5 ms·
I find it funny how MFA is treated as if it would make account takeover suddenly impossible. It's just a bit more work, isn't it? And a big loss in convenience.
by guinea-unicorn 3y ago
I find it funny how MFA is treated as if it would make account takeover suddenly impossible. It's just a bit more work, isn't it? And a big loss in convenience.
I'd much rather see passwords entirely replaced by key-based authentication. That would improve security. Adding 2FA to my password is just patching a fundamentally broken system.
- hangonhn 3y agoyeah someone replied to one of my comments about adding MFA that an attacker can get around all that simply by buying the account from the author. I was way too narrowly focused on the technical aspects and was completely blind to other avenues like social engineering, etc. All very fair points.
- Jakesben10 3y ago[flagged]
- ryukoposting 3y agoCustomer service at one of my banks has an official policy of sending me a verification code via email that I then read to them over the phone, and that's not even close to the most "wrong" 2FA implementation I've ever seen. Somehow that institution knows what a YubiKey is, but several major banks don't.
- Liquix 3y agoFinancial institutions are very slow to adopt new tech. Especially tech that will inevitably cost $$$ in support hours when users start locking themselves out of their accounts. There is little to no advantage to being the first bank to implement YubiKey 2FA. To a risk-averse org, the non-zero chance of a botched rollout or displeased customers outweighs any potential benefit.
- monksy 3y agoThey're pretty terrible when they do. For the longest time the max password size was 8 characters and the csr knew what your password was. Heck I've had Chase security tell me they'd call me back.. dude that's exactly how people get compromised.
- biglost 3y agoA friensd bank, hopefully not the one i use, only allow a password off 6 digits. Yes You read it right, 6 fucking digits to login, i hace him the asvice to run away from that shitty bank
- foepys 3y agoDid this bank start out as a "telephone bank"? One of the largest German consumer banks still does this because they were the first "direct bank" without locations and typing in digits on the telephone pad was the most secure way of authenticating without telling the "bank teller" your password. So it was actually a good security measure but it is apparently too complicated to update their backend to modern standards. They do require 2FA, though.
- asm0dey 3y agoDiBa?
- doubled112 3y agoExactly. 8 character password in the 2010s as the only factor was fine. It was only my money we're talking about. Now I have to wait for an SMS. Great...
- throwaway2990 3y agoSMS is fine on most countries. It’s just America is dumb and allows number transfers to anyone.
- krinchan 3y agoJust say BofA.
- snnn 3y agoNot actually. Even if you enabled passkey, you still can login to their phone app via SMS. So it is not more secure. People who knows how to do SMS attacks certainly knows how to install a mobile app. And BofA gave their customers a fake assurance.
- eairy 3y agoI'm security consultant in the financial industry. I've literally been involved in the decision making on this at a bank. Banks are very conservative, and behave like insecure teenagers. They won't do anything bold, they all just copy each other. I pushed YubiKey as a solution and explained in detail why SMS was an awful choice, but they went with SMS anyway. It mostly came down to cost. SMS was the cheapest option. YubiKey would involve buying and sending the keys to customers, and they having the pain/cost of supporting them. There was also the feeling that YubiKeys were too confusing for customers. The nail in the coffin was "SMS is the standard solution in the industry" plus "If it's good enough for VISA it's good enough for us".
- heyoni 3y agoBut why won’t banks at least support customer provided yubikeys?
- eru 3y agoBecause it's extra hassle?
- mulmen 3y ago> But why won’t banks at least support customer provided yubikeys? > support You answered your own question.
- heyoni 3y agoAnd that’s the answer isn’t it? Banks are behind the times in terms of security and tech.
- intelVISA 3y agoBanks loathe anything relating, or adjacent, to good SWE principles.
- jalk 3y agoBank of America supports user purchased TOTP devices. https://www.bankofamerica.com/security-center/online-mobile-banking-privacy/usb-security-key/ https://www.bankofamerica.com/security-center/online-mobile-...
- gonzo41 3y agoBanks are in a tough spot. Remember, banks have you as a customer, they also have a 100 year old person who still wants to come to the branch in person as a customer. Not everyone can grapple with the idea of a Yubikey, or why their bank shouldn't be protecting their money like it did in the past.
- codedokode 3y agoThe problem is that the bank will automatically enable online access and SMS-confirmed transfers for that 100 year old person who doesn't even know how to use Internet.
- deleted 3y ago[deleted]
- apitman 3y agohttps://xkcd.com/538/ https://xkcd.com/538/
- AgentME 3y agoPasskeys are being introduced right now in browsers and popular sites like a MFA option, but I think the intention is that they will grow and become the main factor in the future.
- riddley 3y agoFrom what I've seen they're all controlled by huge tech companies. Hard pass.
- doubled112 3y agoI liked the username, password and TOTP combination. I could choose my own password manager, and TOTP generator app, based on my preferences. I have a feeling this won't hold true forever. Microsoft has their own authenticator now, Steam has another one, Google has their "was this you?" built into the OS. Monetization comes next? "View this ad before you login! Pay 50c to stay logged in for longer?"
- AgentME 3y agoPasskeys are an open standard with multiple implementations. It represents the opposite of the trend you're worried about there.
- thayne 3y agoBut the way it is designed, you can require a certain provider, and you can bet at least some sites will start requiring attestation from Google and or Apple.
- nmadden 3y agoDo they do attestation by default? I thought for Apple at least that was only a feature for enterprise managed devices (MDM). Attestation is also a registration-time check, so doesn’t necessarily constrain where the passkey is synced to later on.
- fsckboy 3y ago>I'd much rather see passwords entirely replaced by key-based authentication I've never understood how key-based systems are considered better. I understand the encryption angle, nobody is compromising that. But now I have a key I need to personally shepherd? where do I keep it, and my backups, and what is the protection on those places? how many local copies, how many offsite? And I still need a password to access/use it, but with no recourse should I lose or forget. how am I supposed to remember that? It's all just kicking the same cans down the same roads.