We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide
Chip Feedback
Comments
-
What's needed is a device-controlled face ID system. This should involve sensors that can't be fooled by pictures etc. If you device doesn't have its own robust faceID technology (where your biometrics never leave your device), then the app absolutely should not offer it as it is horrendously insecure using just a smartphone camera (and involves the app developer harvesting your biometrics). If you don't have a proper face ID set-up on your device, then any app that offers it should be treated with the greatest suspicion and contempt - these are the organisations that will compromise your identity information and give you a massive identification headache. Don't let them scan your face!Bridlington1 said:
All I can find is this:allegro120 said:
This option appeared only after I set up 4 digit PIN.Bridlington1 said:I set the chip pin up yesterday. There doesn't seem to be any option to set up face ID though this is not unique to the Chip app to be fair.
1 -
I don't know if my phone has any sensors or not but I know it doesn't have the option to be locked with face ID so I'd assume it doesn't have any. I have tried face ID in the Natwest and Atom apps before but these tend to be a bit hit and miss as to whether they actually work or not with them struggling to recognise my face if it's raining or dark outside so I reverted to using pins in the end. As a result I don't normally bother with face ID. I appreciate the warning though.masonic said:
What's needed is a device-controlled face ID system. This should involve sensors that can't be fooled by pictures etc. If you device doesn't have its own robust faceID technology (where your biometrics never leave your device), then the app absolutely should not offer it as it is horrendously insecure using just a smartphone camera (and involves the app developer harvesting your biometrics). If you don't have a proper face ID set-up on your device, then any app that offers it should be treated with the greatest suspicion and contempt - these are the organisations that will compromise your identity information and give you a massive identification headache. Don't let them scan your face!Bridlington1 said:
All I can find is this:allegro120 said:
This option appeared only after I set up 4 digit PIN.Bridlington1 said:I set the chip pin up yesterday. There doesn't seem to be any option to set up face ID though this is not unique to the Chip app to be fair.0 -
I just realised Chip can't even change your nominated bank account without having to talk to the apparently non existent customer service staff. Why would they not add that feature when it's pretty much a basic function of Truelayer anyway? Maybe you can do it by going into the current account and removing Chips Truelayer permissions?0
-
Mainly because of the lack of security in the App. It would be quite a concern if the nominated account could be freely changed without additional security. Customer service staff exist on working days 8am-8pm.Zaul22 said:I just realised Chip can't even change your nominated bank account without having to talk to the apparently non existent customer service staff. Why would they not add that feature when it's pretty much a basic function of Truelayer anyway? Maybe you can do it by going into the current account and removing Chips Truelayer permissions?
0 -
What extra security? You send them a message through the very same app and they remove the nominated account. Then your add a new one.masonic said:
Mainly because of the lack of security in the App. It would be quite a concern if the nominated account could be freely changed without additional security. Customer service staff exist on working days 8am-8pm.Zaul22 said:I just realised Chip can't even change your nominated bank account without having to talk to the apparently non existent customer service staff. Why would they not add that feature when it's pretty much a basic function of Truelayer anyway? Maybe you can do it by going into the current account and removing Chips Truelayer permissions?
0 -
Are you saying that they go through no identity verification steps before removing the existing linked account?grumbler said:
What extra security? You send them a message through the very same app and they remove the nominated account. Then your add a new one.masonic said:
Mainly because of the lack of security in the App. It would be quite a concern if the nominated account could be freely changed without additional security. Customer service staff exist on working days 8am-8pm.Zaul22 said:I just realised Chip can't even change your nominated bank account without having to talk to the apparently non existent customer service staff. Why would they not add that feature when it's pretty much a basic function of Truelayer anyway? Maybe you can do it by going into the current account and removing Chips Truelayer permissions?
0 -
Not that I remember. And it took them more than 24 hours despite they "typically reply within a day". Hardly a surprise if they are busy with manually dealing with such routine actions that can be done by customers without their intervention.masonic said:
Are you saying that they go through no identity verification steps before removing the existing linked account?grumbler said:
What extra security? You send them a message through the very same app and they remove the nominated account. Then your add a new one.masonic said:
Mainly because of the lack of security in the App. It would be quite a concern if the nominated account could be freely changed without additional security. Customer service staff exist on working days 8am-8pm.Zaul22 said:I just realised Chip can't even change your nominated bank account without having to talk to the apparently non existent customer service staff. Why would they not add that feature when it's pretty much a basic function of Truelayer anyway? Maybe you can do it by going into the current account and removing Chips Truelayer permissions?
