5 ms·
With these app-only banks I am always considered about their security if their main forcus for the first years is to grow at a startup-like pace. This talk fro
by hs86 8y ago
With these app-only banks I am always considered about their security if their main forcus for the first years is to grow at a startup-like pace.
This talk from 2016 shows how they cut corners when it comes to security in order to achieve this: https://media.ccc.de/v/33c3-7969-shut_up_and_take_my_money https://media.ccc.de/v/33c3-7969-shut_up_and_take_my_money
- TazeTSchnitzel 8y agoThat talk makes N26 look utterly terrible. With a single command and a leaked email and password, the account could be compromised from anywhere in 5 minutes! D:
- usaphp 8y agoMany of the “big traditional banks” used to have this idiotic rule of not using more than 10-12 characters in your account password for many many years, many still do now. So I would not be so judgeful on the new app-only banks.
- dogma1138 8y agoEU banks issue security tokens which are used for login and to authorize every transaction.
- seszett 8y agoSome of the banks of some EU countries* Most French banks don't do that, for example.
- dogma1138 8y agoFrench banks don’t use TAN codes? Isn’t it an EU directive at this point? It doesn’t have have to be a dedicated hardware token or a chip TAN, mTAN or soft tokens are also acceptable.
- seszett 8y agoUnless a 6-digit "password" that you choose and stays the same for as long as you wish counts as a soft token, no they don't. Well, most don't, although some do.
- dogma1138 8y agoHow do they offer SEPA transactions without TAN codes?
- seszett 8y agoI don't actually know what are the TAN codes you are talking about, I guess, if they're some technical implementation detail I sure don't know about it. For a SEPA transfer, you input the code of the account you want to transfer money to, then the amount and various optional messages and transactions codes if you want, then click "submit" and it's done.
- dogma1138 8y agoThese are the transaction authentication numbers which are unique for each new transaction: https://en.m.wikipedia.org/wiki/Transaction_authentication_number https://en.m.wikipedia.org/wiki/Transaction_authentication_n... For me in the UK to move money I need to generate a TAN using a SecureID token the TAN is generated by using the secret in the token and digits of the account number I need to transfer money too. The same SecureID also generates OTP for 2FA login. But there are other TAN schemes including pregenerated lists and TANs sent over SMS or TANs which are generated by using the smartcard in your debit card.
- kmmlng 8y agoNot French, but German here. TANs are obviously used for transactions, but I've never seen them used for login purposes. To add insult to injury, the _only_ permissible password length for my bank was 5 (five!) characters. Looking to make a switch right now..
- Semaphor 8y agoFor the longest time, my old bank limited my password to 4 (!!) characters…
- CalRobert 8y agoTheir security appears to be superior to at least some of the traditional banks, which is laughably poor. http://olivernash.org/2015/11/18/security-theatre-at-allied-irish-banks-act-2/index.html http://olivernash.org/2015/11/18/security-theatre-at-allied-...
- Rjevski 8y agoAt least in the UK, by law you are not responsible for any fraud on your account, and even if the bank folds the government will bail them out up to 85k per account (FSCS protection), so I wouldn't be worried. Disclaimer: Monzo & Starling Bank customer.
- blibble 8y agoif there's a serious fraud and the "app only bank" disagrees that you had 50k in your bank account: how do you prove it to a court without paper statements? this is the reasoning that prevents me storing any more than trivial amounts in these app only banks a magistrate understands a paper statement on company stationary
- SideburnsOfDoom 8y ago> how do you prove it to a court without paper statements? The UK banking sector is not unregulated. You would expect, that when a company is certified by the relevant authority that they would have to comply with standards and reporting requirements. getting onto the FSCS protection is not trivial, if it was then Revolut would also be on it.
- SideburnsOfDoom 8y agoMonzo and Starling are FSCS protected, Revolut is not. You can check here https://protected.fscs.org.uk/tools/check-your-money-is-protected/ https://protected.fscs.org.uk/tools/check-your-money-is-prot...
- slavoingilizov 8y agoExamples of better security than incumbents: https://monzo.com/blog/2018/06/28/ticketmaster-breach/ https://monzo.com/blog/2018/06/28/ticketmaster-breach/ https://monzo.com/blog/2018/09/07/ba-data-breach/ https://monzo.com/blog/2018/09/07/ba-data-breach/
- IshKebab 8y agoPractical security with these apps, at least Monzo is much better for the average consumer because I'll learn about fraudulent transactions immediately via a notification on my phone. With my high street bank (1st direct, which I only really keep for their free coin machines) I might learn about it... weeks later when I check my balance on their website... maybe. I don't have their app installed because it is shit. Btw another reason I kept 1st direct was to pay in cheques which the government still insists on using, but Monzo lets you do that with a photo of the cheque now I believe. Can you imagine 1st direct ever being that modern? Their website still opens in a popup and tells you no to use the back button!