|
|
|
|
|
by fc417fc802
294 days ago
|
|
Not in the US, at least so far. If that were ever to come to pass I would be in danger of becoming unbanked. I flatly refuse to install third party proprietary software on my phone (I grudgingly accept firmware blobs for lack of a realistic alternative). Here the majority continue to use SMS based 2FA rather than supporting TOTP or hardware tokens. Note that TOTP can be handled by any app of the user's choosing, doesn't facilitate attestation or any other user hostile practices, and in practice means that an attack requires physical theft of the device. While the theory might differ, in practice the effective security level is equivalent to other (objectionable) schemes. |
|
The banks are probably using the same standard behind the scenes, but they don't allow alternate TOTP apps. There's no point where they give you a key to set it up in an alternate app.
I suppose part of the point is a lack of trust in users' ability to handle their own security, and the possibility that they may provide such a key to a compromised TOTP app.
> hardware tokens
It'd be excellent if banks moved back to purpose-specific hardware like that. Even better if it were some standard with multiple providers, like FIDO2.