13 ms·
A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". Th
by dools 2y ago
A family friend of ours recently fell victim to a phishing attack perpetrated by an attacker who paid for Google Ads for a search term like "BANKNAME login". The site was an immaculate knock off, with a replay attack in the background. She entered her 2fa code from the app on her phone but the interface rejected the code and asked her for another one. In the background, this 2nd code was actually to authorise the addition of a new "pay anyone" payee, and with that her money was gone[0].
I have accounts with 2 banks, one uses SMS 2fa and the other uses an app which generates a token. I had thought that the app was by default a better choice because of the inherent lack of security in SMS as a protcol BUT in the above attack the bank that sends the SMS would have been better because they send a different message when you're doing a transfer to a new payee than when you're logging in.
So really the ideal is not just having an app that generates a token but one that generates a specific type of token depending on what type of transaction you're performing and won't accept, for example, a login token when adding a new payee. I haven't seen any bank with that level of 2fa yet, has anyone else?
I guess perhaps passkeys make this obsolete anyway since it establishes a local physical connection to a piece of hardware.
[0] Ron Howard voice: "she eventually got it back"
- recursive 2y agoIf the business model of your search engine is based on ads, your (search user) relationship with them is fundamentally adversarial. Ad blockers will get you some temporary respite, but it doesn't change the nature. This is an observation from a happy kagi subscriber that doesn't use an ad block.
- ikekkdcjkfke 2y agoADS ARE THE PRIMARY WAY ELDERS GET DEFRAUDED
- solardev 2y agoFYI, passkeys do not require anything in hardware. You can connect them to software only password managers like 1Password or Bitwarden. Where they are nice though is that they are also tied to a specific origin (domain), so a phishing site can't ask for the real passkey. But I've never seen a passkey be a primary source of authentication, so they can always fool the user to falling back to some weaker auth (email reset or 2fa).
- michaelmrose 2y agoI wish we could break people of the habit of searching for websites that they visit all the time and using search results to navigate to them. Maybe a secure browser profile that blocks search engine usage and can only visit sited in bookmarks or a whitelist so if you get a new bank and its not on the common whitelist have to explicitly add it to bookmarks. Use your Chrome secure profile tm for banking and refuse to auto complete payment info on the insecure side.
- gcr 2y agoYour solution wouldn’t have prevented the attack you describe unless the user can immediately tell the difference between login 2FA codes and “new payee” 2FA codes and knows not to enter one code into the wrong form.
- dools 2y agoWell, that's what I'm saying. When I get an SMS from one of my banks for example it says "your code to transfer X to Y is ABC" or "Your code to add a new payee is ABC". In this case she had a code generating app, but the codes were not different for login versus other high risk actions. The same is true for my other bank, which has a code which you use to login, and the same code generator, with no distinction, is used for example when you make a large BPay transaction.
- rexf 2y agojust this week, I clicked on the 1st search result ad for "amazon" in google search. It led me to a windows-themed "Virus detected" amazon clone. I'm not using Windows. I was able to close the tab, but it left a bad taste in my mouth for google search results. (I know I could have just typed "amazon.com" and gone directly. But browser autocomplete makes it a tiny bit easier to use the omni-url bar and just type "amazon" than "amazon.com")
- macrael 2y agoPasskeys or FIDO hardware tokens are the solution, as written up by Google ages ago, because they only enter the TOTP code when the URL matches the right site, it wouldn't enter the code for the phishing URL
- marcosdumay 2y agoInstead, the 2fa app should show you the action you are authenticating, just like the SMS version. But actually, we have put way too much stuff on the (inherently transient) web. What solves your problem is permanent client-side storage. Your friend shouldn't reach the bank through a google search.
- aidenn0 2y agoI was saved from a phishing attack by using a password manager that refused to auto-fill my password since the hostname didn't match.
