mntmn,
@mntmn@mastodon.social avatar

i think the EU should pass legislation that enforces standards based 2factor auth (like totp/hotp) for banks, health insurance etc. it is absolutely unacceptable that people are forced to buy android/ios smartphones to use critical services

mntmn,
@mntmn@mastodon.social avatar
frostchild, (edited )
@frostchild@mastodon.social avatar

@mntmn heh, that's the first time you have made me cringe. Although I am sure I have made you cringe many times... impressive though.

The art work aka, made me cringe.

mmu_man,
@mmu_man@m.g3l.org avatar

@mntmn 💯

mmu_man,
@mmu_man@m.g3l.org avatar

@mntmn I asked my bank how I'm supposed to do without an ordiphone… "I'll ask".
That was 4 years ago.

wonka,
@wonka@chaos.social avatar

@mntmn I am quite happy that my bank supports a really secure 2FA: ChipTAN. It needs an extra device, yes, but the TANs are generated from a secret stored on my GiroCard and data about the transaction.

MaybeMyMonkeys,

@mntmn does depend on how the services are delivered. Smartphones are cheaper and more versatile than PCs.

frostchild,
@frostchild@mastodon.social avatar

@mntmn I agree with that as well, but also the world in general.

mobile devices are barely more secure than windows devices.

IE, not very.

Beiz,
@Beiz@mastodon.social avatar

@mntmn better yet, EU should pass legislation that requires all ID authentication software to be owned by the public, open source, and entirely system agnostic.

it's insane that digital ID is privatized, mandatory, and yet only supported on android and ios - preventing european competition from entering the market.

hell, windows should be banned from use within governments. why the hell is a foreign corporation paid billions of public money annually when we could use taxes to develop our own?

zetabeta,
@zetabeta@mastodon.social avatar

@mntmn
furthermore, apps may use push messages, which is bad if it is external push messages, like ios and google push messages.

acb,
@acb@mastodon.social avatar

@mntmn They have something like this in Sweden; it’s called BankID, and while most people use a mobile app, there is also (IIRC) a desktop implementation using a smartcard and a USB-powered reader.

mofumofu,
@mofumofu@mastodon.social avatar

@mntmn my bank in my home country has been using these for decades… in addition they offer an app… but the app still requieres the code from the token generator in addition to the regular password. In addition for some unusual transactions it will ask for an extra sms based OTP. We don’t have laws requiring banks to do that.

theartlav,
@theartlav@hachyderm.io avatar

@mntmn Wait, what are they using instead? Wasn't it all SMS? Or are apps mandatory somehow now?

mntmn,
@mntmn@mastodon.social avatar

@theartlav all my banks are using apps now

sirjofri,
@sirjofri@mastodon.sdf.org avatar

@mntmn @theartlav I asked my bank to send me one of those hardware token generators where you put your girocard in. It works perfectly and I prefer that over another app (also for security reasons). It cost like 20 euros (once), and I'm happy with it.

breizh,
@breizh@pleroma.breizh.pm avatar

@mntmn Well, the EU is actually enforcing the banks to not use TOTP/HOTP because it’s not secure enough (it's not contextual).

lanodan,
@lanodan@queer.hacktivis.me avatar

@breizh @mntmn Meanwhile there's devices for this that banks are already issuing en masse and are standard: credit/debit cards.

Eldeberen,
@Eldeberen@social.middleearth.fr avatar

@lanodan There are a lot of contradictions with banks, but we can't blame them for following the actual regulations…

Moreover credit cards neither are contextual: the regulation says that the MFA device must display the information about the transaction you are validating, such as the amount or company's name. Good luck with your credit card though ^^'

@mntmn @breizh

lanodan,
@lanodan@queer.hacktivis.me avatar

@Eldeberen @mntmn @breizh Ah, that kind of "contextual" (damn meaningless terms).

By the way, company's name is pretty much bullshit as demonstrated many times over with: Company names not being unique (see issues with EV certificates), porn sites using ~shell companies, payment processors (Stripe, Paypal, …) being the ones shown when the business isn't doing it by itself, …

And the amount also is because by design you can charge a card again so subscriptions work.

Eldeberen,
@Eldeberen@social.middleearth.fr avatar

@lanodan TBH I would be quite satisfied with some FIDO2 authentication…

Moreover because the strong authentication for online payments is still up to the vendor website, so completely useless when you see that even for banks it's not enabled (coucou La Poste).

Any scammer can order anything from almost anywhere x)

@mntmn @breizh

wonka,
@wonka@chaos.social avatar
chebra,
@chebra@mstdn.io avatar
steinarb,
@steinarb@mastodon.social avatar

@mntmn My bank SBanken offered credit card sized scraping code cards as an option (not the only option, but an option).

But then they were bought by the bank I had switched to SBanken to escape (back in 2004 or thereabouts)... and the analog 2Factor option went away.

Not the only change I'm not happy with, but the one that annoyed me most, I think.

On the morning commute everybody is sucked into their smartphones.

Except the software developer (me) who reads a paper newspaper.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • kavyap
  • InstantRegret
  • mdbf
  • GTA5RPClips
  • cisconetworking
  • DreamBathrooms
  • ethstaker
  • magazineikmin
  • thenastyranch
  • ngwrru68w68
  • Youngstown
  • slotface
  • rosin
  • Durango
  • megavids
  • khanakhh
  • normalnudes
  • modclub
  • cubers
  • tacticalgear
  • osvaldo12
  • everett
  • Leos
  • anitta
  • provamag3
  • tester
  • JUstTest
  • lostlight
  • All magazines