Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 | 3 
networkn
Networkn
32350 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2590045 21-Oct-2020 21:20
Send private message

Batman:

 

So i guess the solution is don't use SMS 2FA for banking?

 

 

The solution is do not use SMS 2FA for *anything*

 

 




Linux
11413 posts

Uber Geek

Trusted
Lifetime subscriber

  #2590061 21-Oct-2020 21:51
Send private message

Batman:

I heard from a friend that their direct relation had their phone number ported to another carrier, by thieves and then their bank account was drained after using the phone number as bank account verification for log in.


How does one prevent that?


(Just realised while typing that this may not be android related, though the phone was an android)



Was this in New Zealand or another country?

alasta
6703 posts

Uber Geek

Trusted
Subscriber

  #2590120 22-Oct-2020 08:37
Send private message

jjnz1: 
Access to my bank:
Need username and pass and access to text message to activate new device. (This can't be changed I think) then there is no limit to what I can do IMO.

 

This raises an interesting question; for banks like BNZ which have app based 2FA, what exactly is required to install the app on a new device? I assume that if someone has managed to compromise your internet banking username and password then it wouldn't be hard to also get the 2FA app working?

 

I DONT have $1000 limits on my accounts, 10x that seem to go fine (on the very odd occasion I have done that).

What's not easy about this?

 

I am surprised at the $1000 limit because I had no problem doing the transfer last time I bought a car.




michaelmurfy
meow
13242 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

  #2590124 22-Oct-2020 08:45
Send private message

Each bank has different policies around transfer limits. I’m just speaking from experience of one of them. Your limits also may be higher especially if you’ve got a home loan or made large purchases.




Michael Murphy | https://murfy.nz
Referral Links: Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.


qwerty123
147 posts

Master Geek


  #2590481 22-Oct-2020 21:37
Send private message

alasta:

 

This raises an interesting question; for banks like BNZ which have app based 2FA, what exactly is required to install the app on a new device? I assume that if someone has managed to compromise your internet banking username and password then it wouldn't be hard to also get the 2FA app working?

 

 

NetGuard card is required to activate BNZ app. Until the app is activated it doesn't do 2FA, doesn't allow to create payees, etc.


freitasm
BDFL - Memuneh
79263 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2593790 30-Oct-2020 08:32
Send private message

networkn:

 

Batman:

 

So i guess the solution is don't use SMS 2FA for banking?

 

 

The solution is do not use SMS 2FA for *anything*

 

 

I disagree. SMS 2FA is better than no 2FA at all.

 

As mentioned before, people reuse password or passwords are intercepted by malware. No one is advocating to not use passwords for anything.

 

It is a balance. But most importantly, since SMS is only one of a factors the question that should be asked is actually "how did the Bad Actor get hold of the original bank customer account number, bank customer password and phone number?"

 

The answer could be good old social engineering ("Hello, Mr Gullible Client. I am from The Bank. We need to make sure all is good with your account so first we need to verify your identity. Could I please have your account number and password to confirm you are the account owner?"). 

 

If this was a random call to a landline, it could be followed up with a "Great Mr Gullible Client, now that we know it's you, we have a mobile number here as 0319347273 is that still the best way to contact you?" at which point Mr Gullible Client will say "Oh, no something is mixed there because this is not my number - here is the correct number..."

 

Alternatively, it could be malware installed when someone calls saying "I am from your ISP. Our systems identified a problem with your computer and we need to check it for viruses. Can I please remote access your computer now to check it?"

 

SMS 2FA is only one thing - there is more to it.





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


Batman

Mad Scientist
29762 posts

Uber Geek

Trusted
Lifetime subscriber

  #2593792 30-Oct-2020 08:39
Send private message

I see. That's reassuring ...

 

But I thought maybe with certain banks - can you get a new password with SMS?


 
 
 

Shop now on AliExpress (affiliate link).
freitasm
BDFL - Memuneh
79263 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #2593797 30-Oct-2020 08:44
Send private message

Batman:

 

I see. That's reassuring ...

 

But I thought maybe with certain banks - can you get a new password with SMS?

 

 

Then that wouldn't be a second authentication factor. Password resets would be via email, which would have its own authentication scheme.





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


1 | 2 | 3 
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.