- zamber 2y agoBanks like that exist. mBank from Poland does in-app approve/reject - similar to what you get on an Android phone when you try logging in on a new PC. They also send phishing warnings when they find active campaigns. That said, plain old social engineering works well on people. Last week one small-scale influencer fell victim to a bank transfer scam. Got phoned by a bank person telling her that her account is targeted by hackers, then a cybersec police head phoned her and asked to transfer her savings to a 'secure account'.
- bckr 2y agoAnother lesson here is to bookmark/ memorize the url of your bank, and don’t trust search engines to take you to your bank
- alistairSH 2y agoOr skip the website and use their native app.
- DowagerDave 2y agothen you can't block anything
- EasyMark 2y agoWhy do you need to block stuff on your bank? I do all my banking through their app tbh. If I had to block stuff from the bank then I’d switch banks.
- alistairSH 2y agoI don't understand - what would I block that's being delivered by my bank's native app? IF I can't trust their app, I can't trust the institution as a whole.
- akira2501 2y agoIf Google ad words even allows a scammer to create an ad for a bank login page then we have a more fundamental problem.
- dools 2y agoAlso that Google, as a search engine that is also the world's biggest advertising company really should be able to manage not to sell ads to phishing scammers!
- Ekaros 2y agoMaybe if platform is large enough it should be criminally liable for phishing attacks. I see no reason why Google should not be responsible in vetting each and every link they advertise at top of their search results.
- rlpb 2y ago> So really the ideal is not just having an app that generates a token but one that generates a specific type of token depending on what type of transaction you're performing and won't accept, for example, a login token when adding a new payee. My understanding of EU regulation is that it effectively requires this by requiring the 2FA to validate not just the identity but also the transaction (such as an amount, or destination account). Unfortunately it means that all banks use SMS. We did have card reader 2FA that also did this but it's falling out of use because users don't like having to carry a card reader around.
- riffraff 2y ago> Unfortunately it means that all banks use SMS This is not true, I have used multiple financial things where they have different codes for different uses (Raiffeisen, K&H) or apps which have a server sent event and local approval showing the transaction (wise, Fineco)
- wiredfool 2y agoMy EU bank uses an app for consumer accounts. It hasn’t used sms for a few years, except when setting the app up on a new phone/sim.
- rlpb 2y ago> except when setting the app up on a new phone/sim. So it does when it needs to authenticate you :)
- wiredfool 2y agoThe difference is, it’s a pain, has happened twice in 5 years, and I know what triggered it, and it doesn’t happen with every 3d secure purchase or login. So much less likely to get phished.
- bux93 2y agoYes, the Payment Services Directive requires "dynamic linking" to a specific amount and a specific payee in article 97, and the RTS in article 5 go on to say that the payer should be "made aware of the amount of the payment transaction and of the payee". The most elegant implementation I saw of this were card readers with a 2D (colored) barcode scan ; the 2D barcode contained transaction details that the card reader would display on its screen. This was an effective control against MITM. But even I myself always misplaced the card reader. So now, most confirmations are done using the banking app. Even if I use a credit card by filling in its details on a US website, I get a push notification on my phone to confirm the tx on my app. The app asks for a password or uses biometrics, so thats 1FA, and the app is enrolled at some point, so the token on your phone (I presume in some secure storage) counts as the 'thing you have' for 2FA. Enrolling the app nowadays usually entails scanning your ID card and a 'live selfie' (blink your eyes). And of course you get notified (via e-mail) that you just installed the app on some device.
- kardianos 2y agoWe have it: FIDO U2F. you could even treat it like the new password less manager, with a computer/phone specific store. My gut? It actually works, and people didn't like that. Users and orgs like authentication slightly broken so they can work around systems.
- 0xbadcafebee 2y agoIt only works in a couple of situations and it's difficult to manage. When the site doesn't support it (which is almost all of them), when you don't have USB, when you lose or forget your YubiKey, when you don't have a phone with NFC or lose it, when you can't afford the device, or it's difficult for the user to set up, etc it fails. Now you need a different factor to finish logging in, which is probably weaker, so attackers will try to degrade this first factor to force the second weaker one. It's a nice-to-have but not even close to a universal solution.
