📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Strong Customer Authentication (SCA) gone mad - we need standardisation

13»

Comments

  • k_man
    k_man Posts: 1,636 Forumite
    1,000 Posts Second Anniversary Name Dropper
    mar7t1n said:
    For all those saying, but I just use the banks app to authenticate. This is exactly my gripe. That you now have to download that banks specific app. It may be more useful that just the an authenticator but many aren't and that's pretty much all they do. The 2FA codes on Microsoft Authenticator and Google Authenticator and devices you get sent in the post apply a standard algorithm. The service your want to connect to sends a unique code to your device and then the code shown is based on that code and the time. Both sides know what the code is so can determine the same number. Whether you actually read it off and type it in or it's sent digitally it's all pretty much the same thing. Unlike a traditional password you cannot just tell someone what it is and they walk away and use it sometimes later. The "code" held on your device is a long code kept secure by your operating system. My gripe however remains every bank or building society now wants to do it differently, they all insist you download their app. Once you've got more than a couple of accounts it's a right pain.
    Can you give examples of which banks have an app that is just for authentication?

    I have quite a few bank apps, and all are banking apps (albeit some have less features than online banking) not just authenticator apps.

    Also, I much prefer app based authentication compared to TOTP (the method used by Google Authenticator etc), as usually it avoids the need to read and copy/type a code between apps/devices.
  • Daliah
    Daliah Posts: 3,792 Forumite
    1,000 Posts First Anniversary Photogenic Name Dropper
    k_man said:
    Can you give examples of which banks have an app that is just for authentication?

    The only one of the dozens of banks and building societies I know of is Cynergy. They are one of the few who still only do online banking. I think they offer a physical authenticator, as well as their digital one.

  • kaMelo
    kaMelo Posts: 2,863 Forumite
    Sixth Anniversary 1,000 Posts Name Dropper
    Al Ryan also offer an app solely for authentication to log in online alongside the normal app. Mainly aimed at those with older technology as it runs on a lowly Android 4.1 if I remember correctly.
  • Daliah
    Daliah Posts: 3,792 Forumite
    1,000 Posts First Anniversary Photogenic Name Dropper
    kaMelo said:
    Al Ryan also offer an app solely for authentication to log in online alongside the normal app. Mainly aimed at those with older technology as it runs on a lowly Android 4.1 if I remember correctly.
    Ah yes, that's correct. I never use their online banking as I can do everything I need to do through their normal app.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.3K Banking & Borrowing
  • 253.2K Reduce Debt & Boost Income
  • 453.7K Spending & Discounts
  • 244.2K Work, Benefits & Business
  • 599.3K Mortgages, Homes & Bills
  • 177.1K Life & Family
  • 257.7K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.