|
|
|
|
|
by kevin_nisbet
2950 days ago
|
|
Actually I think TD just launched a SMS based two factor, I set it up on the weekend (I got prompted when I logged into EasyWeb, and it's also in my security settings). It's SMS based, and can be configured on how aggressive it is (when you change IP/computer, or every time you log in). I would much prefer to see a second factor like TOTP, U2F, etc as the problems with SMS based second factor are well documented, but I'll take what I can get. |
|
That’s why proper banks should use 2FA mechanisms that will ask the user to confirm the transaction on a second device (e.g. photoTAN or similar).
Of course, this won’t help against attacks if both devices are compromised or you are using the second factor device to access the system, but it’s still better than TOTP.
And, of course, TOTP is still way better than SMS 2FA or no 2FA.