- armada651 2y ago> My gut? It actually works, and people didn't like that. Users and orgs like authentication slightly broken so they can work around systems. People like authentication systems that are secure enough to keep bad actors out, but not so secure that it keeps legitimate users out. It's got nothing to do with users wanting to break into a system.
- aftbit 2y agoI like FIDO U2F as a second factor, although you always need a fallback of some kind in case you are stuck using a device without a USB port. I don't like it as a single factor, as most devices make it hard or impossible to back up your keys. Using Passkeys with Bitwarden is pretty interesting though, and appears to satisfy most of my concerns, as they're just stored in my password manager and move devices with me.
- joncrocks 2y ago> the ideal is not just having an app that generates a token but one that generates a specific type of token depending on what type of transaction you're performing and won't accept, for example, a login token when adding a new payee. I think at least some UK banks will do this. When I've done it using a card + card reader, you select the option to choose which type of operation you're trying to do. And if you're just trying to login it just displays a rolling code, but for authorisation of particular events it will take the form of a challenge/response, i.e. you have to select the operation on the card reader + enter a code provided from the site. This should I think prevent _simple_ replay attacks. I even think for some transactions such as transfers over a certain amount, you have to enter the amount into the reader as part of the code generation.
- arp242 2y agoYes, my AIB card reader works like this. When transferring money to an unknown account I also need to enter the amount and "sign" that with the card reader. For adding a new payee it's a challenge/response.
- hbn 2y ago> an attacker who paid for Google Ads for a search term like "BANKNAME login" I tried out buy Google ads once out of curiosity cause they gave me a free credit. It was crazy how many ridiculous stipulations and guidelines I had to work around before they'd accept my ad. How are they that strict for me, but seemingly they'll sell to a phishing page that's impersonating a bank and targeting it to people searching for that bank?
- EasyMark 2y agoDon’t they usually put in “legitimate” ads and info then swap out the content afterwards with the spamscam?
- qingcharles 2y agoI have an ads account; I don't see them checking I haven't done a switcheroo on the landing page contents. I think I could easily put a JS redirect on the landing page, if nothing else worked. They are reasonably strict about the keywords though -- I often go into a "verifying" stage when setting up the ads.
- Ozzie_osman 2y agoBecause the impersonator is probably a lot more sophisticated at this than you or I, and it's likely that 999 impersonators were rejected and this is just the 1/1000 who found a way around it. The system probably produces a lot of false positives AND negatives.
- gorlilla 2y agoAnd even at those failure rates (no matter how anecdotal), economies of scale creep in so a couple billion failures/day still would result in nearly a billion successes per year. The machine never rests and is fueled by creative people from all walks of life from every possible place on earth.
- UncleMeat 2y agoCriminals are incentivized to evade detection. And you only get to observe the successful criminals and none of the unsuccessful ones. This makes it appear like the criminals are getting through the filters trivially. What you don't see is the work they are putting in to get a successful phishing ad up there. Not to excuse failures, but there isn't a "it is easy for them but hard for me" situation.
- 2Gkashmiri 2y agoHow did entering login and 2fa do the following things. 1. Login 2. Add payee 3. Create transaction 4. Verify transaction This appears to be a banking issue where they do not try to maximize the attack surface. Sure people will try to game the system by doing phishing but its the responsibility of banks to actively make it harder
- dylan604 2y agoI read it as the first 2fa code was used to login, then the system quickly attempted to add this new payee which required a second 2fa code, so the phishing site quickly sends another request stating the code saying the first was rejected.
- twelve40 2y agoYep. A few simple steps like an extra SMS (or email) code to add a recipient, an email notifying about the change, not perfect, but will make this harder to pull off. Not sure what is '"pay anyone" payee', i don't think it's a thing at my bank. They could try to scrape the account number though, I think in the States that may be enough to try to debit someone's account.
- BriggyDwiggs42 2y agoThis is a great example of why a search engine shouldn’t overtly let people pay them to alter rankings lol.
