Hacker News new | ask | show | jobs
by spixy 28 days ago
Which is difficult since smartphones are used as 2FA, and not every service has web interface, only mobile one (some banks, chats, dating, uber, etc..)
1 comments

m.uber.com

Never had a bank without a usable web app. You should consider the same!

Stop shooting the web in the foot.

With the banks I use, the difference is:

A) on mobile, use my face or 6-digit pin to get in.

B) on web, go get my wallet where my ID is, hunt for the USB digital ID reader, grab a USB-C adapter, put everything together, and either confirm the certificate with a PIN I always forget or use the bank’s own calculator for a login code.

Not exactly a fair setup for the web.

My bank supports Ubikeys for 2FA, but you cannot disable the SMS authentication. So you may as well use your phone.
Way more common than it should be.
My bank supports both SMS and push notification for 2FA. Also PIN code in an app is probably local and doesn't protect from a kernel exploit. I hope you do not keep too much money in the bank.
I think the in-app PIN code and/or biometric ID is merely a convenience to avoid typing your password all the time. I’ve never used a banking app that doesn’t offer both, and then ask for your real login details every now and then.

As a stay-at-home dad: my bank account is indeed not worth attacking.

If you want to sacrifice security for convenience, that’s a different conversation than “I’m forced to”.

Storing credentials and passkeys in browser password manager (backed up to Google or Apple) and using autofill is pretty normal stuff for mobile users today.

(Not being able to find your credentials or keep your gear in order is also not a great reason to shoot the web in the foot!)