3 ms·
While this is all good(and it is, no sarcasm intended). What I really want/care about is banking sites/companies. If this website could also compile a list for
by jug6ernaut 13y ago
While this is all good(and it is, no sarcasm intended).
What I really want/care about is banking sites/companies. If this website could also compile a list for these institutions that would be awesome. It truly amazes me how most major banks lack 2fa.
- alexchamberlain 13y agoI feel that I should point out that nearly every UK banking site uses 2fa for transactions, and many as an option for login. This only comes with chip & pin.
- joe_inferno 13y agoI setup a bank account in Germany in 2007 that issued me a hardware token generator (I forget the name of the bank). It was my first experience with 2 factor auth, and I'm a little surprised that I have yet to see it implemented with banks in the US.
- luchs 13y agoToday, these usually work by transmitting some code via a flickering field on the website. You insert your bank card into the generator, hold it to your screen and type the number it shows on the device. The German Wikipedia has some pictures: http://de.wikipedia.org/wiki/Transaktionsnummer#chipTAN_comfort.2FSmartTAN_optic_.28Flickering.29 http://de.wikipedia.org/wiki/Transaktionsnummer#chipTAN_comf...
- jmspring 13y agoA long while back, American Express through it's Blue card line actually proposed the use of a card reader and physical token (the card for internet purchases). It never took off. An article on such -- http://bits.blogs.nytimes.com/2008/12/05/a-credit-card-loses-its-high-tech-cred/?_php=true&_type=blogs&_r=0 http://bits.blogs.nytimes.com/2008/12/05/a-credit-card-loses... That said, their own site (at least when I last changed my password) had some fairly silly password rule restrictions like no punctuation.
- coffeecheque 13y agoI agree. Banking login options are far from the most secure. My phpBB login passwords are much, much more secure than my banking. I just went to send a web-form email to my bank about it, and got this error: > Input contains invalid characters. e.g. angle bracket, quotes, slashes, semicolon. If a web form doesn't allow basic punctuation, I don't hold out much hope for a two-factor authentication system.