5 ms·
I can confirm that Scotia Bank, another major Canadian bank, does not support 2FA. This has always bothered me and is especially concerning because Canadian ban
by ResearchAtPlay 8y ago
I can confirm that Scotia Bank, another major Canadian bank, does not support 2FA. This has always bothered me and is especially concerning because Canadian bank accounts can be used to log into Canada's immigration services (CIC). That immigration account is protected only by one more layer of self-selected security questions, after which the intruder potentially has access to a swath of personal data, including passport numbers, and a very detailed personal history section.
In my opinion, Canadian banks are way overdue to switch to 2FA.
- verelo 8y agoNor does TD. They don't even do phone notifications of logins. Ironically i signed up with one of the local credit unions in Toronto to take advantage of a high interest savings account for a future tax debt of which I am sitting on the cash for, and found they supported SMS 2FA, and texts when anyone (even me) logged into the account. I wish TD supported this, but then again, as long as their money is backed by the government i don't really care all that much.
- ams6110 8y agoSMS as a 2FA has been discredited, but I suppose it's better than nothing.
- ahelwer 8y agoNope, it's worse. Websites will use it as an authentication method in password-reset workflows, which means hacking your account reduces to intercepting or redirecting text messages (easily accomplished). Rampant cryptocurrency theft over the past year has conclusively demonstrated that SMS-based 2FA is worse than no 2FA at all. The worst offender? Gmail. It uses your phone number for password recovery and is in turn used for password recovery by every other website.
- lotsofpulp 8y agoGmail allows you to use SMS, but does not force you to and gives you other secure options.
- ahelwer 8y agoThat's true, but I single it out because: 1) Many people have had their Gmail account for a long time, starting before SMS-based 2FA was widely known as a security disaster (this is in fact still not widely-known) 2) Google still actively encourages users to add a recovery phone number 3) Users could have added a phone number years ago then forgotten (this was the case with myself) 4) Users often have many websites using their Gmail account for password-reset workflows (this is definitely the case with myself) All of these combine to make Gmail the ideal hacker entrypoint. See this hack: https://www.reddit.com/r/ethtrader/comments/8klw4f/someone_just_stoke_over_150k_in_crypto_from_me/ https://www.reddit.com/r/ethtrader/comments/8klw4f/someone_j...
- gruez 8y ago>2) Google still actively encourages users to add a recovery phone number i would consider the average person to be pretty bad at handling otp backups. how else would you do recovery?
- ahelwer 8y agoYou are correct this is a significant usability issue. Personally I use Authy, which performs automatic encrypted backups in case I lose my phone. I then have to remember my Authy recovery password (not stored in my password manager, which is itself secured with a TOTP - hello circular dependency danger!) I also keep a yubikey authorized with all my accounts as second backup. All these things are beyond what the average person wants to worry about, as you say, but HN readers will find it simple. Personally I'm hoping U2F (Yubikeys) are the future, since your average person certainly understands the concept of a key.
- kevin_nisbet 8y agoActually I think TD just launched a SMS based two factor, I set it up on the weekend (I got prompted when I logged into EasyWeb, and it's also in my security settings). It's SMS based, and can be configured on how aggressive it is (when you change IP/computer, or every time you log in). I would much prefer to see a second factor like TOTP, U2F, etc as the problems with SMS based second factor are well documented, but I'll take what I can get.
- verelo 8y agoCorrect! Thanks for posting this, i just enabled it. For anyone who wants to set it up you can find it by... 1) Logging into Easy Web 2) Click your name in the top right 3) "Password and security"
- ahelwer 8y agoSMS-based 2FA is less secure than just a password. You unfortunately decreased the security of your account :(
- kevin_nisbet 8y agoCan you elaborate? I'm not sure I understand why you believe SMS codes as a second factor compromise the security of the password authentication.
- derefr 8y agoIt’s very easy to socially engineer a cellular ISP into redirecting arbitrary customers’ calls/texts to you, with just publically-available information.
- A2017U1 8y agoThat only matters if account reset is done through SMS. Barring that it is another layer of protection albeit weaker than TOTP.
- soperj 8y agoTD is actually terrible. If you forget your password and you can answer one of the questions about the person (Ie: what was your high school mascot?) they actually just let you change the password at that point.
- Pxtl 8y agoHah, I remember when TD actually started supporting proper password lengths and published a bunch of fluff pieces about good password practices, as if none of their users remember their old short password restrictions.
- mabbo 8y ago> one of the local credit unions in Toronto Got a name? And do you recommend them? Long-time RBC customer, which means they treat me terribly. Mortgage is coming up for renewal soon enough.
- verelo 8y agoI signed up for both Meridian and EQ bank. Both supported various 2FA options. I only used them as a higher interest savings account (One was 1.5% the other was 2%, so yeah, low but not terrible - I've since moved that tax liability to Wealthsimple's high interest account), cannot really vouch for their service outside of saying they gave me the interest and the initial capital back without any drama.
- auxym 8y agoTo my knowledge none of the big canadian banks support U2F or TOTP. Accounts can also be used to log in to the CRA website.
- miketery 8y agoCRA = Canada Revenue Agency (Canada's IRS)
- kazinator 8y ago= CCRA: Canada Customs and Revenue Agency
- flyGuyOnTheSly 8y agoWhen you sign up to CRA's online control panel... they actually make you tick a box that says in essence: "we're not responsible if we get hacked and lose all of your CRA related data to some random hacker... that's your fault"
- himom 8y agoGrrr. Google Authenticator and such are free. It would be mostly user support costs to deploy. Heck, could even SMS or robodial (Twilio etc) a TOTP code for people without smartphones.
- shawnz 8y ago> Heck, could even SMS or robodial (Twilio etc) a TOTP code for people without smartphones. SMS is not secure for this purpose since there are many attacks which allow you to sniff SMS messages.
- icebraining 8y agoThere's no need for that, TOTP runs everywhere, including J2ME apps installed from WAP.
- Scoundreller 8y ago> can be used to log into Canada's immigration services (CIC) I've looked around an account I'm a representative on, and other than passport numbers, not much sensitive personal data. CIC is still a lot of pen and paper these days, but perhaps it depends on one's immigration pathway... The bank's information can be used to log into CRA however...
- deleted 8y ago[deleted]
- throwaway2048 8y agoIts pretty ridiculous that all the big banks give you a smart card, but not a $5 smartcard reader to login with...
- miguelrochefort 8y agoTangerine doesn't support 2FA, and passwords must be 6-digit numbers...
- sebtoast 8y agoI just wanted to say that Scotia's corporate accounts do have 2FA with a physical token generator, so they do have the technology they just don't enforce it for consumer accounts.
- swat535 8y agoWhat really bothers me about these banks is that they attempt to keep their platforms secure by things like disabling the back button. Just so that hypothetically, if somehow a person has access to your physical machine, they can't just press back and view a cached copy of your account. Yet they fail on actual security practices. No 2FA - check Maximum password length of 6 characters - check Storing / Sending passwords in pain text - check The list goes on. It boggles my mind that institutions with such financial power, fail to employ these practices. It's clearly not a question of cost..