- EasyMark 2y agoAnd why ads should be to the side at the very least and not mixed with search results
- account42 2y agoI am continually surprised that in a country as litiguous as the US companies can continue to sell advertising space and then just shrug when the buyer uses that space to defraud someone.
- somehelpdeskguy 2y ago"...with a replay attack in the background." Wouldn't this be MITM?
- dools 2y agoI called this a "replay attack" because it sounds more like this: "A replay attack in a network communications setting involves intercepting a successful authentication process—often using a valid session token that gives a particular user access to the network—and replaying that authentication to the network to gain access" Even though this wasn't a session token, it was an authentication process and token, gathered from a fraudlent source and replayed to a valid source. MITM is: "A man in the middle (MITM) attack is a general term for when a perpetrator positions himself in a conversation between a user and an application—either to eavesdrop or to impersonate one of the parties, making it appear as if a normal exchange of information is underway." So to me a MITM would be more like using a wifi access point to access the correct banking URL, but the service carrying the data was acting maliciously.
- leni536 2y agoI'm not familiar with the nuances of terminology, but I would expect MITM to only apply when you (and your computer) actually attempt to connect to service A, and a malicious actor X intercepts that communication. Phishing is different in the sense that you connect to the phishing page directly, and it may or may not replay some of your inputs to the actual service it is phishing.
- ReK_ 2y agoI guess theoretically phishing could be considered MiTM, but the latter term generally implies the attack is fully transparent to the user, whereas phishing convinces the user to insert the malicious party themselves.
- aareet 2y ago> So really the ideal is not just having an app that generates a token but one that generates a specific type of token depending on what type of transaction you're performing and won't accept, for example, a login token when adding a new payee. I haven't seen any bank with that level of 2fa yet, has anyone else? Some banks in India have a separate “transaction password” that’s required to operate on the account vs just login and view balances. It’s not a rotating token, but it’s somewhat close to what you’re suggesting.
- whodev 2y agoThis almost happened to my S/O. Luckily I had setup NextDNS to block newly registered domains along with a list of uncommon TLDs so the site got blocked.
- TacticalCoder 2y ago> Luckily I had setup NextDNS to block newly registered domains along with a list of uncommon TLDs so the site got blocked. I go further: I generate tens of thousands of variants of all the "sensitive" websites we use (like banks and brokers). All the "levenshtein edit distance = 1" and some of the LED = 2. All variation of TLDs, etc. I blocklist most TLDs (now that most are facetious): the entire TLD. I blocklist many countries both at the TLD level and by blocking their entire IP blocks (using ipsets). For example for "keytradebank.be", I generate stuff like: # Generated by typosquat.clj for keytradebank.be (9809 entries) 0.0.0.0 keeytraebank.be 0.0.0.0 kebtradebank.be 0.0.0.0 kytradebani.be 0.0.0.0 keytrxdebak.be 0.0.0.0 kewytadebank.be 0.0.0.0 keytgadbank.be 0.0.0.0 aeytradeank.be 0.0.0.0 keytradebsan.be 0.0.0.0 keymradebnk.be 0.0.0.0 kytradeb9nk.be 0.0.0.0 ketrade-bank.be 0.0.0.0 keytradbeban.be 0.0.0.0 eytradebafk.be 0.0.0.0 keytraebank.ee 0.0.0.0 keytrad3bak.be 0.0.0.0 keytradebzn.be ... I don't care that most make no sense: I generate so many that those who could fool my wife are caught by my generator. I then force the browser to use the "corporate" DNS settings: where DoH/DoT is forbidden from the browser to the LAN DNS. I can still use DoH/DoT after that if I feel like it. So any DNS request passes through the local DNS resolver (the firewall ensures that too). My firewall also takes care of rejecting any DNS attempt to an internationalized domain names (by inspecting packets on port 53 and dropping any that contains "xn--"). I don't care a yota about the legit (for some definition of legit): "pile of poo heart" websites. My local DNS resolver has 600 000 entries blocked I think, something like that. I then also use a DNS resolver blocking known malware/porn sites (CloudFlare's 1.1.1.3 for example). So copycat phishing sites have to dodge my blocklist, the usual blocklists (which I also put in my DNS), then 1.1.1.3's blocklist. P.S: some people go further and block everything by default, then whitelist the sites they use. But it's a bit annoying to do with all the CDNs that have to be whitelisted etc.
