Hacker News new | ask | show | jobs
by YPPH 1369 days ago
Password length isn't necessarily cause for concern in this context. See: https://www.troyhunt.com/banks-arbitrary-password-restrictio...

As for MFA, the only Australian bank that seems to do it right is Macquarie (who let you remove SMS 2FA and replace it with a decent authenticator app). A handful will issue physical tokens on request (eg HSBC).

1 comments

Bendigo also do physical tokens as well as app based 2FA.

Macquarie have unpersoned me before (cancelled all of my accounts with no explaination or notice, on a Friday afternoon). I've heard of it happening to others too. As such, I make it my mission whenever dealing with large scale finance in business to refuse to deal with them.