3 ms·
1. We follow a "trusted devices" model, where you 2FA using your phone number for the first login on a device. Future logins on that device aren't 2FA'd. I agre
by wdaareg 5y ago
1. We follow a "trusted devices" model, where you 2FA using your phone number for the first login on a device. Future logins on that device aren't 2FA'd. I agree that using a code gen is a good improvement we can make over time.
2. Marketing opt-out is prominent in account settings. Any email that is very strictly not transactional is considered marketing by our team, and can be opted out of. Developing simple, focused products is core to our identity and we won't add irrelevant features that might upsell to 10% of customers. I assure you there won't be a "refer your friends" badge blinking on the home page of the app.
3. Unfortunately we're not on web yet - but we'd love to get there after iOS and Android. We hear from most people that iOS or Android are their preferred platforms, so we have to start there.
4. We share data as required to support financial transactions and other core parts of the business, but we do adhere to the GDPR.
5. I think VPNs are allowed - at least I don't think we block them in particular.
We're excited to bring a fresh perspective and better pricing to a landscape with a lot of providers doing approximately the same thing. We'd love for you to try out the app once it's available - if you decide to register on our site we'll be sure to keep you updated.
- 3np 5y agoThanks for following up! (BTW, double line breaks if you want to make a HN comment more readable, or double leading spaces for blockquotes) > We follow a "trusted devices" model, where you 2FA using your phone number for the first login on a device It sounds like associating and verifying a phone number is required to sign up and use the service - is this something you're open to changing? > I assure you there won't be a "refer your friends" badge blinking on the home page of the app That's great! And TBH I wouldn't mind terribly as long as it can be permanently disabled after a first view. > We hear from most people that iOS or Android are their preferred platforms, so we have to start there Understandable. At the very least it would be a huge boon if we can expect to run the Android app without hickups on a fully degoogled Android device (e.g. GrapheneOS). Will keep an eye on how things develop :)
- pkavanagh 5y agoHi, other founder here. Thank you for your feedback! >It sounds like associating and verifying a phone number is required to sign up and use the service - is this something you're open to changing? Are you looking for something like Authy or Google Authenticator here?
- 3np 5y ago> Are you looking for something like Authy or Google Authenticator here? Precisely! Both are implementations of TOTP[0] - it's a simple protocol which doesn't rely on any particular implementation. The other common one with that same characteristic would be Fido U2F[1] (for hardware keys such as Yubikey and Google Titan). If/when you do implement it, make sure to support adding more than one token to facilitate users sorting out their own backups. Both are open standards that are well-supported with both proprietary and open implementations across platforms. If you have to initially only pick one of the two I'd go with TOTP. [0]: https://en.wikipedia.org/wiki/Time-based_one-time_password https://en.wikipedia.org/wiki/Time-based_one-time_password [1]: https://en.wikipedia.org/wiki/Universal_2nd_Factor https://en.wikipedia.org/wiki/Universal_2nd_Factor
- pkavanagh 5y agoCool, we should be able to do this. Thank you for your feedback.
- donalhunt 5y agoIn addition, for regular users, consider providing free or subsidised hardware keys (yubikey, Google titan). While many will raise concern with the UX of having to carry around hardware, in the fintech world I think it's a good tradeoff and raises the bar for the industry (I always shudder when I see "we use industry-standard protection"). :)