Comment by macintux
2 days ago
This comment is worrisome:
> My Chase bank account was hacked early this year despite having 2 factor authentication, and when I contacted them to ask how, they said because the person used my actual driver’s license to verify their identity and remove my security features from the account.
I feel like that should require an in-person visit, as troublesome as that might be. A picture of an ID is not the same thing as presenting the actual ID
I think Pope Leo would respectfully disagree.
https://www.nytimes.com/2026/05/05/us/pope-leo-xiv-bank-cust...
I almost mentioned that situation in my reply, but that's kind of the exception that proves the rule. Even in that case, someone should need to physically intervene, especially with high profile people like politicians or celebrities
Can't read the article, is there a summary
I agree, particularly when it comes to removing security features. However these days it's often possible to open an account without ever showing up in person. So I think the requirements would need to vary per-account and ideally be selected by the customer. (Personally I would opt out of any and all account changes without an in person visit if I could.)
Sometimes I feel it's a blessing that for even a minor change my banks make me visit the branch and ask for my real Govt issued IDs (often more than one) while also make me do the online auth (Govt ID; needs OTP and biometric) and still make me submit self-attested print-outs and then add a delay to it (and even reject once in a while if they feel the signature didn't match..and then the cycle restarts :D). I know, I know - there is a solution of this on hn and it will even scale handsomely. But I'd rather have my hard earned savings safe.
Wouldn't this also mean Gmail, Facebook, etc are no longer safe? The person can simply provide this documentation as proof they own the accounts and claim they were hacked.
Facebook is definitely safe. I provided my ID to try to regain access to a hacked account and they never even responded to the request.