5 ms·
more than that. For Robinhood to even allow initial account setup without robust (reda: no SMS) 2FA is bordering on criminal negligence. the only explanation to
by spatley 6y ago
more than that. For Robinhood to even allow initial account setup without robust (reda: no SMS) 2FA is bordering on criminal negligence.
the only explanation to not doing that is feat that it would reduce their signup completion rate. Which fits Robinhood's prior behavior.
This should be a class action at minimum, companies cannot shovel this kind of risk onto the general public.
- thrill 6y agoHyperbolic much? "Criminal negligence"? There are no laws requiring 2FA. Half the world thinks 2FA means SMS.
- kube-system 6y agoThere are laws that require financial services companies to take appropriate steps to protect customer data.
- bigbubba 6y agoSure, but those laws don't require 2FA (maybe they should) and Robinhood is far from the only institution that doesn't require it. A startling lot still think 'state your name, SSN/PIN/ or account number and birthday over the telephone' is sufficient.
- bostik 6y ago> Sure, but those laws don't require 2FA Funny that. The PSD2 regulations in Europe do.[0] The downside is that they don't mandate properly secure 2FA, so we have a mishmash of SMS, time-based tokens and whatever else passes for various banks under the regulations.[ß] 0: https://www.bankinfosecurity.com/psd2-authentication-requirements-implementation-hurdles-a-13086 https://www.bankinfosecurity.com/psd2-authentication-require... ß: My UK bank requires locally generated, time-based reader/app tokens, and has done so as long as I've lived here. My Finnish bank uses SMS.
- medina 6y agoNot sure what you mean laws but there is certainly regulatory guidance that assessors will be using. The agencies consider single-factor authentication, as the only control mechanism, to be inadequate for high-risk transactions involving access to customer information or the movement of funds to other parties. Financial institutions offering Internet-based products and services to their customers should use effective methods to authenticate the identity of customers using those products and services. The authentication techniques employed by the financial institution should be appropriate to the risks associated with those products and services. Account fraud and identity theft are frequently the result of single-factor (e.g., ID/password) authentication exploitation. Where risk assessments indicate that the use of single-factor authentication is inadequate, financial institutions should implement multifactor authentication, layered security, or other controls reasonably calculated to mitigate those risks. https://www.ffiec.gov/pdf/authentication_guidance.pdf https://www.ffiec.gov/pdf/authentication_guidance.pdf
- Wowfunhappy 6y agoEnabling 2FA by default is probably a good idea, but I do believe quite strongly that users should be able to turn it off. You don't know the user's situation—maybe they don't have consistent access to a single phone, for instance—and if they actually use a strong and unique password, that should be sufficient. Additional factors are of course always safer, but everything is a trade-off between security and usability, and users should have control.