We're aware that some users are experiencing technical issues which the team are working to resolve. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Strong Customer Authentication - **Now delayed** changes to online verification

Options
12526272931

Comments

  • Stompa
    Stompa Posts: 8,374 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    masonic wrote: »
    I'm a bit confused about what actually happened. This is what I originally thought:

    1) Installed app
    2) Entered information into app to identify yourself
    3) Prompted to call Nationwide (as no 2FA options possible)
    4) App activation completed over phonecall
    5) Mobile number added within app

    Or did the app allow you to edit your details after step 2, without NW intervening? Or did NW add the number for you when you used activation of the app as an excuse?
    I'm not sure I used activation as an excuse as such. But it was 1,2,3 and I then asked them to just add the number to my account.

    I imagine I could have avoided all this palaver by simply phoning up customer service and getting them to do it. And I would have done just that if it weren't for the fact that it says on their website (in at least two different places) that you can't do it that way.
    Stompa
  • DragonQ
    DragonQ Posts: 2,198 Forumite
    Part of the Furniture 1,000 Posts
    So HSBC & First Direct are the only ones to not allow OTP to login. Definitely won't be using them for anything day-to-day then. I like that the Lloyds Group banks (and TSB) allow OTP to a landline too.
  • eskbanker
    eskbanker Posts: 36,929 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    DragonQ wrote: »
    So HSBC & First Direct are the only ones to not allow OTP to login. Definitely won't be using them for anything day-to-day then.
    Are you seeing the HSBC/FD 2FA model as less secure than OTPs?
  • Ergates
    Ergates Posts: 3,022 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    DragonQ wrote: »
    So HSBC & First Direct are the only ones to not allow OTP to login. Definitely won't be using them for anything day-to-day then. I like that the Lloyds Group banks (and TSB) allow OTP to a landline too.

    The EBA have declared that OTPs do not meet their security requirements for PSD2. Unfortunately, they declared this very late in the day, *after* most banks had already built their 2FA systems using OTPs.

    So, expect to see more banks moving away from OTPs.
  • masonic
    masonic Posts: 26,986 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    DragonQ wrote: »
    So HSBC & First Direct are the only ones to not allow OTP to login. Definitely won't be using them for anything day-to-day then. I like that the Lloyds Group banks (and TSB) allow OTP to a landline too.
    HSBC and First Direct both use OTP. Specifically they use time-based OTP or TOTP using a device, which is the preferred implementation. You have the choice of activating it through their mobile app or a physical device ("secure key").

    SMS-based OTP has had its days numbered since 2016, when the NIST pointed out its flaws. Good to see the EBA catching up at last, and eventually the FCA is bound to follow suit. The only reason it has been so widely adopted is it is convenient, but convenience is the enemy of security.
  • mro
    mro Posts: 813 Forumite
    Tenth Anniversary 500 Posts Combo Breaker
    masonic wrote: »
    HSBC and First Direct both use OTP. Specifically they use time-based OTP or TOTP using a device, which is the preferred implementation. You have the choice of activating it through their mobile app or a physical device ("secure key").

    SMS-based OTP has had its days numbered since 2016, when the NIST pointed out its flaws. Good to see the EBA catching up at last, and eventually the FCA is bound to follow suit. The only reason it has been so widely adopted is it is convenient, but convenience is the enemy of security.
    Until security becomes too much, inconvenient & over the top.
    .
  • mro
    mro Posts: 813 Forumite
    Tenth Anniversary 500 Posts Combo Breaker
    Will Brexit affect rollout ?
    .
  • eskbanker
    eskbanker Posts: 36,929 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    mro wrote: »
    Will Brexit affect rollout ?
    Not unless this UK government (or a future one) independently chooses to repeal the Payment Services Regulations 2017 and I imagine they'll have somewhat bigger fish to fry....
  • masonic
    masonic Posts: 26,986 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    mro wrote: »
    Until security becomes too much, inconvenient & over the top.
    .
    Well not really. You can have perfect security when when a product becomes so inconvenient that nobody can be bothered to use it.
  • Doc_N
    Doc_N Posts: 8,537 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    masonic wrote: »
    Well not really. You can have perfect security when when a product becomes so inconvenient that nobody can be bothered to use it.

    Which is the point that was being made. And some products are fast reaching that point for some of us, perhaps.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.6K Banking & Borrowing
  • 253K Reduce Debt & Boost Income
  • 453.4K Spending & Discounts
  • 243.6K Work, Benefits & Business
  • 598.3K Mortgages, Homes & Bills
  • 176.8K Life & Family
  • 256.8K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.