Hacker News new | ask | show | jobs
by auxym 2950 days ago
To my knowledge none of the big canadian banks support U2F or TOTP.

Accounts can also be used to log in to the CRA website.

3 comments

When you sign up to CRA's online control panel... they actually make you tick a box that says in essence:

"we're not responsible if we get hacked and lose all of your CRA related data to some random hacker... that's your fault"

CRA = Canada Revenue Agency (Canada's IRS)
= CCRA: Canada Customs and Revenue Agency
Grrr. Google Authenticator and such are free. It would be mostly user support costs to deploy. Heck, could even SMS or robodial (Twilio etc) a TOTP code for people without smartphones.
> Heck, could even SMS or robodial (Twilio etc) a TOTP code for people without smartphones.

SMS is not secure for this purpose since there are many attacks which allow you to sniff SMS messages.

There's no need for that, TOTP runs everywhere, including J2ME apps installed from WAP.