4 ms·
It's dumbfounding how awful bank websites are at security. They started with the stupidest conceivable way to implement two-factor--a second clear-text password
by Splognosticus 6y ago
It's dumbfounding how awful bank websites are at security. They started with the stupidest conceivable way to implement two-factor--a second clear-text password that is an answer to a very small number of secret questions. Then they limited the secret questions to things people could find out about you on Facebook, then on top of that added secret questions about esoteric crap like your father's mother's childhood neighbor's dog's name, secret questions that have answers that vary over time like your favorite song, secret questions that have ridiculous length or punctuation requirements, authentication by SMS, authentication by robocall, and on and on and on. The only thing they absolutely refuse to try is an actual friggin' two-factor app!
There's security theater, and then there's Punch and Judy security puppet shows.
- rblatz 6y agoDon’t forget security images! Don’t put your password in unless you see the random picture!
- stubish 6y agoOur banks in Australia try two-factor apps. Every bank has their own unique one, so phone only and the expected app pollution. And then they push you to using a different app on the same phone for your banking (say by having unique features such as push notifications of credit card purposes), which completely defeats the purpose of the TFA app since you can drain the accounts with nothing but the phone and (if you are lucky) a PIN number.