrong?

#354
post #236
post #191

Earlier quoted context omitted.

BoA is one of the very few US banks that do any modern auth - they support fido2 security keys. Of course effectively 0% of their customers actually use it, and instead rely on sms

Huh I set up SMS 2FA for BofA back in 2016 and I never knew they now support fido2.

They don't let you get rid of sms fallback, so it's not immune to sim theft

It does help vs phishing though

Re: Why are banks still getting authentication so wrong?

#355
post #137

Earlier quoted context omitted.

SMS isn't resilient to the worker at the local retail store for the phone carrier giving someone else a SIM for my phone number. That's a much bigger threat vector than Google/iCloud/a sync target I manage storing an encrypted version of the TOTP credentials.

How realistic is this threat? I would think that the employees would have to jump through hoops that require you to be present (or at least a lot more of your info to be stolen than just your name and number) and that the home network would detect a duplicate E.164 number with conflicting IMEI/IMSI numbers and locations pretty quickly.

FWIW: https://en.wikipedia.org/wiki/SIM_swap_scam

This is more like confused deputy than collusion (though that can happen as well), but nevertheless the end result is somebody else ends up with your number, and your device gets deactivated.

Re: Why are banks still getting authentication so wrong?

#356
post #183

Earlier quoted context omitted.

Birthdates are frequently asked in US health settings not as a protection against attack, but as a protection against mistake . They are not worried that someone is going to come in, and steal your appointment. They are worried that someone with the same name as you might show up on the same day and the doctor might treat the wrong patient with the wrong information. This is an completely different risk profile than…

This is a realer problem than some realize. I have the same name as my father (first and last, , different middle). We live at the same address. It’s a small town so we share a lot of the same doctors. We use the same pharmacy. For just a bit of extra spice are birthdays are only two days apart.

For sure, my dad lives in the same town as someone with the same (relatively uncommon) name as him who is roughly the same age. This causes confusion all the time with local services and organizations (especially since the other guy has had some, err, unflattering encounters with the legal system).

Re: Why are banks still getting authentication so wrong?

#358
post #259

Earlier quoted context omitted.

Well, a TPM would eliminate this user-hostile auth dance, although that security model is different than a password. Failing to recognize and channel human behavior into positive behaviors and outcomes does suggest a level of ignorance/arrogance outside of extreme situations. There’s probably a type of data one might handle to justify physical access threat models, but incompetence and out of date knowledge from thes…

I think it’s valid to question the wisdom of a CISO using misguided password guidelines. I don’t think it’s valid to respond to guidelines you disagree with by willfully sabatoging security. You relinquish your righteous position on password security when you put your password on a post-it in your laptop.

Reads like you are trying to argue for abstinence only education here. The reality security must operate in is that the best security policies are those that people don't circumvent.

If people have to resort to sticky notes, sharing credentials, scripts that automatically update a file containing a plaintext credential, or what have you, odds are that security has massively fumbled the ball.

Keep in mind this is already intuitive enough for everyone, even the security minded, within some set of social and or professional norms. No one uses one time pads for common password based authentications, nor do they rotate passwords daily, nor do they require 64+ characters. We don't do this because its obvious to everyone that business would be too great, and people simply would not comply. Many security teams seem interested in pushing that boundary as far as they can without regard to what the probability density function of compliance actually looks like.

I say this as my password for Nationwide Children's Hospital has officially become the first password to cross that line for me, and now lives in a paper notebook. Forced reset, 2FA mandated, requiring 15 characters, upper, lower, number, and special char (but only a subset of special chars).

Maybe its overkill that the place I go to fill out questionnaires about baby poop, has minimum password requirements such that the entire world's computer would take over 10,000 years to crack.

Re: Why are banks still getting authentication so wrong?

#359
post #269

Earlier quoted context omitted.

In the case of credit card payments this is true, but for checks and other P2P payments, there is no merchant to pass on costs to. For these, it's usually the banks absorbing the losses themselves (or their customers, if they aren't legally required to, but in many cases they are).

Check fraud is a relatively small percentage of all fraud. It's also pretty much a solved problem, it's expensive to cash a check anywhere but into a checking account in your name. If you write too many bad checks or try to deposit them you'll get banned from... the entire banking sector.

Yeah – because the US, until recently, didn't have push P2P payments via banks. The only thing you used to be able to do in your online banking was checking your account balance or maybe initiating wires (which are so expensive that manual review is probably not an issue).

Zelle is changing that and is, expectedly, running into a wall of fraud since banks don't have the authentication infrastructure/know-how to actually support it.

Re: Why are banks still getting authentication so wrong?

#360
post #52

Earlier quoted context omitted.

I had someone ask for my name. I told them my first and last name. They said it wasn't correct. After a few minutes of discussion, it turns out the person wanted my name as it appeared on my card , which is first name, middle initial, last name and a suffix. I told the person as feedback that what they asked for and what they wanted were two different things. I'm not optimistic that anything will change.

It will improve once we have AI smarter than agents who work for the wages banks pay for this. The weakness is in the processes and the lack of critical thinking skills of people executing processes.

About a year ago, I had a voice-based screening interview with an AI agent.

It asked better and more relevant follow-up questions than any other technical interview I've ever had with an actual human.

Post reply on HN