|
|
|
|
|
by seryoiupfurds
1870 days ago
|
|
Interac E-Transfers are great, except that I wish they didn't train people to click a link from their email and type in their bank password. Sure, it redirects to a login page on your own bank's web site, but how does a non-technical user know it's not a phishing lookalike? Really, the existing autodeposit feature would be perfect if it let you log in to your online banking and confirm pending transactions before autodepositing them. For that matter it would be nice if the email gave me a string I could paste into my online banking to get to the existing confirmation page. It's all much better than having to link your bank account to some third party or give away your credentials though. |
|
Similarly, we won't be able to get rid of email but if clicking a link in an email opened an app instead of a webpage, it would be a lot harder for phishing websites to pretend to be my bank. (Assuming I'm expecting a mobile app, of course. A second line of defense is that my password manager might not prompt me to fill in the password because the URL doesn't match. But even that's not foolproof.) Even better would be if Interac E-Transfer itself was an app I could sign up for, then it could send me a push notification and I could skip my inbox entirely for these sort of transactions.
Of course, the only reason I trust apps more than websites is that I went to download them previously, rather than clicking a link that just showed up in my inbox. To that end, Gmail and other email providers have immense power if they created a design which could highlight emails from senders I've seen before as "trusted" and those from unknown senders as unknown.
Things get more gray-area though when the system itself fails: You can request money from anyone using Interac E-Transfers, and that means spammers could hijack a bank account and request money from friends and relatives you've recently sent e-transfers to, for example. Those emails would then appear as "trusted" and there's not much you can do to stop that, it's the cost of making money transfer "easy".