Hacker News new | ask | show | jobs
by warrenski 397 days ago
Here in South Africa all the banks I know of moved away from SMS text messages for 2FA ages ago, and perform authentication in-app with biometrics instead. Having a banking app installed on your phone is pretty much mandatory, and criminals have no doubt grown wise to this fact. So what happens when someone holds a gun to your head and forces you to perform a large transfer of funds from your phone? I'm sure the banks will try convince you that their fraud detection systems will come to your aid.

One bank here recently introduced a duress-PIN, which when entered, will commence monitoring and send help, but they still don't offer any guarantee of a refund. Another bank allows you to change their app's icon and name, in an effort to masquerade as something less recognisable.

I'd much rather delete the apps, unlink my devices from my bank accounts and use a TOTP authenticator app instead.

1 comments

> I'd much rather delete the apps, unlink my devices from my account and use a TOTP authenticator app instead.

I'm not clear how this changes the gun to your head scenario.

I would want to see numbers before making policy changes based on potential armed robbery.