The_Tired_Horizon,
@The_Tired_Horizon@lemmy.world avatar

All our local banks closed their branches. We’re lucking if we can get a human to talk to.

lseif,
MargotRobbie,
@MargotRobbie@lemmy.world avatar

Thanks.

lseif,

No problem Margot Robbie

Dempf,

Google and the banks can eat my whole asshole.

CCF_100,

Honestly, screw apps that do this. It’s pathetic.

electricprism,

Ok fine no banks it is then.

anarchy79,
@anarchy79@lemmy.world avatar

This is actually something I have spent a lot of time thinking about. In Sweden, where my boyfriend lives, their BankID app is ubiquitous, and there is very little cash handling going on, additionally the fees for actually going to the bank or subsidiary to pay your bills are exorbitant.

Everybody pays their bills online using “BankID”, which is kinda nifty and works well enough if a single point of failure is your thingaling, but what if people simply choose not to get a phone, or don’t want a computer, just basic like that, what if?

It feels kind of creepy to me, I don’t know…

lseif,

thats scary

anarchy79,
@anarchy79@lemmy.world avatar

Sweden has gone about 80% fascist, in case you didn’t know. By popular vote, even! We have literal Nazis in government right now, they’re the second largest party, and while “not all Swedes” agree that they are Nazis, their heritage and lineage stems directly from the neo-Nazi movement in Sweden in the 80’s and 90’s, supported financially by Putin. <- this is not a joke, btw

All SIM cards have to be registered with your personal identification number (more or less “social security number”, but with your 100% full identifiable personal information), by law, and by law it is illegal not to state where you live (like a census law, you must report to authorities at all times where you reside. If you don’t have a home, well, your last address is where you officially live).

The right wing extremists have pumped money into police, and they now have the right to effect stop-and-frisk zones, and wiretapping anyone they please without probable cause or even suspicion of criminal activity.

BaardFigur,

Don’t you have a code generator?

In Norway we gave 3 options. BankID by code generator, BankID by simcard, and BankID by app.

The code generator isn’t even connected to the internet, and is the oldest type of bankid

anarchy79,
@anarchy79@lemmy.world avatar

This is true, but almost nobody uses it- Mobile BankID is the ubiquitous app for that, and while there still is the possibility, not all sites accept it. Not to mention, this still requires a computer, and while you may be inclined to say that “well there are always libraries”, you cannot install third party software on their computers, and they do NOT carry BankID application (because of course not). This is true for social services as well.

The real fear is the fact that once everything goes digital - and it will - everybody is at the mercy of finance and the ability to procure a telephone, and or a computer, and or an internet connection (all SIM cards have to be registered with national identification before the state, adding to the problem of how you would identify yourself in the first place in lieu of such capabilities or possibilities).

Neither having a phone or a computer is considered a human right yet, as far as I know, and in either case the state is not obligated to provide you with one regardless.

May seem like nitpicking, but that is what lawmaking and jurisprudence is all about.

s0phia,
@s0phia@lemmy.world avatar

I use Magisk with the DenyList enabled and I just add banking and government apps to that list. Everything works perfectly.

TheKMAP,

TOTP is not secure

OfficerBribe,

What’s wrong with TOTP?

TheKMAP,

Phishable. Use FIDO2 (webauthn) with user verification (pin, fingerprint)

1371113,

Preach

funkless_eck, (edited )

fingerprint has law enforcement issues (especially in America) - they can compel you to provide it, but not a password.

TheKMAP,

OK so use the Pin

MargotRobbie,
@MargotRobbie@lemmy.world avatar

This post is against Rule 6, but I’ll leave it up this time since there are a decent amount of discussion here now.

lseif@sopuli.xyz, please remove the image when you can. You can post it in the comments.

KoalaUnknown,

Banks do this because most people don’t know how to use technology and it’s a lot easier to get remote access and malware on your computer than your phone.

MTK,

I hate this so much!

My bank is like that and another horrible thing is that after you choose your password (which can be long and complex) you need to choose a 6 DIGIT restore code incase you forgot your password…

Why is is my BANK so bad at security??

LodeMike,

Wait

You have a second password that’s (opens calculator) 20 bits of entropy???

lseif,

genius

Dnn,

And they all develop their own shitty app for 2FA (the lazy ones just rebrand SecureGo as their own - you still have to install all of them separately) instead of using the 15 year old TOTP standard. The latter is good enough for tiny companies like Google and Amazon but what do they know about itsec, right?

FrogMaster,

Doesn’t work because of Play Integrity API but there are ways to bypass it. At least for now. Look up PlayIntegrityFork.

Sprokes,

Some apps implement other checks. Mine checks whatever you replaced the stock webview (checking the package name). So sometimes it is challenging to find those checks to bypass them.

scoobford,

You might try another bank. Several still provide online banking, so you can just use their website.

aeharding,
@aeharding@lemmy.world avatar

Get new bank

sgibson5150,

My credit union’s web site looks like a MySpace page. They don’t even offer freaking 2FA. Been meaning to transition to cash management account but such a PITA.

bamboo,

I have an account with a larger credit union and their Android app implements onerous rules which some exec must feel makes it more secure, but is just a burden 99.999% of the time. Today I found that the fingerprint login expires after a week of not logging in, requiring the username/password to log in. Annoying but ok, I log in with a username and password. Then it says I need to do MFA and presents 3 options, email, SMS, and app push notification. The UI for app push notification even says “This device”. I selected that one, and the app shows the approve/deny button over the MFA requirement screen.

So obviously the saved state in the app wasn’t actually expired, since it could still approve MFA requests. So what good is it expiring biometric auth if the app is still authorized to log me in effectively bypassing MFA?

DanVctr,

So obviously the saved state in the app wasn’t actually expired, since it could still approve MFA requests. So what good is it expiring biometric auth if the app is still authorized to log me in effectively bypassing MFA?

I love this and hate this so much

  • All
  • Subscribed
  • Moderated
  • Favorites
  • android@lemmy.world
  • DreamBathrooms
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • mdbf
  • tacticalgear
  • JUstTest
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • megavids
  • lostlight
  • All magazines