We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

App based bank security

Options
12346»

Comments

  • km1500
    km1500 Posts: 2,790 Forumite
    1,000 Posts Second Anniversary Name Dropper
    One interesting experiment is to see what happens when you click 'forgotten logon details' on your banking website

    I remember Lloyds only wanting details from your debit card and a sms text to reset everything
  • Qyburn
    Qyburn Posts: 3,571 Forumite
    Fifth Anniversary 1,000 Posts Name Dropper
    Qyburn said:
    Our home LTE router can receive SMS messages. I'm experimenting using that as the designated mobile for some savings accounts. 
    That's an interesting idea, the router I'm guessing doesn't leave the house. 

    Would the device that you read the SMS messages on also be non-mobile (PC rather than mobile phone)?

    Are there not times when the savings provider might need to talk to you on the mobile number? Is that possible on a 4G router?
    Correct, the router stays in our roof space. To read the SMS I access from the LAN side via SSH, web or their proprietary management application. This can be done from phone, tablet or PC but only from inside our LAN, management protocols are disabled on the WAN as well as blocked by the firewall. For a savings account I don't need access from away from home. Theoretically I could VPN into the home network, to access from elsewhere.
    There's an element of security by obscurity as well.
    My router doesn't support voice calls, some modes do by having an analogue phone port.

  • Qyburn
    Qyburn Posts: 3,571 Forumite
    Fifth Anniversary 1,000 Posts Name Dropper
    I just noticed another weakness in on bank's App. It allows you to view full debit card details, including the security code. That particular bank authorised debit card transactions via the app so we're back to that single factor - break into the phone and you can do anything.
  • masonic
    masonic Posts: 27,126 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    edited 7 February 2023 at 7:33PM
    Qyburn said:
    I just noticed another weakness in on bank's App. It allows you to view full debit card details, including the security code. That particular bank authorised debit card transactions via the app so we're back to that single factor - break into the phone and you can do anything.
    If you can break into the app (i.e. get past lockscreen and app password or biometrics), then you wouldn't need to commit fraud by debit card. It would be more convenient just to transfer out all available funds via faster payment. It wouldn't be single factor, as it would still require something you have+know (password) or have+are (biometrics).
  • 35har1old
    35har1old Posts: 1,892 Forumite
    1,000 Posts Second Anniversary Name Dropper
    masonic said:
    It is a little concerning that a few of the banking apps have a passwordless login. Just enter a code sent by SMS and you're in. Many people don't have a lockscreen protected by a strong password, or allow message previews to be shown on the lockscreen. In an ideal world, banking apps would be loaded on a separate device that is physically secured and not taken out and about everywhere the owner goes.
    You can lock some phones with a 6 character ‘pin’ of letters and numbers, to protect your apps. And the phone will give a baddy only a few guesses at the pin before the phone is disabled. That’s not bad security. And any notifications don’t have to appear on the lock screen, nor should they if they’re sensitive.
    The banking apps that i use don't send SMS to log in. You enter a numerical code of 6 numbers that you set when you first use the app

    I recently opened a current account which could only be opened by app and in branch but it required you to have a mobile
  • cwep2
    cwep2 Posts: 233 Forumite
    Part of the Furniture 100 Posts Name Dropper Combo Breaker
    For what it's worth, any banking apps which could be used to send money to a new payee, I never use FaceID/Biometrics for, I always don't choose that when setting up so I still need to put in a password/passcode I remember. Slightly slower but feels more secure.

    Some savings accounts I use Face ID but these can only transfer to the one linked current account and the current account needs a passcode I have to remember. There may be edge cases where someone could try to change linked account but I'd like to think this would have some comeback to the institution if that happened after a phone gets stolen.

    Of course if someone comes at gun point and threatens to shoot me if I don't let them into the account, there's not much that can stop that.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.8K Banking & Borrowing
  • 253K Reduce Debt & Boost Income
  • 453.4K Spending & Discounts
  • 243.7K Work, Benefits & Business
  • 598.5K Mortgages, Homes & Bills
  • 176.8K Life & Family
  • 257K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.