3 ms·
this is such a hilariously bad idea, its like knowingly installing malware on your computer - malware that has access to your bank account. please god, any sane
by 38 2y ago
this is such a hilariously bad idea, its like knowingly installing malware on your computer - malware that has access to your bank account. please god, any sane person reading this do not install this, you've been warned.
- layer8 2y agoAccess to your bank account typically requires 2FA.
- ceejayoz 2y agoNot necessarily if the device is already trusted!
- layer8 2y agoOn a desktop? Where I live all banks require a mobile app (which in turn requires 2FA for login and also for any transaction) or else separate authentication hardware.
- ceejayoz 2y agoThe US doesn't have 2FA for transactions. I can't think of a single bank app/site that requires 2FA on every login; most have a "trusted device" option and that cookie becomes your "something you have" second factor for future logins.
- oezi 2y agoThe PSD2 directive mandates the 2nd factor to be able provide you with an independent means of displaying the transaction you are performing. This essentially means the 2nd factor must be an device.
- superkuh 2y agoYikes! Requiring a smart phone (or other extra hardware) is pretty exclusionary for a service that all people need like banking. First time I've heard about practices like that. I hope it doesn't spread.
- layer8 2y ago“or else separate authentication hardware.” It doesn’t require a smart phone. You can also get a ~$25 photo TAN device or similar.
- oezi 2y agoIn the EU no bank is allowed to operate without safe 2FA (no SMS) due to the PSD2 directive.
- tpm 2y agoSms is still allowed I think (at least one of my banks still allows it despite also having other options).
- lanstin 2y agoIn the US "people with smart phone" is larger than "people with a computer." The real people being left behind are "people without email". I have a neighbor in this state and we occasionally have to make a temp email to qualify for various discounts or the like. It would only muddy the waters if we anyone thought he actually has an email.
- PhilipRoman 2y agoThere are usually alternatives that you can get, like a little calculator-looking thing that generates one time codes. What really surprises me is that despite needing 2FA to make any transactions, some companies like Amazon still have the ability to magically get money from my account using only the info on card.
- makingstuffs 2y agoWhere I live banks generally require you to do some form of in app verification for purchases online TBF. This is regardless of it being from a trusted machine or merchant from which you’ve purchased before. There are probably some cases where this is not true (thinking people without a banking app) but I get the 3D verify for every transaction I make regardless of payment method or vendor.
- timeon 2y agoAs example, people use spyware willingly. Safari has feature that 'it can prevent trackers' - if you want. Safari can't do it automatically for everyone, because spyware is normal software now. Every spyware now has: "We value your privacy" and people are ok with that. It is going to be same with malware.
- botanical76 2y agoThis would be a valid concern if it were fast enough to do anything dangerous before you could stop it. Per the project readme, it acts at a snail pace, so you would have to be very irresponsible to suffer damage from use of this app. That said, if there isn't already, perhaps there should be a !!!BIG WARNING!!! around leaving it to its own devices... or rather, your devices.
- prmoustache 2y agoDo you really stay logged to your bank account? I only access mine from a VM that does just that and I still have to log on every single time.