← Back to context

Comment by jojobas

6 months ago

Some banks require app confirmation for PC-initiated transactions, using play integrity requiring apps. Cause security, you know.

I think it's time to look for a new bank.

  • In my country we have a large religious community that eschews smartphones. Due to this no company or government agency requires a smartphone for service.

It's because it's way easier to install malware on PC than mobile. None of us are immune either. In recent times there has been malware distributed by common NPM packages as well as game mods. Every NPM package you install has the ability to steal your browser session tokens and the only thing stopping the attacker from actually logging in and spending your money is the fact it has to be confirmed on your phone.

  • Choosing between a risk of that and preinstalled non-removable malware in every phone? Tough one, I know.

  • That doesn't require a bank approved app - we already have authentication mechanisms that are standardized.

    People do proprietary bullshit because they want to do proprietary bullshit. Anything else is made up.

What kind of transactions require this? Normal bank transactions don't, right?

  • Fraud prevention on my primary transaction account requires 2FA for every transfer.

    The only supported 2FA is the bank's own dedicated 2FA app.

  • Depends on the bank's policies. Currently it tends to be when you transfer to a new destination and/or above a certain amount. I could certainly imagine a bank requiring it for every PC-initiated transaction as and when they reach a point where most normie customers are using their app.

  • My brokerages require it every time I login from a computer. My bank will require it if it can't find a cookie from a previous login session. Occasionally, my bank will require it seemingly randomly since I usually log in at least once a week from my laptop yet every couple of months or so I have to reconfirm on the app or another secondary method.