📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Strong Customer Authentication - **Now delayed** changes to online verification

1246731

Comments

  • Migster
    Migster Posts: 150 Forumite
    Part of the Furniture 100 Posts
    The September deadline is somewhat up in the air at the moment, at least for e-commerce card payments.

    There are three elements to authentication under SCA and the banks must use two of them. The three elements are a) something you are, b) something you possess and c) something you know.

    Up until recently, it was assumed that an OTP would count as something you know, but the EBA recently threw a spanner in the works by stating that this was not the case.

    In response to this the FCA had the following to say:

    “…the FCA recognises the challenges in meeting this deadline and has been working with the industry to develop a plan to migrate the industry to implement SCA for card payments in e-commerce as soon as possible after this”.

    If you google “EBA SCA opinion” you’ll find more details, though be warned, it’s not the most exciting read.
  • londoninvestor
    londoninvestor Posts: 1,351 Forumite
    Sixth Anniversary Combo Breaker
    lr1277 wrote: »
    I think Metro bank are using a OTP to a mobile phone based on this webpage:
    https://www.metrobankonline.co.uk/ways-to-bank/i-want-some-information-about/fraud-and-security/

    Yes for setting up payees; not (yet) for logging into online banking.
  • Herbalus
    Herbalus Posts: 2,634 Forumite
    Tenth Anniversary 1,000 Posts Name Dropper
    Not sure how extensive you want the list to be, but tandem credit cards are already using an OTP to mobile when making purchases online.

    But given it’s app only, everybody who has it will by definition have a mobile so won’t be a barrier.
  • brianposter
    brianposter Posts: 1,510 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    Migster wrote: »
    The September deadline is somewhat up in the air at the moment, at least for e-commerce card payments.
    Already had my HSBC cards fail repeatedly for online purchases.
    The banks appear to be being particularly incompetent in implementing these measures - sending passcodes to fixed line phones doesn't appear to be especially difficult.
  • eskbanker
    eskbanker Posts: 36,928 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    Herbalus wrote: »
    Not sure how extensive you want the list to be, but tandem credit cards are already using an OTP to mobile when making purchases online.
    Happy to add info in if supported by a link?
  • peachyprice
    peachyprice Posts: 22,346 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    18cc wrote: »
    Does this also apply to eg Monzo, Starling or is it desktop banking they are targeting?
    eskbanker wrote: »
    Two factor authentication involves:My understanding is that an app is considered to be the middle of these and therefore, if combined with passwords/PINs, etc, satisfies the requirement, hence the use of apps as a second factor for non-app banks.

    So, app-only banks, assuming they also require the use of something the user knows (or is, such as fingerprint/facial recognition), shouldn't need any additional securing.

    Happy to be corrected though, I'm not claiming to be an expert!


    Monzo already use OTP.

    Although they seem to be pretty good at recognising spending patterns and will auto authorise transactions from retailers you've already used an OTP for a few times.
    Accept your past without regret, handle your present with confidence and face your future without fear
  • Herbalus
    Herbalus Posts: 2,634 Forumite
    Tenth Anniversary 1,000 Posts Name Dropper
    eskbanker wrote: »
    Happy to add info in if supported by a link?

    Probably doesn’t make the cut for authoritative info on here from the FAQs looking like a community blog https://intercom.help/tandembank/en/articles/1978234-online-purchases

    But the first 3 transactions I’ve done online (I’ve only just got the card) have all sent a passcode to my mobile.
  • MovingForwards
    MovingForwards Posts: 17,139 Forumite
    10,000 Posts Sixth Anniversary Name Dropper Photogenic
    Can't find the virgin letter eskbanker, but will come back if I get any more information.
    Mortgage started 2020, aiming to clear 31/12/2029.
  • Radnorsaver
    Radnorsaver Posts: 26 Forumite
    Ninth Anniversary 10 Posts Combo Breaker
    Capital One (capitalone.co.uk) credit cards will send OTP to EITHER mobile or landline, which is fine. Why can't others do it?
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.4K Banking & Borrowing
  • 252.9K Reduce Debt & Boost Income
  • 453.3K Spending & Discounts
  • 243.4K Work, Benefits & Business
  • 598K Mortgages, Homes & Bills
  • 176.6K Life & Family
  • 256.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.