4 ms·
Disclaimer: I don't use Tesco Bank so this is just speculation and some observations. The types of 2FA vary dramatically between banks. Some use an SMS OTP but
by jsingleton 10y ago
Disclaimer: I don't use Tesco Bank so this is just speculation and some observations.
The types of 2FA vary dramatically between banks. Some use an SMS OTP but as we know phone numbers aren't secure [0]. Most use a card reader but they often do this differently. Some use the 'identify' function to log on and the 'sign' function for payments (as designed) but others use the 'respond' function for everything. The danger in using 'respond' for payments is that the account and amount aren't entered into the card reader so you don't know what you are authorising.
<pure-speculation>
If Tesco have a flaw in how they are using 2FA, by only using 'respond', then local malware could intercept genuine payments, alter the account/amount details, and get the user to authorise this. Or Android malware could intercept SMS messages. N.B. This assumes the issue is in the faster payments system but it could be in the payment card system. It appears cash points still work but this is a separate system to debit card payments.
</pure-speculation>
From what I've read no one will lose money but having transactions frozen is still a big inconvenience. As mentioned elsewhere here, this is why it's a good idea to have many different bank accounts from various parent institutions (also important from a deposit guarantee position). Some banks share the same infrastructure and liability. Always have some cash available too, although that is getting harder to spend everywhere [1].
[0]: https://unop.uk/phone-numbers-for-examples-and-user-identification/ https://unop.uk/phone-numbers-for-examples-and-user-identifi...
[1]: https://unop.uk/do-you-accept-cash/ https://unop.uk/do-you-accept-cash/
- emp_zealoth 10y agoWelp, just because you get to have Verizon give up your phone number because someone asked nicely doesn't mean it is universally a bad idea Hell, I can't even get authenticated with my provider half the time because the simcard comes with it's ID/PIN/password that is printed on your contract. You need that to do any changes on your account. I personally think cell phones can be made secure enough and are the most convenient. If somebody really wants to fuck with you, they will anyway, for most people there is not much point to it anyway
- dogma1138 10y agoNot all banking systems require 2FA, phone banking doesn't. If tested systems that allow you to transfer money between accounts, if you can bypass the initial authentication you can transfer money without needing to use 2FA or generating a TUN code. And these systems can be breached.