| > It is better if [...anyone...] include a security warning / specific reason the code is sent with the password reset pins and similar credentials. I think anyone building such systems (either via e-mail or SMS or whatever) should at least remember THIS. Send something like this via SMS: > The password reset code you requested via our website is 12345. We will never ask you for this code except when you requested a password reset. 1. What is requested
2. How was it requested
3. Is it safe to pass this to some other human being Okay, 4. in better English ;) As opposed to: > Your caller verification code is 12345, please read this code to your banking agent to verify your identity. Also, ChipTAN is great: https://en.wikipedia.org/wiki/Transaction_authentication_num... If your bank would use this, it would be require extraordinary smart social engineering (or a really naive user). |
For example, for online transactions, the SMS includes a warning to not share the code with anyone, while SMS codes for telephone banking tells you to share the number with the representative.