TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

What Is Your Bank’s Security Banking On?

72 点作者 andimm大约 7 年前

9 条评论

HoyaSaxa大约 7 年前
(Disclaimer: I&#x27;m the co-founder of Narmi which provides online banking, mobile banking, and banking APIs to banks and credit unions in the United States)<p>For anyone interested, Associated Bank (mentioned in the article) is using Fiserv&#x27;s Corillian [1] product.<p>The U.S. financial ecosystem is quite different than others around the world. Despite the asset base being consolidated heavily with a handful of institutions, there are still over 11,000 banks and credit unions around the country. Of those 11,000, I would estimate that less than 5% have any significant in house engineering teams (and that is a generous estimate). The rest rely entirely on third parties to run the technology and software that makes a bank a bank. The market is dominated by Fiserv, FIS and Jack Henry &amp; Associates as the article mentions, but there is also a long tail of providers.<p>Very few bank and credit union executives understand the basics of cybersecurity. The vast majority of CEOs come from some type of lending centric leadership position since that has been the main source of revenue traditionally.<p>Unabashed plug: If you know a credit union or bank that is need of a better digital banking experience, I would greatly appreciate the plug&#x2F;intro for Narmi.<p>[1] <a href="https:&#x2F;&#x2F;www.fiserv.com&#x2F;customer-channel-management&#x2F;online-banking&#x2F;corillian-online.aspx" rel="nofollow">https:&#x2F;&#x2F;www.fiserv.com&#x2F;customer-channel-management&#x2F;online-ba...</a>
评论 #16537029 未加载
评论 #16538897 未加载
评论 #16537541 未加载
lakechfoma大约 7 年前
Discord has stronger authentication methods than any of the 8 or so financial institutions I have accounts with.<p>All 8+ do their auth quite differently yet they&#x27;re all broken and they all fall back on SSN. Why hasn&#x27;t this industry standardized around one process that is actually effective?<p>Recently I made an account with Fidelity brokerage. Username maxes at 12 chars or something, password at 20. Not the worst, but then I had to get phone support and to authenticate over the phone you need to enter either your username or SSN on the keypad, and then the password on the keypad. The charspace of both the username and password have thus been reduced to 0-9 and * for all specials.<p>Another institution is for my employee share purchase plan. The phone support can initiate sells and transfers I&#x27;m pretty sure, yet their only auth is for my full name, employee number, and birthday. My employee number is literally printed on my laptop and some other stuff next to my full name, my birthday easily googleable with my name.
评论 #16536800 未加载
ekns大约 7 年前
All or most Finnish banks use an ~8 digit account ID and a 4-6 digit one-time password from a slip of paper that has 80 to 300 of them. Some have a separate PIN&#x2F;password too.<p>For confirming large transactions (&gt;5000 or 10000 eur) there&#x27;s a separate phone call or SMA verification.<p>Nowadays there&#x27;s apps for 2FA instead of always requiring the use of a one-time password. My corporate bank account still uses the paper backed one-time passwords though.
评论 #16540015 未加载
zaarn大约 7 年前
The security of my bank is pretty good, any account management action (password reset, card pin change, mailing address, email, name, etc.) requires physical presence in the closest branch. Not any arbitrary branch, the closest. With my passport. Not some bill or mail on my address. My passport.<p>The password reset will then setup a new password with 12 characters, number and specials included. This password is then sent via german postal service to my house, I can&#x27;t pick it up on my local branch or have it told to me. Send via mail. Period.<p>The letter advices me to change the password to something secure immediately and destroy the letter securely afterwards. The banking website enforces this and you cannot change your password to any temporary password that your account previously had. (So if someone intercepted the letter, you would either notice or it would be useless)<p>The only downside is they have an ancient COBOL mainframe doing the accounts, so they&#x27;re case insensitive and encoded in ECBDIC, although they are properly hashed using bcrypt, there is an upper limit of 24 characters because it still passes through there.<p>So I would say my bank is banking on the customer picking a good enough password and hoping they can replace the COBOL mainframe at some point.
