3 ms·
The story in the article was completely preventable if banks just tried harder. The default 2FA solution should be Google authenticator or an analogous tech. I
by harmon 4y ago
The story in the article was completely preventable if banks just tried harder.
The default 2FA solution should be Google authenticator or an analogous tech. If SMS MUST be used, it should be opt in.
Notification of anomalous transactions should be automatic, not something you have to configure.
Anomalous wire transfers should be flagged and require verbal authentication by phone.
Banks should stop sending so much spam marketing email so that when people receive an email from their bank it is something they actually read.
Etc
- thimkerbell 4y agoI get many emails 'from' one of my financial institutions asking me to give them feedback on how they're doing. These all come from an email address that's from a different domain. This dissuades me from giving the institution feedback that I do think they need.
- DoneWithAllThat 4y agoSome thoughts on app based 2FA, having recently switched phones and needing to redo all my codes: * I have to redo all my codes, and that’s annoying. I have about 15 and it took me almost an hour of logging in and out of all my accounts to switch the device. It’s very cumbersome and in most cases logs me out of my accounts on other devices. It’s frankly a huge pain. I understand the need for it but there needs to be a better way if we’re going to be 2FA everywhere. * Most sites/services don’t have an option for “change to new device” although some do. In most cases the way to change the device is to turn 2FA off, then turn it back on with the new device. It’s a terrible user experience (it’s not like it even tells you this is what you have to do, you just have to know it). If 2FA is so critical why do I have to disable it to switch auth devices? * The flow for using it on many sites still treats 2FA as like this geeky or techie thing, it would be very off putting if I wasn’t familiar with it. They’re not very reassuring about what it does or how it works (although some do try to help the user understand it). * Backup codes are janky and not always offered. Sometimes when they’re offered they’re explicitly provided when enabling 2FA, sometimes they’re a totally separate menu item and the site doesn’t explain why they’re important, some don’t have them at all, and most just dump a text file of weird letters and numbers in your download folder. No header or anything to say what they are when trying to find them later. Abysmal user experience. I had to resort to printing them out and scribbling with a pen what site they were for. Some sites though do better, and include header info and/or a print button. Just not many. * The Google Authenticator UI looks utilitarian and unintuitive. It’s nice that it’s so uncluttered, but again if I wasn’t already technical I would struggle with feeling comfortable with it. Why are the numbers blinking? What’s the countdown timer? Oh no the numbers are red now! Did I break something? Wait now they’re green again. What’s going on? I love 2FA and think it needs to be way more ubiquitous. But at least right now it’s still pretty shit.
- shard 4y agoI use Authy, which allows the app to be installed on multiple devices. It's currently on 3 devices, so I never have to redo choices because I changed phones.