|
|
|
|
|
by consp
3781 days ago
|
|
[rant mode]
From personal experience I can say that true crypto knowledge is not needed as a Bank CISO. Just keep repeating 'hardware token only, hardware token only' and everyone will trust you opinion at the expense customer experience and true security. The reason that most banks use the identifier+card method is because they don't want to change. (or don't see the benefit of an improved customer journey without actual loss of security and improved/lowered cost)
[/rant mode] |
|
>at the expense customer experience and true security
I always call this "lazy security"[1] and it's what you get when you hire some security professionals to "make it secure". It's a mistake to separate security from product design, the two should inform each other to come up with a compelling product that remains secure. Separating them misaligns interests, the security team will push for a change that improves security irrespective of any impact it may have on user experience.
I think Touch ID is a great example of how a novel solution can improve both security and usability.
At Mondo we are committed to investing time and energy into finding these solutions, security at the expense of user experience is a last resort.
[1]https://medium.com/@danielchatfield/lazy-security-32acc31fbd...