1 -
Wow. If true, then that's a red flag, and a potential breach of the Payment Services Regulations around carrying out actions that may imply a risk of payment fraud without strong customer authentication. At best, a message being sent from within an app that doesn't come with any sort of password protection by default, is single factor authentication.grumbler said:
Not that I remember. And it took them more than 24 hours despite they "typically reply within a day". Hardly a surprise if they are busy with manually dealing with such routine actions that can be done by customers without their intervention.masonic said:
Are you saying that they go through no identity verification steps before removing the existing linked account?grumbler said:
What extra security? You send them a message through the very same app and they remove the nominated account. Then your add a new one.masonic said:
Mainly because of the lack of security in the App. It would be quite a concern if the nominated account could be freely changed without additional security. Customer service staff exist on working days 8am-8pm.Zaul22 said:I just realised Chip can't even change your nominated bank account without having to talk to the apparently non existent customer service staff. Why would they not add that feature when it's pretty much a basic function of Truelayer anyway? Maybe you can do it by going into the current account and removing Chips Truelayer permissions?
0 -
I can confirm I changed my nominated account from Lloyds to Nationwide by sending them a message in the app only 2 months ago. No additional security was required.masonic said:
Wow. If true, then that's a red flag, and a potential breach of the Payment Services Regulations around carrying out actions that may imply a risk of payment fraud without strong customer authentication. At best, a message being sent from within an app that doesn't come with any sort of password protection by default, is single factor authentication.grumbler said:
Not that I remember. And it took them more than 24 hours despite they "typically reply within a day". Hardly a surprise if they are busy with manually dealing with such routine actions that can be done by customers without their intervention.masonic said:
Are you saying that they go through no identity verification steps before removing the existing linked account?grumbler said:
What extra security? You send them a message through the very same app and they remove the nominated account. Then your add a new one.masonic said:
Mainly because of the lack of security in the App. It would be quite a concern if the nominated account could be freely changed without additional security. Customer service staff exist on working days 8am-8pm.Zaul22 said:I just realised Chip can't even change your nominated bank account without having to talk to the apparently non existent customer service staff. Why would they not add that feature when it's pretty much a basic function of Truelayer anyway? Maybe you can do it by going into the current account and removing Chips Truelayer permissions?
If someone else had got hold of my phone at that time and got past my lock screen I wouldn't have known until I'd checked my emails and seen an email from Chip telling me that my nominated account had been removed and that I would be prompted to add a new debit card next time I logged into the app. They never even sent me a message telling me they'd received a request to change my nominated account details beforehand.
I was able to make a withdrawal to my new nominated account that same day.1 -
Well that is an unsatisfactory way to handle such a change, to say the least. They don't actually have any password or security questions on file, other than personal information collected during application, so that puts them at quite the disadvantage when confirming they are chatting to the account holder.Zaul22 is probably on to something when mentioning revocation, as requiring the customer to revoke TrueLayer access, which can only be done after logging in to the linked bank, would verify that it is really the customer who wishes to make the change (any fraudster who could do this probably wouldn't need to change the linked account). They could fall back to the selfie holding ID document method that they use for changing the phone number for situations where the customer cannot revoke access. All could be done without CS intervention.It gives me pause to reconsider my use of Chip. A change of linked account does require verification of the new linked account holder's name, I don't know how strictly that is being checked, and it might not be enough for a targeted attack involving identity theft. Personally I think I keep my devices sufficiently secured not to be too concerned about that, but if they are not following regulatory obligations here, what else are they doing wrong that I don't know about?..2
Confirm your email address to Create Threads and Reply
Categories
- All Categories
- 353.4K Banking & Borrowing
- 254.1K Reduce Debt & Boost Income
- 455K Spending & Discounts
- 246.5K Work, Benefits & Business
- 602.8K Mortgages, Homes & Bills
- 178K Life & Family
- 260.5K Travel & Transport
- 1.5M Hobbies & Leisure
- 16K Discuss & Feedback
- 37.7K Read-Only Boards
