3 ms·
I think the article brings up some good points about the issues of verifying identity over the internet, something that yet does not have a universal standard.
by slashink 9y ago
I think the article brings up some good points about the issues of verifying identity over the internet, something that yet does not have a universal standard.
In Sweden we have a system called "BankID" which basically let's you use your phone as a 2FA device in order to verify your identity to companies, the tax agencies, police etc and it works very well, although limited to Sweden. This is not an SMS based system and is not tied to your SIM card, instead tied to the application on your phone together with a personal password. Hopefully a system like this can catch on in the future as a way of verifying identity.
With this said i will excuse myself for going out of topic here but i am getting very tired of the recent trend of putting reaction GIF's in pieces like this. Reading it on desktop is just hard for me when getting into a nice reading flow, only to be broken up by a reaction GIF 1/3 the size of my monitor height. Authors adding a GIF to the end does not disturb me, but for me this article breaks the reading flow by adding so many.
Here is how large one of these reaction GIF's render for me: https://imgur.com/a/dYihu https://imgur.com/a/dYihu
- PinguTS 9y agoSo, you mean a 2FA tied to a mobile phone number? Ever heard of SS7 and its flaws? Hopefully, my government (Germany) will never come up with such stupid ideas.
- slashink 9y agoNo, the 2FA is not tied to a mobile number. The way it works is you install the application on your phone, set a 6-8 digit numerical password for your app and then through your bank, you bind the application on that specific phone to your identity. Hence when you want to login to something you authorise with the application and your password, which means in order to auth you have to have both the phone and your password for the identity in order to verify that it's you. I am aware of the security flaws of SMS and i realise i was unclear about the process of this in the parent comment.
- tallanvor 9y agoI'm guessing BankID in Sweden is very similar to the version in Norway, which is a pretty horrible service. In order to use BankID, you have to bind it first to one bank account and use that bank's code brick to log in. Or you use BankID on your phone which is tied to your SIM card and some providers will charge you for using it! It also relies on your phone having service (not just WiFi access), so the amount you're charged for using it can be much higher overseas. BankID would be just as secure if they used the authentication scheme behind Google Authenticator, and it would allow people to use it without additional costs.
- slashink 9y agoNo, luckily our version is not tied to the SIM card at all and works on just wifi devices. It's also free for the consumer to use. For being a service primarily integrating with banks, i will say it works very well in Sweden and now most providers has started to support it. Sure, there can always be improvements and i wish there were a standard not owned by a company, but i'm also glad when my 80+ year old grandmother has something simple enough to authenticate that provides a reasonable layer of security. If you are interested there's some details here https://sv.wikipedia.org/wiki/E-legitimation https://sv.wikipedia.org/wiki/E-legitimation that lists the differences.
- tallanvor 9y agoThat's good to know. I wish Norway would get on board with better practices!