Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Funny that bank software needs approved phone, but runs absolutely fine in the browser. That to me sounds like collusion - something that regulators should look at. There is absolutely no need for banking app to require "legitimate" Android or other operating system.


Increasingly, browser-based online banking requires authentication with a proprietary smartphone app, where it used to accept other forms of 2FA


As terrible as proprietary app 2fa is, it still beats the tar out of SMS or email 2fa, security-wise. I don't get why my bank, who used to be pretty cutting edge, never implemented TOTP or passkeys...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: