TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Secure messaging to solve phishing scams

2 点作者 helghardt将近 2 年前
Let’s use banks as an example, but it applies to other services too. Why do banks rely on emails and sms to communicate login alerts, password changes, transaction confirmations and even promotional alerts?<p>It is sooo prone for phishing attacks! HTTPS helped us confirm the website we visit is legit along with being confident the data transmission is encrypted. Everyone managed to fall in line adopting this standard and relying on a certificate authority sitting in the middle.<p>Taking this one step further, why have banks not tried to create a secure messaging service where there is a certificate issued and associated with your website to validate authenticity.<p>Furthermore, the messaging service could be opt-in only, more accurate labelling of incoming messages, etc.<p>So my question is why does such a messaging standard&#x2F;service not exist, has anyone tried but failed?

3 条评论

na4ma4将近 2 年前
Because it would be fragmented and have 1000 incompatible implementations if it ever got that far.<p>Large institutions would prefer something they control 100%, email and SMS are only used because they became ubiquitous first.<p>But some companies use their apps as a secure alternative.
dave4420将近 2 年前
Banks who create a secure messaging service build it into their app and website. There’s no incentive to create a generic service.
评论 #36919278 未加载
helghardt将近 2 年前
Another benefit that comes to mind is the cost saving of not having to send SMS’es. In some regions SMS’es go up to $0.25&#x2F;SMS via services like Twilio&#x2F;local variations.