- weberer 2y agoThe Nordea ID app tells you if you're verifying a purchase and shows how much you'll pay.
- EGreg 2y agoI never understood why these sms confirmations don’t tell you what you are actually confirming. They should also tell you when some major change was made. Seems so silly!
- arp242 2y agoWhen I tried to pay on a website a while ago I kept getting "unknown error". Fast forward about an hour waiting in the helpdesk phone queue, and turns out you need to set up a special password for that. This is not an "unknown" error, it's a known error... Why can't it just show me? Sigh. I wonder how many people they've need to "help" with this. Yes, I know there's tons of old code in many banks, but they would have saved money if they had a single developer work on this full-time for a month or something. Support people may be cheaper than devs, but they're not free.
- AegirLeet 2y agoTurns out ads aren't just annoying little acts of psychological terrorism that eat up a lot of bandwidth and computing power, they are also the #1 vector for spreading scams and malware on the web. In other words: If you're trying to improve your security posture, installing an ad-blocker is one of the best things you can do. If you have less tech-savvy friends and relatives, I would strongly recommend setting up uBlock Origin for them.
- DowagerDave 2y agoTIP: I sold my senior mom on uBlock Origin because YT ads are so obnoxious. The added benefits are extra security and performance improvements. She was even able to understand that if something doesn't seem to be working right (like a banking site) "turn it off and try again".
- baxtr 2y agoAnd at the same time ads are the reason we can use many services for free.
- dpkirchner 2y agoIt's to the point that even the US government (even with all its faults and lobbying) recommends using an ad blocker for this reason.
- slothtrop 2y agoWhy isn't there any market fulfillment for "safe, non-intrusive ads", on the part of a vendor? Is it because it's not possible, or not worth the overhead either because of cost or no effect on consumer behavior/blocking? This seems like it ought to be low-hanging fruit. I would have less aversion to clicking on ads if I did not default to it being a security risk.
- schmorptron 2y agoI'm paranoid enough at this point that I check that the Cert authority for my bank is the one I know it to have before I log in on the website.
- TacticalCoder 2y agoWhat's your process? Where do you save the cert? I'd be interested in automating that.
- schmorptron 2y agoOh nah, I just check the lock icon in firefox, and it's a pretty unusual (and not publically accessible) cert authority so I'd notice if it's a different one
- brightball 2y agoI still don’t understand why banks just don’t use FIDO2/WebAuthn yet. I’d much prefer to use a Yubikey over all other options at this point.
- ReK_ 2y agoBecause banks are financial institutions and every decision they make is based in that. If the cost of insurance is less than the cost to actually secure the system, they will choose that every time. Banks and payment processors have some of the worst technical debt. For example, a lot of transactions are processed using the ISO8583 standard, a binary bitmap-based protocol from the 80s. The way cryptography was bolted onto this was the minimum required to meet auditing standards: specific fields are encrypted but 99% of the message is left plaintext without even an HMAC.
- timr 2y agoI don't work at a bank, but I do work in fintech, and this strikes me as excessively cynical. The reason banks are slow about this stuff is not necessarily because "it's cheaper" (though maybe it is), but because the complexity of any change is simply off the charts: money-related logic must work correctly, to a far higher standard than almost any tech company. It makes you conservative, in the same way that demanding 99.999% uptime is exponentially harder than demanding 99%, and makes moving quickly essentially impossible. (Also, of course, they're probably working on COBOL stacks that were written in 1978.) For a bank, pile on top of that mountains of (often conflicting) regulatory review, such that just about any change sounds the alarm for armies of nearby lawyers to swarm upon you and bury you in paper. All it takes 0.1% of annoyed users filing complaints that they can't access their accounts, and you might well be looking at a steep fine, a class-action lawsuit, or worse.
