3 ms·
I wouldn't say it's badly implemented, I would say that the implementation clearly errs on the side of preventing social engineering than giving customers who c
by davewritescode 4y ago
I wouldn't say it's badly implemented, I would say that the implementation clearly errs on the side of preventing social engineering than giving customers who can't match their signature a good experience.
I've been a part of designing these types of processes and this is all argued about forever. The alternative is the e*trade approach where I can call in, give my DOB, Address and last 4 digits of my social social and I get a new MFA token immediately. No PIN, no signature nothing.
- CamperBob2 4y agoSo your model is dictated by the potential behavior of criminals rather than the actual needs of customers... and you don't consider this to be "badly implemented." What company did you say you were designing security policies/processes for...?
- davewritescode 4y agoThe processes are dictated by what legal, compliance and the business at large are willing to let you use to recover MFA and that doesn't always match with UX. If the legal/compliance team says signatures have to match, what are you, as an engineer supposed to do? The process we use now is automated but customers don't like having to find recovery pins, billing information so a lot of them still call if they get a new phone and their TOTP isn't there. It will also fail for various other reasons related to browser fingerprinting and reputation that I won't go into details about. MFA recovery is very tricky, most websites don't even let you do it in an automated way for security reasons. If it goes wrong, you've basically broken MFA for your whole site. Banks are the types of places that are going to err way on the side of caution.