• atzanteol@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    57
    ·
    7 days ago

    That’s great when my bank only uses sms for mfa though.

    Seriously, bank and credit card companies need to get with the program more than me and my friends.

    • Captain Aggravated@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      10
      ·
      7 days ago

      Steam. The store front I get my video games from. Has 2-factor authentication with a short time rotating code. To secure my Steam account.

      My bank uses SMS and “security questions” aka personal trivia questions.

        • toynbee@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          6 days ago

          While I agree with you, some people answer these questions with deliberately incorrect answers. If my closest friend tried to compromise my bank account with my security questions, he’d get them all wrong (and even he doesn’t know my wrong answers).

          Still a bad design, though.

        • Draconic NEO@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          3
          ·
          6 days ago

          Or literally anyone who knows you. It’s based on the idea that strangers are the ones who will try to screw you over but everyone knows that it’s people who you know that end up screwing you over in most cases. So security questions are basically useless in all those cases.

    • sugar_in_your_tea@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      ·
      7 days ago

      That’s a huge part of why I use my brokerage, Fidelity, as my main bank, they support Symantec VIP TOTP. I prefer my regular TOTP solution, but this us miles ahead of literally every other bank I’ve used.

    • Eezyville@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      ·
      7 days ago

      The only bank that allowed me to use totp was a credit union. You’d think the rich ass banks could afford to hire a developer to set up good MFA.

    • Chais@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      9
      ·
      7 days ago

      Right? Had a bank account once, where the login password could only have up to 8 characters. And only digits.