3 ms·
That's because they're stupid or doing something suspicious, probably both. There's legitimately zero reason to allow 2FA only on your own propreitary app. You
by array_key_first 1y ago
That's because they're stupid or doing something suspicious, probably both.
There's legitimately zero reason to allow 2FA only on your own propreitary app. You can't even make a financial argument - allowing other TOTP methods is cheaper because now you don't need an app!
- weikju 1y ago> That's because they're stupid or doing something suspicious, probably both Small comfort for whoever needs to use that bank. This is the disconnect geeks and Free Software needs to bridge to make any headway.
- exe34 1y agoit costs basically nothing to change banks. you sign up to a new one and they transfer your account and direct debits. you just tell your employer where to send your next salary payment.
- weikju 1y agoSometimes it’s more complicated than that. And the other banks aren’t any less “stupid”.
- array_key_first 1y agoI mean, I concur, but ultimately I can't fix shitty banks being shitty. No geeks can. Banks have been shitty for a long, long time. Do you know how we usually stop them from being shitty? Forcefully, with legislation.
- buzer 1y agoUnfortunately the EU regulation makes the truly user controlled 2FA methods essentially non-compliant. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32018R0389 https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... > Article 7 Requirements of the elements categorised as possession > 1. Payment service providers shall adopt measures to mitigate the risk that the elements of strong customer authentication categorised as possession are used by unauthorised parties. > 2. The use by the payer of those elements shall be subject to measures designed to prevent replication of the elements.
- jojobas 1y agoThis says something along the lines of "it should be hard to extract the TOTP secret". However if you can get so far as to get the secret from the TOTP app, you can as well back up the entire phone and restore elsewhere, can't you?
- nh2 1y agoNo, because phones that lock keys in hardware effectively prevent that, and that works only with hardware that prevents its owners from having full control an doing what they want with their hardware. "Unextractable keys" works with hardware that you don't "truly own".