Changes to banking login - now using SMS for OTP: bad idea?
Discussion
I'm with Nationwide and their online portal has been announcing for some time that they're 'changing the way you log in' in the near future. Currently the process is:
Aside from meaning that logging into my online banking will now require me to have either the card-reader or phone to hand (which in turn assumes I have power and a signal), it doesn't actually feel like the new system actually improves security in any way.
I know there are some on PH who work in these circles - are these changes actually a backward step in your view? At the moment I have 3 unique pieces of information which only I know. Under the new system someone who knows my birthday and can get hold of my phone has 66% of the information needed to access my online banking - the only information they don't have is my customer number.
It all seems not only less convenient but also less secure? Is this going to be the same across all banks or is it just Nationwide getting it wrong?
- Customer number (which is not your account number)
- 'Memorable data' - this is a password of your choice
- 3 random digits of your 6-digit security code
- Customer number
- Date of birth (hardly a great secret)
- One-time passcode sent via SMS
Aside from meaning that logging into my online banking will now require me to have either the card-reader or phone to hand (which in turn assumes I have power and a signal), it doesn't actually feel like the new system actually improves security in any way.
I know there are some on PH who work in these circles - are these changes actually a backward step in your view? At the moment I have 3 unique pieces of information which only I know. Under the new system someone who knows my birthday and can get hold of my phone has 66% of the information needed to access my online banking - the only information they don't have is my customer number.
It all seems not only less convenient but also less secure? Is this going to be the same across all banks or is it just Nationwide getting it wrong?
Edited by Funk on Wednesday 18th September 14:12
It's massively less secure. It's not massively hard for someone to social engineer your mobile network into issuing a new SIM for your number. Once done they have your one-time passwords. This happened recently to the CEO of twitter: https://www.wired.com/story/jack-dorsey-twitter-ha...
Using SMS as the second factor in 2FA should be banned!
Using SMS as the second factor in 2FA should be banned!
It's not massively less secure, it's more secure.
Current process:
IT illiterate user clicks on phishing email appearing to be from bank, telling them to login, they enter memorable numbers, passwords etc into fake website. Details are sold on black market and later used to login and steal money, apply for credit etc
New process:
IT illiterate user clicks on fishing email appearing to be from bank, telling them to login, they enter memorable numbers, passwords etc into fake website. Details are sold on black market. IT illiterate user receives SMS saying login detected for their account, enter this code to continue hackers unable to login, user informed of login attempt and can resolve with bank.
As pointed above the extra steps of gaining access to the phone or new sim etc adds an extra layer of work required to breach the account.
Current process:
IT illiterate user clicks on phishing email appearing to be from bank, telling them to login, they enter memorable numbers, passwords etc into fake website. Details are sold on black market and later used to login and steal money, apply for credit etc
New process:
IT illiterate user clicks on fishing email appearing to be from bank, telling them to login, they enter memorable numbers, passwords etc into fake website. Details are sold on black market. IT illiterate user receives SMS saying login detected for their account, enter this code to continue hackers unable to login, user informed of login attempt and can resolve with bank.
As pointed above the extra steps of gaining access to the phone or new sim etc adds an extra layer of work required to breach the account.
Phateuk said:
It's not massively less secure, it's more secure.
Current process:
IT illiterate user clicks on phishing email appearing to be from bank, telling them to login, they enter memorable numbers, passwords etc into fake website. Details are sold on black market and later used to login and steal money, apply for credit etc
New process:
IT illiterate user clicks on fishing email appearing to be from bank, telling them to login, they enter memorable numbers, passwords etc into fake website. Details are sold on black market. IT illiterate user receives SMS saying login detected for their account, enter this code to continue hackers unable to login, user informed of login attempt and can resolve with bank.
As pointed above the extra steps of gaining access to the phone or new sim etc adds an extra layer of work required to breach the account.
OK, I can see that - perhaps I'm not viewing it through the lens of 'idiot'. That said, I would still contend that DoB is NOT a good way to aid identification of a user, nor is the use of SMS as a delivery method for a OTP.Current process:
IT illiterate user clicks on phishing email appearing to be from bank, telling them to login, they enter memorable numbers, passwords etc into fake website. Details are sold on black market and later used to login and steal money, apply for credit etc
New process:
IT illiterate user clicks on fishing email appearing to be from bank, telling them to login, they enter memorable numbers, passwords etc into fake website. Details are sold on black market. IT illiterate user receives SMS saying login detected for their account, enter this code to continue hackers unable to login, user informed of login attempt and can resolve with bank.
As pointed above the extra steps of gaining access to the phone or new sim etc adds an extra layer of work required to breach the account.
At best then it's a half-baked attempt at security; if they were using a proper 2FA authenticator I could understand it more.
Not often I'll say this but I have some sympathy for banks.
I can't think of many other institutions that have to juggle providing ready access to potentially huge sums of money to the rightful owners of that money whilst keeping ever more ingenious bad guys out.
That said I'm struggling with their reasoning around removing the "Something you know" (and that someone else can't easily find out) element i.e. a unique strong password.
I can't think of many other institutions that have to juggle providing ready access to potentially huge sums of money to the rightful owners of that money whilst keeping ever more ingenious bad guys out.
That said I'm struggling with their reasoning around removing the "Something you know" (and that someone else can't easily find out) element i.e. a unique strong password.
b
hstewie said:
hstewie said: That said I'm struggling with their reasoning around removing the "Something you know" (and that someone else can't easily find out) element i.e. a unique strong password.
That does seem odd, since DOB is essentially public info these days.I bank with First Direct, they're shortly changing the web login to require name+passphrase+code from FD Phone app (or separate h/w key device).
outnumbered said:
That does seem odd, since DOB is essentially public info these days.
I bank with First Direct, they're shortly changing the web login to require name+passphrase+code from FD Phone app (or separate h/w key device).
If I have to pick up the phone to authenticate on a desktop browser then I may as well just use the banking app on the phone... Further to that they know if you're using the app so why not use the app for authentication which would be even more secure than SMS? I appreciate that, again, SMS would be the lowest common denominator as I'm sure there are still luddites out there who aren't using smartphones or if they are, who won't use their bank's app.I bank with First Direct, they're shortly changing the web login to require name+passphrase+code from FD Phone app (or separate h/w key device).
I applaud efforts to secure things more, I just don't see how using information which is widely available (such as DoB) helps with that. The issue of OTPs being displayed on locked phones is also still a major oversight in my opinion. I guess the bank's argument would be that that's down to the user to secure though - in the event of fraud occurring they will say that the 'secure' OTP was used, therefore the user MUST have authorised it and therefore the liability shifts away from them which is all they really care about?
Funk said:
If I have to pick up the phone to authenticate on a desktop browser then I may as well just use the banking app on the phone... Further to that they know if you're using the app so why not use the app for authentication which would be even more secure than SMS? I appreciate that, again, SMS would be the lowest common denominator as I'm sure there are still luddites out there who aren't using smartphones or if they are, who won't use their bank's app.
I applaud efforts to secure things more, I just don't see how using information which is widely available (such as DoB) helps with that. The issue of OTPs being displayed on locked phones is also still a major oversight in my opinion. I guess the bank's argument would be that that's down to the user to secure though - in the event of fraud occurring they will say that the 'secure' OTP was used, therefore the user MUST have authorised it and therefore the liability shifts away from them which is all they really care about?
I would accept that its not really doing anything in terms of the value you enter - Hargreaves Landsdown do similar asking for DOB - there may be a reason they want it thats not obvious to you, maybe the time to enter the DOB is somehow monitored and if its too long then it rejects the log in, or its a simple crosscheck to prevent someone hacking away with random account names (which may have a specific format that can be derived) and guessing a 4 or 6 digit pins - ie it makes brute force attacks much less likely as you can't just guess an account number of someone you don't know, you have to also guess the DoB of the person, all while creating very little inconvenience to youI applaud efforts to secure things more, I just don't see how using information which is widely available (such as DoB) helps with that. The issue of OTPs being displayed on locked phones is also still a major oversight in my opinion. I guess the bank's argument would be that that's down to the user to secure though - in the event of fraud occurring they will say that the 'secure' OTP was used, therefore the user MUST have authorised it and therefore the liability shifts away from them which is all they really care about?
RizzoTheRat said:
Just logged in to my bank website from a PC and they now put up a QR code which you scan with the mobile banking app and then login to the phone app with fingerprint or PIN to unlock the website on the PC. Seem to work well and presumably not bad security wise.
That seems a far more sensible idea security-wise. Although by that stage you might as well have just used the phone app...I thought of another reason why DoB is daft - it can't be changed.
Edited by Funk on Friday 20th September 14:43
menguin said:
The SMS thing is due to new legislation - PSD2. I agree that the DOB change is strange, and a unique question/answer or passcode would be preferable, but expect to see SMS verification (or similar) come not only to bank logins, but 3D secure, etc.
It just surprises me that we're entrusting verification to a completely unencrypted system which can be co-opted by a third party (ie. someone in any mobile provider's store could move your number to another SIM) and where the sensitive information transmitted can be seen on the lockscreen of a phone without needing to unlock it (unless it's specifically turned off by the user and working in IT I know how much users will prioritise security over convenience when given the choice....!).I just can't see how using SMS is a good idea. I suppose that to do any real harm once into an account you'd still have to have the card and reader to set up a payment.
Probably doing some behind the scenes stuff like device profiling and bot/automation prevention, blocks attacks like credential stuffing which the old authentication was vulnerable to. Consider the threat model for average user it's unlikely to be a targeted attack but more mass phishing or cred stuffing.
Edit HSBC give you a proper 2fa fob which I like. They did until recently have a "I've lost my fob" password backdoor which I didn't like but it's been turned off I think.
Edit HSBC give you a proper 2fa fob which I like. They did until recently have a "I've lost my fob" password backdoor which I didn't like but it's been turned off I think.
bmwmike said:
.
Edit HSBC give you a proper 2fa fob which I like. They did until recently have a "I've lost my fob" password backdoor which I didn't like but it's been turned off I think.
ABN AMRO give you one if those card readers for a challenge and response 2fa. Great security but not so good for usability as you don't carry it around with you. Edit HSBC give you a proper 2fa fob which I like. They did until recently have a "I've lost my fob" password backdoor which I didn't like but it's been turned off I think.
The new thing with the QR codes is way better, especially add its tied in with IDEAL payments so you can just scan the QR code and identify yourself with a fingerprint or password to pay online.
I bank with Nationwide and I’m getting more frustrated with their security strategy, and agree with OP that using DOB seems strange compared to memorable data, which could be anything (it doesn’t display what memorable data is, so could be anything).
But recently I was trying to pay an existing payee through the app (think I was paying to a credit card), and it asked for my card reader to complete the transaction, which I didn’t have on me. To me this makes no sense considering I was fully authenticated through the mobile app, and it was an existing payee I’d paid to many times. just makes the app less useful.
But recently I was trying to pay an existing payee through the app (think I was paying to a credit card), and it asked for my card reader to complete the transaction, which I didn’t have on me. To me this makes no sense considering I was fully authenticated through the mobile app, and it was an existing payee I’d paid to many times. just makes the app less useful.
Gassing Station | Finance | Top of Page | What's New | My Stuff


