5 ms·
Interesting, I've always wondered why so many banks use this system online instead of something more robust like two-step auth.
by latimer 14y ago
Interesting, I've always wondered why so many banks use this system online instead of something more robust like two-step auth.
- dfc 14y agoThe only reason the banks use these systems to begin with is the FFIEC guidance. These "improvements" were not voluntarily put in place by forward thinking bankers, they had to because their regulators told them to. So it is all about the cost of the system. Before anyone says Chase/HSBC makes X billion dollars profit keep in mind that these regulations also apply to smaller community banks with 5 Billion in holdings. Keep this in mind when you assess any of these systems; the authentication systems are not put in place to manage customer risk, they are put into place to manage regulatory risk.
- mortehu 14y agoWhen I signed up for USAA, by default they had a silly authentication system based on "security questions". I was very disappointed until I found out that they support several mechanisms, and allow you to disable the ones you won't use. Hence, I use the one where I combine my password with a token generated by a mobile app. Maybe other banks have alternate authentication mechanisms stashed away as well?
- snowwrestler 14y agoThey do. Bank of America, which to my knowledge is the largest bank that still uses the "security image", also allows users to enable 2-factor authentication via SMS.
- yourapostasy 14y agoNot just via SMS, but you can also purchase a token card called a SafePass.
- svachalek 14y agoI've only seen two step used to validate the user to the server. Are there sites that use two step to verify the server to the client?