Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is totally and completely insane. If a site gets hacked and your money is stolen there's no way the bank is going to indemnify you when you willingly turned over your credentials to a third party.

Do they have to have all kinds of specialized fraud detection in place to prevent unknown IPs from transferring more than a certain dollar amount? It also just occurred to me that you probably can't have 2-factor enabled on your bank account.



This same procedure is used in the United States with startup darlings like Coinbase. No debit card or one-time-password required, please give your real bank account password.

https://support.coinbase.com/customer/en/portal/articles/194...


It's also used by all the major financial-management apps like Mint.com and Bank of America Portfolio Manager

https://www.mint.com/how-mint-works/security


I had heard good things about mint, and I liked the 'dashboard' screenshots and such. Then I looked at how it worked, particularly "provide your bank credentials" part.

It didn't take long to realize how incredibly dangerous that was, and leave.

Banks should provide API access for services like this because it mitigates significant security issues.


They at least make it optional.


How does this, in any way, make it better that they do it at all?


The second factor is the one time password. You get ~200 by snail mail and need one for each transaction. So you only give up control for one transfer. But yes, indeed, this is insane.


So you need to order new passwords if you're making a lot of online purchases? That seems even more insane, really.


You do not have to use that service and there are also electronic versions of a one-time-password generator.


Many banks now actually provide code generators, but yes in the past you would receive new codes every so often.


Generally, as the bank also tracks the rate at which your passwords get invalidated (by being used), they will automatically send you a new sheet when there are only ~20 remaining on your current sheet.


What if snail mail gets stolen?


In theory nothing bad happens as the person with the snail mail code list still needs your login/password to issue money transfers.

But then again ... you just handed your banking credentials to some shady fintech startup.


You need to activate the next block of TANs with one of the previous.


There isn't actually anything you can do with the login + password. Sure, you can look at the transactions, so I guess it's a privacy problem.

But any transaction or change usually requires generating a single use pin with your debit card and a small card reader. Some also use your mobile phone.


That really depends.

Some banks dont require a code at all for known contacts. Some banks dont require a code at all for small amounts (under 50). Some banks send you a plain SMS with a one-time-password. Some banks send you an SMS with some additional information (receiver, amount) and a one-time-password. Some banks ask for a one-time-password from a dongle. Some banks ask for a one-time-password by entering a challenge code into your dongle and then the dongle generates the new one-time-password. etc.

What I am trying to say is, there is no real standard. The best method I've come across so far is a device in which you insert your debit card, enter your pin, then scan a QR code on the computerscreen and the device will actually show you the receiving IBAN + amount. After pressing OK you get a challenge that you have to enter on the website.

Also in the Netherlands the banks have an API they can use called iDEAL which does the same as "SOFORT" but instead of having "SOFORT" log in to your account, your actual bank immediately transfers the funds and sends an OK to the vendor.

It makes me really angry that bank security isnt standardized and that good systems like iDEAL dont find international adoption. Luxembourg is trying to develope its own version of iDEAL e.g.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: