Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Phone 2FA would be good but a bit pointless because the 2FA app is on the phone, and so is the banking app.

This is exactly like having a physical token with you. If it gets stolen, they have the tokens. But, at least, having token on the phone app is waymore convenient for customers and also has another layer of protection (think of the fingerprint/passcode ecc you need to access your phone)



Over here in EU land the mobile identifier app is pin protected. Think Google Authenticator but with a pin to access the tokens.

You need my phone unlocked and my six digit pin in order to identify as me.

There are still possible social engineering attacks, though.


Yes, I actually am in EU land myself, and I forgot about that




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: