Live data from Hacker News

The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

blog.opencore.ch

41–50 of 64 posts

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#41
post #32

Earlier quoted context omitted.

Phone is something they have, password is something they know, once you tell them.

Imagine somebody owned your phone remotely. Aren't you immediately screwed? This is something I don't expect from 2FA.

Depends on details... I might not be screwed until I need to auth for something, at which point the auth is captured and I'm screwed.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#42
post #41

Earlier quoted context omitted.

Imagine somebody owned your phone remotely. Aren't you immediately screwed? This is something I don't expect from 2FA.

Depends on details... I might not be screwed until I need to auth for something, at which point the auth is captured and I'm screwed.

And you do need to do it from time to time. So it's only 2FA against some threats, not necessarily most important ones for ordinary users.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#43
post #31

> Thieves actively exploit this by “shoulder surfing” a victim’s iPhone passcode before stealing the device If someone is using biometrics how often are they really using their pin that this would at all be a valuable tactic? I very rarely actually need to enter my pin on my phone so this largely seems like a moot point? Like yeah it is still technically possible but if we really get down to it, if someone were to ge…

I use a PIN to unock because of legal rulings as you cannot be compelled to give your PIN (5th Amendment applies because it's "testimonial") but you can be compelled to use biometrics (5th does not apply).

Individual apps I use biometrics except on reboot if they support that.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#44
post #41

Earlier quoted context omitted.

Depends on details... I might not be screwed until I need to auth for something, at which point the auth is captured and I'm screwed.

And you do need to do it from time to time. So it's only 2FA against some threats , not necessarily most important ones for ordinary users.

If what you have (phone) and what you know (authentication) are both stolen, 2FA didn't keep your account secure. But it was still 2FA. They had to steal two things. Same as if it's a user entered OTP code, and you put your password into the phishing site, and then put your OTP code into the phishing site too; 2FA didn't help you, but it was still 2FA.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#45

What I missed from the article is the usual: biometric authentication is not secure. https://www.youtube.com/watch?v=tJw2Kf1khlA (Yes, I'm linking YouTube because unlike popular belief, some channels are actually informative, or some make it easy for us to understand the content.) I would never use my fingerprint for authentication, because it's a flawed concept. The problem is, that your fingerprint is not a passwor…

So if I give you my fingerprint on a cup, can you get into my phone?

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#46

Earlier quoted context omitted.

Exactly, your phone can break or get stolen any time. Plus I just don't want to limit myself to a single device.

Buy an older iPhone for ~$150. Install financial apps on it and don't use it for anything else. Keep it in a safe place, only carry it around if you must. If you need to manage non-trivial amounts of money through your phone, having a specific device to do that is a no-brainer.

Is the risk that someone's going to steal my phone, forcibly hold it to my face, and wire my money somewhere? So far I've known two close friends who got mugged, the robber didn't think of this. Last time I tried intentionally wiring a large amount of money to someone, it took forever and involved tons of approval.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#47

Passkeys seem overrated for three reasons: (1) Their use of public-key cryptography is not quantum safe (against quantum computing). In contrast, passwords are very much quantum safe. (2) They are tied to the provider. Why on Earth would I want to have the provider own my passkeys? Why would I want this vendor lock-in for my authentication? (3) What if I want multiple accounts for a site? Some passkey vendors may sup…

1. Neither are passwords… Unless you use a quantum safe hashing algorithm which I believe I’ve only seen Apple adopt, maybe others but most of the internet isn’t using it.

2. By definition this isn’t true

3. Again not true, don’t confound whatever terrible implementation you have used with what is allowed or capable

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#48
post #31

> Thieves actively exploit this by “shoulder surfing” a victim’s iPhone passcode before stealing the device If someone is using biometrics how often are they really using their pin that this would at all be a valuable tactic? I very rarely actually need to enter my pin on my phone so this largely seems like a moot point? Like yeah it is still technically possible but if we really get down to it, if someone were to ge…

FaceID only works like half the time on me. Really want the fingerprint unlock back. The thing is, to get into Chase, you need my long Chase password OR my Face ID. Can't just use my passcode.

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#49
post #34
post #29

Earlier quoted context omitted.

The issue I'm having with this sort of "something you own and something you know/are" two-factor authentication is that it has some potential to cause violence - both can be beaten out of you: https://www.citizen.co.za/network-news/lnn/article/banking-a...

What can't though?

[deleted]

Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA

#50
post #36
post #34

Earlier quoted context omitted.

What can't though?

A TAN generator or security key stored in a drawer at home. At least it reduces the opportunities for theft since people don't carry these devices with them all the time as opposed to their phones. Opportunity makes the thief.

Idk how this would play out, they might force you to go get that
Post reply on HN