- Tepix 2y agoKraken is a cryptocurrency exchange that utilizes (at least) two different TOTP codes, one for login and one for money transfers.
- smeej 2y agoFor a long time (still?) Kraken also refused to add SMS 2FA as an option due to its weak security. I still don't see how that's worse than no 2FA at all, which was an option, but I appreciated that they were banging the "SMS 2FA isn't very secure" drum.
- Negitivefrags 2y agoIt’s worse in a lot of implementations because often SMS is often used as part of a recovery flow in cases where you lose the first factor. I find it more secure in some contexts to never give a company my phone number at all if possible, so that it simply can’t be used as any kind of authentication no matter what.
- smeej 2y agoYeah, I'd draw a hard line between "SMS 2FA is better than no 2FA" and "SMS should never become a single-factor recovery method." I agree SMS should never be an option for single-factor recovery.
- renonce 2y agoMy bank app asks for different tokens for different operations. A code for login, a code for transfers (the code needs to be generated with the payee account number as input). So it’s not a problem of tokens vs SMS.
- Tuna-Fish 2y agoThe way both my banks work is that I log into the bank, do something that requires confirmation, and then I need to go open my app to confirm it, and it shows all the details for what exactly I'm confirming in the app.
- dsego 2y agoI believe it's the 3d secure protocol, my bank has it, usually a push notification or with a token.
- shortrounddev2 2y agoI've noticed my browser has started recognizing URLs that look similar to legit URLs of bigger companies and then warns me that the site is likely a phishing site. Sometimes it gets false positives for URL shorteners (like goo.gl instead of google.com)
- ptero 2y agoWas this in the US or elsewhere, what was the amount and how long did it take to notice? Just curious. In the US the bar to pull money out of an account is pretty low. Most banks would allow reasonably-sized transfers out with just routing and account numbers. I was stunned by this, but this is the reason utilities and stores can pull your money without you even talking to your bank. Just give them the info. And that information is not secret, it is printed on your every check. The flip size is that for those "convenience" and service payments the money is easy to get back: banks, at least traditional, will bend over backwards to prevent being seen as enabling fraud.
- dools 2y ago> Was this in the US or elsewhere, what was the amount and how long did it take to notice? Just curious. It was in Australia, amount was thousands of dollars, she noticed when she was asked to enter yet another code and all of a sudden it made her snap out of her "autopilot" and take notice and look at the URL and other details. So as soon as she realised that something was fishy, she logged into the correct site, then saw the money was gone. > In the US the bar to pull money out of an account is pretty low. Most banks would allow reasonably-sized transfers out with just routing and account numbers. I was stunned by this, but this is the reason utilities and stores can pull your money without you even talking to your bank. Just give them the info. And that information is not secret, it is printed on your every check. The flip size is that for those "convenience" and service payments the money is easy to get back: banks, at least traditional, will bend over backwards to prevent being seen as enabling fraud. This was a "pay anyone" transfer. So money was being transferred to a bank by BSB/Account number in the background. The bank required a code when a new Payee is added, but the codes were not differentiated, so she was asked for a code to login, then told the code was wrong and asked for another code. In the background the real banking site to which her actions were being replaced had successfully logged in and had initiated a transfer to a new Payee. The real banking site asked the attackers for a code to add the new Payee, the fake banking site asked her for a new code to login. The thing that really enabled the attack is that the same code generator was used for both codes, without any indication that a different action was being performed.
- 2y ago
- dtx1 2y ago> So really the ideal is not just having an app that generates a token but one that generates a specific type of token depending on what type of transaction you're performing and won't accept, for example, a login token when adding a new payee. I haven't seen any bank with that level of 2fa yet, has anyone else? My local german bank uses an App specifically for 2fa. When i log in i have to approve the login within the app and the website redirects automatically. It shows me that I am approving a login or a transaction with all the transaction details. Since I don't enter my second factor into the browser, a replay wouldn't be possible and it would be VERY obvious to spot the difference between approving a login and approving a transaction. German Sparkasse for those that care.
