Hacker News new | ask | show | jobs
by krinchan 809 days ago
Just say BofA.
1 comments

Not actually. Even if you enabled passkey, you still can login to their phone app via SMS. So it is not more secure. People who knows how to do SMS attacks certainly knows how to install a mobile app. And BofA gave their customers a fake assurance.