4 ms·
They do? My bank is very explicit about "don't ever run the front-end and the second factor on the same device". Perhaps it's a German thing, with all our Daten
by usrusr 3y ago
They do? My bank is very explicit about "don't ever run the front-end and the second factor on the same device". Perhaps it's a German thing, with all our Datenschutz fundamentalism that will happily consider even IP addresses PII?
- kaliszad 3y agoMy experience is with select German and Czech banks and/ or "Sparkasse" which is a kind of savings bank used very often by private citizens. These tend to have better mortgage options in some cases but are quickly inconvenient if you have an unusual (digital/ SaaS) business or any kind of special requirements, like if you want to transfer larger sums of money into other countries with a decent exchange rate. > "don't ever run the front-end and the second factor on the same device" This is required in some cases, probably unless you apply for the physical hardware token generator which costs extra. You must apply for the 2FA-app initialization through the banking app that you are supposed to run on the same phone. In both cases, it is basically impossible to have a backup. Also, the banking app and the banking key app are supposed to have a separate PIN/ short password or a biometric login. Of course, the biometric approach has all kinds of problems in legal challenges (e.g. something you know is protected differently to something you are). Also, something you know cannot be easily obtained while you are asleep. Also, you probably don't want to use your password manager on your mobile phone - so there you are, typing a generated password to log into the key/ 2FA app for security theater. If there wasn't the banking app right next to the key app, the bank could probably just use something like FreeOTP+ or Google Authenticator without reinventing the wheel, also enabling backups in the process and skipping sending physical mail with the initial setup tokens. But that would be too straight forward and not "enterprise" security or whatever. The situation in Czechia is more or less similar. The banks tend to belong to the same banking groups so the underlying infrastructure might be similar even though Czechia still does not have the Euro/ SEPA.