4 ms·
This is funny to read as where I live (Germany) banks have been slowly migrating away from SMS-based verification to app-based code generators that in turn requ
by pluma 7y ago
This is funny to read as where I live (Germany) banks have been slowly migrating away from SMS-based verification to app-based code generators that in turn require one-time authorization via physical mail.
And we're generally lagging behind when it comes to digital solutions, so I would expect other countries to be ahead of the curve and no longer using SMS for anything important.
- toomuchtodo 7y agoBanks are a great use case for TOTP or other 2FA auth methods that aren't SMS, as if you need to verify identity in person, you can require the user come to a physical branch (in the US, you can get something called a "medallion signature guarantee" [1], which is typically required to verify your identity if you're moving more than $250k in assets between financial service firms). Services that can't provide identity verification services in meatspace are at a disadvantage, which is why they fall back to SMS as identity verification and management. ID cards that support cryptographic functions (such as Estonia's National ID [2], or in the US, DoD CACs [3]) would go a long way to fixing these problems. [1] https://en.wikipedia.org/wiki/Medallion_signature_guarantee https://en.wikipedia.org/wiki/Medallion_signature_guarantee [2] https://e-estonia.com/solutions/e-identity/id-card/ https://e-estonia.com/solutions/e-identity/id-card/ [3] https://www.cac.mil/ https://www.cac.mil/
- pluma 7y agoFWIW in Germany we have PostIdent, which consists of taking a printout to the local post office, showing your ID card and then having the clerk fill out and sign the printout and send it to the organisation you're trying to authenticate with. This is typically done for age restrictions in online delivery services (e.g. being able to order goods marked as 18+ on Amazon -- not signing up for porn sites or stuff like that), for example. The ID card technically comes with a PIN and there were supposed to be special readers that could be used with a handful of authorized online services to verify your identity but as far as I can tell not much came from that as end users would have needed to buy special hardware and services interested in using that would have required special licensing or something. That said, SMS is less secure than e-mail, so this seems like an odd choice these days (much like magnetic stripes rather than chip and pin).
- toomuchtodo 7y agoI was unfamiliar with this, thank you for bringing it to my attention!