![]() ![]() ![]() |
|
Do surveys for Beer money (referral link) - Octopus Group
Link for buying beer (not affiliated, just like beer) - Good George
Do surveys for Beer money (referral link) - Octopus Group
Link for buying beer (not affiliated, just like beer) - Good George
ajobbins:1080p: I think Kiwibank's system is the best. You can set it to ask you a question only you know the answer to and it will request a couple of letters from each answer every time you log in.
It really is an ingenious method of extra security without requiring you to carry a piece of plastic about or a dongle.
Obviously, if you answer their questions with information that others already know about you then it is not effective but that would be on you rather than Kiwibank.
It's just a bit cumbersome, and isn't true 2FA. 2FA is supposed to be something you know (a password) and something you have (A token). Kiwibank's is a something you know and something you know - or possibly a something you know and something others might know too.
And the fact you need it even to log in and check a balance or move money between your own accounts is just painful.
Kyanar: Could be worse - Westpac's security is something you know (your password), something WE know (blackbox analysis of login to determine if trustworthy or not) and something everyone knows (your birthplace or one of 7 other stupid questions 5 seconds of searching on Google or Facebook can tell you - and even then only if Westpac determined that your login didn't match their pattern analysis).
Random factoid you probably didn't know - your password is case insensitive if you are with ASB, Westpac, and I believe Kiwibank and ANZ. TSB and BNZ your password is definitely case sensitive. Try it yourself sometime - enter the case of your password incorrectly and marvel as your bank happily logs you into your accounts!
1080p:
Given that two factor authentication was broken before it was even used widely does not inspire me with confidence.
What is more cumbersome is having to fish out a card/dongle every time you want to log in or receiving an SMS/e-mail. Kiwibank's security schema is much more intuitive, secure (keyloggers), and convenient (simply a password and two letters from a phrase only you know) than any other system in New Zealand.
Twitter: ajobbins
Kyanar: To those pointing out that banks cover the direct cost of fraud... well, no, they don't. In the case of credit cards they claw the money back from the merchants (meaning you the customer cover the cost of fraud) and in the case of online banking they bake these costs into their margins (meaning you the customer cover the cost of fraud).
Twitter: ajobbins
ajobbins: Not quite true. Banks and merchants each have agreed responsibilities when it comes to protecting against fraud. In cases where the merchant did nothing wrong, they are not liable. If they didn't take reasonable steps to ensure that the card use was genuine and authorised however, they could be hit with a charge back.
|
![]() ![]() ![]() |