6 ms·
When you say fraud, do you mean theft or identity fraud? 2FA is extraordinarily relevant when it comes to theft with regard to online banking. The purpose of 2F
by RandomInteger4 9y ago
When you say fraud, do you mean theft or identity fraud? 2FA is extraordinarily relevant when it comes to theft with regard to online banking. The purpose of 2FA is mostly to prevent automated attacks or remote account entry via password resets by email or something similar.
I'm not sure if you're aware, but Europe has proper 2FA in the form of a dongle type device, and not this SMS BS many companies in the US use out of laziness. They also need to use this device for not just online banking, but basic everyday transactions.
- closeparen 9y ago>2FA is extraordinarily relevant when it comes to theft with regard to online banking If theft through online banking even exists, it's at such a low volume as to be irrelevant. Most online banking interfaces are a read-only view of recent transactions. Some provide the ability to transfer funds between your own linked accounts at the same bank. Fewer still provide bill pay for a specific set of partner institutions, and a tiny proportion of the most technologically sophisticated banks provide the ability to transfer money to any arbitrary person. When they do, adding a new payee is loud (sends a bunch of notifications) and requires SMS verification and/or digits off your debit card. The transfer is loud and takes several days to actually happen (so you can cancel it), and is limited to a couple thousand dollars at most. This is a fringe thing that a handful of people use occasionally. Most peer-to-peer transfers are going to happen through Venmo, which piggy-backs off a debit card, or through paper checks. Most online bill pay is going to happen by giving the biller your account and routing number. The largest vector by far for stealing from a bank account is capturing a debit card number in some legitimate transaction, and reusing it to make fraudulent transactions. The strength of the communication channel between payer's bank and payer is irrelevant, because you don't get to weigh in on debit card transactions (or checks) against your account. They just happen, and then you can dispute them later.
- evfanknitram 9y ago> and a tiny proportion of the most technologically sophisticated banks provide the ability to transfer money to any arbitrary person. In the country where I live all internet banks supports this. And all of course use 2FA. Most if not all banks here let's me do any kind or transactions. Not just viewing my data but transferring money, buying stock, setting up new bank accounts, pension management and everything else. Maybe it's the lack of security at your place which prevents useful functionality.
- closeparen 9y agoWell yes, the country where you live needs 2FA on online banking because it actually has transaction capabilities. The US essentially doesn't, so the lack of 2FA isn't a significant problem.
- evfanknitram 9y agoSo why does the US banks not have transactions capabilities? Online banking without transactions seems like a oxymoron.
- Tehnix 9y agoI am not aware of a country in Europe where the online banking interface is not able to transfer money, both domestically and internationally vi e.g. SEPA and other methods - it’s called “online banking”... Phishing and other things were a large attack vector until 2FA mostly did away with it.
- closeparen 9y agoThe capabilities of European online banking are irrelevant to the security needs of American online banking. Yes, you need 2FA, because your online banking is actually for making transactions. In the US, it isn't. On the off chance that the capability is there, it's seldom used. You make transactions by telling the other party your account number.
- RandomInteger4 9y agoWhat kind of backwards bank do you bank with that doesn't allow transactions to be made from their web portal?
- algesten 9y agouhm. no?! I've paid all my bills and transferred money between friends/family using online banking for the last 20 years. Sweden had full online banking since at least 1997.
- rimliu 9y agoCan you clarify what country are you talking about? Because it’s nothing like this where I am and around. On the contrary, banks have been pushing for even more online capabilities for years, so you not only can pay whomever whenever wherever you want, you can open accounts, take loans, buy insurance, see your spendings grouped in categories, etc. etc. The more you can do online yourself, the less staff banks have to pay. Also, there is none of this weird payment card acount/normal account thing. You just have an account and card(s) tied to it. For any purchase I do with my card I get a notification instantly on my phone. As I do for other activity in my account.
- oblio 9y agoWhere do you live that online banking is read only? I'm from Romania, so a developing country, and we've had full online banking (transfer money abroad, schedule monthly payments, make savings accounts, etc.) since at least 2007 for all the major banks. If someone would hack my online banking account they could do quite a few nasty things...
- closeparen 9y agoThe context of this thread is puzzlement that the US doesn't have widespread 2FA for online banking, and I'm telling you why.
- oblio 9y agoThat's just sad if it's widespread in the US.
- jasonkester 9y agoYou're mistaken. All three of my US banks allow you to send money out via bill pay, ACH to accounts at other US banks, and wire transfers overseas. It's Online Banking, not Online Statement Viewing.
- mmcnl 9y ago> Most online banking interfaces are a read-only view of recent transactions. What year is this, 1997? Is this normal in the US? I'm beyond amazed. Using online banking for transferring money is such a normal activity here (has been for at least 10 years).