评论 #16536663 未加载
评论 #16535678 未加载
PeterStuer大约 7 年前
For my bank it is:<p>- Log in: Two factor authentication based on chip card &#x2F; chip card reader [1] with 4 digit PIN attached to card.<p>- 3 wrong PIN attempts blocks card, and requires phone unlock - The &#x27;call&#x27; is secured by asking you the typical weak questions that are easily guessed<p>- each transaction requires using the same device to generate an 8 digit electronic signature<p>You could argue the &#x27;security questions&#x27; part is weak, but I guess in the context of the process (buying you another 3 attempts)it&#x27;s an ok&#x27;ish trade-off.<p>We have come a long way since the first &#x27;Phone Banking&#x27; where all that was needed to access the account and make whatever transaction was punching in a 4 digit &#x27;password&#x27; on a tone-dial.<p>[1] <a href="http:&#x2F;&#x2F;c621460.r60.cf3.rackcdn.com&#x2F;Kaartlezer---kaart.jpg" rel="nofollow">http:&#x2F;&#x2F;c621460.r60.cf3.rackcdn.com&#x2F;Kaartlezer---kaart.jpg</a>
ocfnash大约 7 年前
To log in to an account for my Irish bank, AIB, you just need:<p><pre><code> * A theoretically-secret 8-decimal-digit id * Three digits from a secret 5-decimal-digit PIN </code></pre> For many years all new online credentials were assigned an 8-decimal-digit id of the form: ddmmyynn where ddmmyy was the account holder birth date and nn was a sequence number.<p>I don&#x27;t know how many accounts still have these birth-date-style ids but I have good reason to believe it is a great many.
评论 #16536284 未加载
rocqua大约 7 年前
In the Netherlands, most banks use a system that depends on the security of the chip-debit card, and a specific hardware device that each customer gets sent.<p>In my case (rabobank), whenever the bank needs authentication (i.e. when logging in, transfering money, or changing details) they present me with a QR-like code. I then use their supplied hardware [1]. This requires I enter my card and enter my PIN. I can then scan the QR-ish code with a camera built into the device.<p>The device then prompts me with what I am doing. Something like &quot;You are sending € X to account Y &quot; or &quot;Login into account Z&quot;. Upon clicking confirm, it outputs a numerical code I have to enter into the website.<p>I really love this system, I like it the best of all dutch systems I know. One bank I know of (ANB-amro) has a similar hardware device, without using the QR codes, but numbers you enter. They also provide a USB connection so you don&#x27;t need to enter numerical codes twice. Another bank I know of uses standard password and SMS 2-factor authentication.<p>The mobile app for rabobank is quite a bit worse though. You need the scanner once to set up a PIN on the device. With that PIN, you can immediately login and see all account details. Moreover, small amounts to accounts you&#x27;ve previously sent money too can be sent using only that PIN. The idea being that these are your &#x27;friends&#x27; and it is nice to pay your friends quickly. There is even a setting that will allow you to send amounts below a threshold (I think €100) to any account using only that PIN. Luckly, you can turn that off, and it takes the scanner to turn it back on. However, you cannot turn of the transfer to &#x27;friends&#x27; unless you simply refuse to install the app.<p>[1] dutch wikipedia link: <a href="https:&#x2F;&#x2F;nl.wikipedia.org&#x2F;wiki&#x2F;Rabo_Scanner" rel="nofollow">https:&#x2F;&#x2F;nl.wikipedia.org&#x2F;wiki&#x2F;Rabo_Scanner</a>
评论 #16536339 未加载
评论 #16536010 未加载
评论 #16536994 未加载
cupofjoakim大约 7 年前
In Sweden the standard is something called BankID, which is basically a digitally bank issued id that ties into 2FA and works kind of like the Blizzard authenticator or the Googla Auth app, but I&#x27;m not sure about the solutions for people without smartphones. It&#x27;s becoming kind of big here and is regarded as the most secure solution. The startup I&#x27;m at now use it for logging into both the admin dashboard and the customer pages.<p>The user fills in his SSN to our form, we push a request to bankid, they send a request to the users phone, user types a min 6 digit code which is posted to bankid, bankid tells us to go ahead with the login. For iPhone X there&#x27;s even support for skipping the code and using FaceId.
t3h2mas大约 7 年前
My bank runs a public bug bounty program. It&#x27;s a start