Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 | 3 
networkn
Networkn
32871 posts

Uber Geek
+1 received by user: 15464

ID Verified
Trusted
Lifetime subscriber

  #2590045 21-Oct-2020 21:20
Send private message

Batman:

 

So i guess the solution is don't use SMS 2FA for banking?

 

 

The solution is do not use SMS 2FA for *anything*

 

 




Linux
12185 posts

Uber Geek
+1 received by user: 8480

Trusted
Lifetime subscriber

  #2590061 21-Oct-2020 21:51
Send private message

Batman:

I heard from a friend that their direct relation had their phone number ported to another carrier, by thieves and then their bank account was drained after using the phone number as bank account verification for log in.


How does one prevent that?


(Just realised while typing that this may not be android related, though the phone was an android)



Was this in New Zealand or another country?

alasta
6891 posts

Uber Geek
+1 received by user: 3365

Trusted
Subscriber

  #2590120 22-Oct-2020 08:37
Send private message

jjnz1: 
Access to my bank:
Need username and pass and access to text message to activate new device. (This can't be changed I think) then there is no limit to what I can do IMO.

 

This raises an interesting question; for banks like BNZ which have app based 2FA, what exactly is required to install the app on a new device? I assume that if someone has managed to compromise your internet banking username and password then it wouldn't be hard to also get the 2FA app working?

 

I DONT have $1000 limits on my accounts, 10x that seem to go fine (on the very odd occasion I have done that).

What's not easy about this?

 

I am surprised at the $1000 limit because I had no problem doing the transfer last time I bought a car.




michaelmurfy
meow
13581 posts

Uber Geek
+1 received by user: 10914

Moderator
ID Verified
Trusted
Lifetime subscriber

  #2590124 22-Oct-2020 08:45
Send private message

Each bank has different policies around transfer limits. I’m just speaking from experience of one of them. Your limits also may be higher especially if you’ve got a home loan or made large purchases.




Michael Murphy | https://murfy.nz
Referral Links: Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.


qwerty123
147 posts

Master Geek
+1 received by user: 20


  #2590481 22-Oct-2020 21:37
Send private message

alasta:

 

This raises an interesting question; for banks like BNZ which have app based 2FA, what exactly is required to install the app on a new device? I assume that if someone has managed to compromise your internet banking username and password then it wouldn't be hard to also get the 2FA app working?

 

 

NetGuard card is required to activate BNZ app. Until the app is activated it doesn't do 2FA, doesn't allow to create payees, etc.


freitasm
BDFL - Memuneh
80657 posts

Uber Geek
+1 received by user: 41065

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2593790 30-Oct-2020 08:32
Send private message

networkn:

 

Batman:

 

So i guess the solution is don't use SMS 2FA for banking?

 

 

The solution is do not use SMS 2FA for *anything*

 

 

I disagree. SMS 2FA is better than no 2FA at all.

 

As mentioned before, people reuse password or passwords are intercepted by malware. No one is advocating to not use passwords for anything.

 

It is a balance. But most importantly, since SMS is only one of a factors the question that should be asked is actually "how did the Bad Actor get hold of the original bank customer account number, bank customer password and phone number?"

 

The answer could be good old social engineering ("Hello, Mr Gullible Client. I am from The Bank. We need to make sure all is good with your account so first we need to verify your identity. Could I please have your account number and password to confirm you are the account owner?"). 

 

If this was a random call to a landline, it could be followed up with a "Great Mr Gullible Client, now that we know it's you, we have a mobile number here as 0319347273 is that still the best way to contact you?" at which point Mr Gullible Client will say "Oh, no something is mixed there because this is not my number - here is the correct number..."

 

Alternatively, it could be malware installed when someone calls saying "I am from your ISP. Our systems identified a problem with your computer and we need to check it for viruses. Can I please remote access your computer now to check it?"

 

SMS 2FA is only one thing - there is more to it.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


 
 
 

Support Geekzone with one-off or recurring donations Donate via PressPatron.
Batman

Mad Scientist
30014 posts

Uber Geek
+1 received by user: 6217

Trusted
Lifetime subscriber

  #2593792 30-Oct-2020 08:39
Send private message

I see. That's reassuring ...

 

But I thought maybe with certain banks - can you get a new password with SMS?


freitasm
BDFL - Memuneh
80657 posts

Uber Geek
+1 received by user: 41065

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2593797 30-Oct-2020 08:44
Send private message

Batman:

 

I see. That's reassuring ...

 

But I thought maybe with certain banks - can you get a new password with SMS?

 

 

Then that wouldn't be a second authentication factor. Password resets would be via email, which would have its own authentication scheme.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


1 | 2 | 3 
View this topic in a long page with up to 500 replies per page Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.