this post was submitted on 20 Dec 2024
92 points (100.0% liked)

Cybersecurity

23 readers
7 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Rules

Community Rules

founded 2 years ago
MODERATORS
 

So, why do almost all banks, in the U.S. at least, only support the worst 2FA authentication method exclusively? And, this article doesn't mention SIM-swap attacks, which are unavoidable. It can't be that difficult to support an authenticator app.

https://gizmodo.com/feds-warn-sms-authentication-is-unsafe-after-worst-hack-in-our-nations-history-2000541129

#Cybersecurity

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 8 points 2 days ago* (last edited 2 days ago) (2 children)

My CU offers auth app support. Yet my big name options provider doesn't. It's so stupid.

[–] [email protected] 2 points 2 days ago (1 children)

Similar on my end.

The main CU I work with will let you verify logons inside their mobile app when logging on from like a desktop (text/call only for mobile logins), but the high yield savings I have at a much larger name bank is text only for 2FA (Which is not a mandatory nor default setting BTW).

What's everyone's opinions on verifying logins via mobile apps?

[–] [email protected] 3 points 2 days ago

Anything but it being STUCK on my phone. Lose your phone and you're up shits creek. Reading through my banks info crap about their 2sv, every 2nd paragraph about any issue involves deactivating 2fa, and resetting it all up again.

It's being stupid. I want 2fs through an authenticator which I have locked down with another authenticator. I also have yubikey for quicker access for certain things.

[–] [email protected] 1 points 2 days ago

I love my CU, but their app is an afterthought that tries (unsuccessfully) to use google authenticator. And if you try to call for tech support, you get whatever teller was unlucky enough to answer the phone.

Bless their hearts; they're trying. And I'd rather give them my business than any for-profit bank.