3 ms·
Assuming that one stores top-tier passwords (banking, primary email) in the password manager. Which is to say, yeah, 99.9% of users.
by lips 11y ago
Assuming that one stores top-tier passwords (banking, primary email) in the password manager. Which is to say, yeah, 99.9% of users.
- gpvos 11y agoI've decided to start doing that (banking at least, not yet primary email), since remembering many high-security passwords is hard, and my bank has 2FA anyway. A keylogger could easily get at all of my passwords anyway, so that doesn't make the threat any worse.
- iaskwhy 11y agoWhich would be fine it more banks used a two tier approach to bank operations. Checking the balance? Username and password should suffice. Making a transaction? SMS token or matrix card or RSA key, all seem fine.
- ddmf 11y agoRoyal Bank of Scotland and First Direct use a 2FA device that is authenticated first with your bank card pin (3FA?)
- mdpye 11y agoAll the devices are the same (across customers and banks), so your card is the second factor, the device is just a reader for it.
- mdpopescu 11y agoOne of my banks (BCR Romania) requires a login with a token for initial access (just seeing stuff, or transfers between one's own accounts) and another token OTP, based on the amount and the last four digits of the destination account, for transfers to someone else.