Live data from Hacker News

Why are banks still getting authentication so wrong?

jamal.haba.sh

371–375 of 375 posts

Re: Why are banks still getting authentication so wrong?

#371

Earlier quoted context omitted.

The only bit we're lacking is the "tied to one's bank account". The rest already exists in the form of yubikeys and other hardware security tokens.

Your bank/credit/debit/etc. card is a “physical token with a crypto key that is protected by a password and tied to one's bank account”. FIDO and EMV even both use the same underlying ISO/IEC 7816 and 14443 protocols for communications.

Ah! I forgot about my debit card. I only use it ~once per month. Yeah, we'd need an additional piece of hardware to be able to connect it to our computers but that also could enable doing chip-based transactions over the internet so I think it would absolutely be worth it.

Re: Why are banks still getting authentication so wrong?

#372
Worse yet is when banks tie authentication notifications to the ability to send you marketing and advertising permissions. My bank's app was sending me weekly marketing messages, and the only way to stop that was to go back to SMS 2FA.

I wish Apple (and Google, I presume) would actually enforce their app store guidelines and at least threaten to ban apps that do this. That seems like the only thing that'd actually have traction.

Re: Why are banks still getting authentication so wrong?

#373
post #167

Earlier quoted context omitted.

This is fine for services you can easily access on a phone or computer. My employer requires I change my laptop password every 60 days, it stores the last 2 years of passwords to prevent reuse. I am not opening up LastPass and plugging in a 32 character random string every time I want to start my computer up. My password at any given point is either a few random words and a number, or a short (8-12 character) alphanu…

> because the CISO is an idiot. How do these people get these jobs? I have 25 years of enterprise-level web application development experience. I passed the CISSP on my first try with minimal study. I read RFCs for fun. And yet I can't even get a screening interview with an actual human (although my one AI interview asked surprisingly competent follow-up questions).

> How do these people get these jobs?

Relationships.

Re: Why are banks still getting authentication so wrong?

#374

Earlier quoted context omitted.

That's horrible but why would it be worse together with an e-id system?

Because without thoroughly-enshrined protections for identities, an e-ID system provides an avenue for the government to effectively de-person undesirables at will, by removing their ability to use banks, sign contracts, access healthcare, etc.

Isn't that what permit of residency and citizenship already is? Without legal residency or citizenship all those things become hard/impossible/illegal. It's not personhood, it's citizenship (or a permit of residency). It's the job of governments everywhere?

Re: Why are banks still getting authentication so wrong?

#375
post #308

Earlier quoted context omitted.

>This problem is solved in China It isn't. China is the best example that draconian identity verification / KYC processes don't stop scammers.

could you explain more? im always under impression that chinese scam/fraud are rare. what keywords should i search for?

Most scams in China are a mix of romance and investment scams.

Since WeChat allows accounts created outside of China, it's these accounts that are used. And it's why there are times it's a pain to create a WeChat account outside of China.

The financial transactions all take place outside of WeChat.

Post reply on HN