Strong Customer Authentication (SCA) gone mad - we need standardisation

mar7t1n
mar7t1n Posts: 115 Forumite
Part of the Furniture 10 Posts Name Dropper Combo Breaker
edited 29 May 2022 at 7:11PM in Budgeting & bank accounts
Strong Customer Authentication or 2 Factor Authentication is a wonderful thing to keep digital systems secure. And means the banks can now trust the instruction with a high degree of confidence which means they tend to do it rather than block you moving your own money and insist you call them. I know for sure even if someone finds my password, they still cannot access my account or use my card. But we need some industry standardisation on how it's achieved for everyone's sanity. Every bank now insists I download and install their bespoke authenticator app and set it up. For my main bank that's fine I want the app, but for accounts I'll setup now and leave for 1 year or more it's just OTT. The simplest systems are just sent me an SMS or call me with a code whenever I login. Google Authenticator is an alternative which stores all your 2FA codes in one place. Soon I'll need an app for every system I use - it could be hundreds.

The need for bank specific apps is a barrier to anyone born last century to setting this up, and means people feel forced into keeping their money with fewer financial institutions to avoid the authenticator app faff.

Mr Lewis we need a campaign to standardise and simplify or least insist the banks provide multiple ways of doing it so that you can choose the one which suits you best. It's simply good customer service. But the banks that provide that unfortunately don't pay very good interest rates.
«13

Comments

  • SiliconChip
    SiliconChip Posts: 1,772 Forumite
    1,000 Posts Third Anniversary Name Dropper
    I'm inclined to agree about the authenticators, I declined to open a Tandem account because they required use of their own authenticator (and as it happens the new YBS account pays more anyway - I can't have a Chase account as my phone isn't supported). I already have a Microsoft authenticator that I need for work, and I'd be willing to have a Google one too if it can cater for multiple apps, but banks insisting on their own authenticator seems to be overkill.
    Unfortunately there is approximately zero chance of Martin reading your thread, if you really want him to take it up you'll need to contact him through another route.
  • Daliah
    Daliah Posts: 3,792 Forumite
    1,000 Posts First Anniversary Photogenic Name Dropper
    I don't share your concerns, or your view that different authentication methods at different banks force me to keep my money in fewer places. I am nearly 70 and have no problems using dozens of different apps and websites. I don't choose where I keep my money based on the login method but based on where I get the best returns, whilst keeping my money best protected against loss. 

    The logical conclusion of your theory is that all financial institutions must use the same app / the same online banking, as processes like applying for an account, setting up a payee, making a payment, setting up a Standing Order etc are the same, and there isn't a reason for why they should use different technologies, designs and systems. The chances of any of this ever happening are next to none.


  • Daliah
    Daliah Posts: 3,792 Forumite
    1,000 Posts First Anniversary Photogenic Name Dropper
    I'm inclined to agree about the authenticators, I declined to open a Tandem account because they required use of their own authenticator 
    What Tandem authenticator?
  • masonic
    masonic Posts: 26,340 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    edited 27 May 2022 at 10:33AM
    It seems the regulator had some concerns about it becoming a monoculture, so standardising on a particular method could run counter to their policy. There was a clear steer towards giving multiple methods for SCA, including something not dependent on a smartphone. Not all banks currently offer this, but an increasing number are expanding options. Something built into the app itself using push notifications is becoming increasingly common, this is going to be the safest option as far as banks are concerned. The only providers who use TOTP and are compatible with Google Authenticator and others are (as far as I'm aware) investment providers. I'd personally be delighted if push notification, TOTP, SMS and email were all offered as options and could be selected or disabled by each customer depending on their needs, but I don't think that's even slightly realistic.
  • penners324
    penners324 Posts: 3,460 Forumite
    Sixth Anniversary 1,000 Posts Name Dropper
    In app authentication is vastly more secure than text message code. 
    I'd prefer all banks did it through their app.
  • penners324
    penners324 Posts: 3,460 Forumite
    Sixth Anniversary 1,000 Posts Name Dropper
    Daliah said:
    I'm inclined to agree about the authenticators, I declined to open a Tandem account because they required use of their own authenticator 
    What Tandem authenticator?
    Their own app.... but then it's an app only bank....
  • Zanderman
    Zanderman Posts: 4,839 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    mar7t1n said:

    The need for bank specific apps is a barrier to anyone born last centaury to setting this up, and means people feel forced into keeping their money with fewer financial institutions to avoid the authenticator app faff.

    Doesn't make me feel forced to do that at all.

    Indeed I (mostly) like the more secure systems via the apps.

    And I am definitely over 23.
  • Daliah
    Daliah Posts: 3,792 Forumite
    1,000 Posts First Anniversary Photogenic Name Dropper
    Daliah said:
    I'm inclined to agree about the authenticators, I declined to open a Tandem account because they required use of their own authenticator 
    What Tandem authenticator?
    Their own app.... but then it's an app only bank....
    Exactly. You wouldn't have a Tandem account without the Tandem app. I can't see the added value of bolting on an off-the-shelf authenticator, or messing about with their existing, smooth, processing for the sake of standardisation
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 349.7K Banking & Borrowing
  • 252.6K Reduce Debt & Boost Income
  • 452.9K Spending & Discounts
  • 242.7K Work, Benefits & Business
  • 619.4K Mortgages, Homes & Bills
  • 176.3K Life & Family
  • 255.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 15.1K Coronavirus Support Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.