- lolinder 2y agoIt's worth reminding your loved ones that the FBI specifically recommend using an ad blocker in search engines to avoid exactly this kind of scam [0]. > Use an ad blocking extension when performing internet searches. Most internet browsers allow a user to add extensions, including extensions that block advertisements. These ad blockers can be turned on and off within a browser to permit advertisements on certain websites while blocking advertisements on others. [0] https://www.ic3.gov/Media/Y2022/PSA221221 https://www.ic3.gov/Media/Y2022/PSA221221
- paholg 2y agoI'm curious if the different SMS message would have mattered in practice. I for one don't ever read those messages, and Android at least will usually copy the code for you making them even easier to ignore.
- dools 2y agoI read those messages. The ones from one of my banks that uses SMS and differentiates them, says "your code to do BLAH is BLAH". I was actually saved from phishing once because my credit card company included the vendor and the amount in the transaction SMS and it was for a different site and a much larger amount than what I thought I was spending.
- renewiltord 2y agoJust use apps. Apple protects.
- callalex 2y agoNope. Apple participates in the same pay-for-search-placement scheme, and therefore will happily distribute the same kinds of scams. https://usa.kaspersky.com/blog/dangerous-apps-in-app-store/28975/ https://usa.kaspersky.com/blog/dangerous-apps-in-app-store/2...
- renewiltord 2y agoWell, TIL
- callalex 2y agoIt's really incomprehensible, whatever minuscule revenue Apple is getting from running this protection racket, I mean ad network, must be minuscule compared to the potential damage they cause to their users and brand. But I guess that's next quarter's problem.
- renewiltord 2y agoTheir ad business is generally booming but the brand rap can’t be worth letting these in. OTOH maybe it’s either all in or don’t bother. There’s no way to staff reviews at the scale you need an ads business to work.
- idontwantthis 2y agoThat’s fun to read about because my bank forces you to use their integrated 2fa which always rejects the first code you put in.
- funmi 2y ago> So really the ideal is not just having an app that generates a token but one that generates a specific type of token depending on what type of transaction you're performing and won't accept, for example, a login token when adding a new payee. I haven't seen any bank with that level of 2fa yet, has anyone else? HSBC actually has this. All of their country-specific apps allow you to generate a different security code depending on whether you want to login to the website, verify a transaction (e.g. transfer funds to payee), or re-authenticate (e.g. to change your personal info, like your phone number). Here's a screenshot of what that looks like on their Australia app (similar screens in their US and UK apps): https://www.hsbc.com.au/content/dam/hsbc/au/images/ways-to-bank/online-banking/9795-generate-security-code-2-1280x720.jpg https://www.hsbc.com.au/content/dam/hsbc/au/images/ways-to-b... They've had this for years. I'm not quite sure why this isn't a standard yet or at least been adopted by other US banks.
- TacticalCoder 2y ago> The site was an immaculate knock off ... Then I can picture a great way, locally, to screw these knock off big times. Either the site is a great knock off, visually similar (if not identical) or it won't fool people, right? So what about this: what about the browser saving, locally, screenshots of the login pages you visit. Then, when a new login is made, compare, visually, the page to what's saved and see if any saved pages are similar? "Oops, the page www.banklng.com looks nearly identical to www.banking.com which you visited previously, they're probably trying to scam you!".
- recursive 2y agoWhen a measure becomes a target, it ceases to be a useful measure.
- Eisenstein 2y agoAnother step everyone will ignore because it isn't a problem for any particular person until it is.
- TacticalCoder 2y ago> Another step everyone will ignore ... Well then enforce it, at the browser level.
- breischl 2y agoI feel like PassKeys and browser-integrated password managers both solve this problem better already. And yeah they're extra things to do, but so is this.