📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Tandem login query

2»

Comments

  • jaypers
    jaypers Posts: 1,023 Forumite
    1,000 Posts Third Anniversary Photogenic Name Dropper
    Qyburn said:
    Biometric security is misleading in this context. If someone else sets up the app on their phone to access your account, it will be their face or their fingerprints "protecting" the app. If they can read your text message, they're in. Not just into Tandem but to some extent into your OB linked accounts. 

    I tested this process this morning.
    For them to be able to read my text message they would need to have my phone and also my phone unlock code or I would have needed to have unlocked it for them. 
    If your SIM doesn’t have a PIN set and it’s a physical SIM a criminal can simply put it in another phone and then have access to any new text messages etc. Common fraud. 
  • Qyburn
    Qyburn Posts: 3,497 Forumite
    1,000 Posts Fourth Anniversary Name Dropper
    For them to be able to read my text message they would need to have my phone and also my phone unlock code or I would have needed to have unlocked it for them. 
    Fair enough if you're happy with that level of protection. I was concerned that people commenting about face ID or other biometric logins, might mistakenly think that these protect their account in some way.

    I have some savings that will become available on 27th, I'm hoping someone matches Tandem's rate by then, or it will be a tough choice.
  • refluxer
    refluxer Posts: 3,167 Forumite
    1,000 Posts Fourth Anniversary Photogenic Name Dropper
    Do people receiving text messages every time they open the Tandem app have phones without fingerprint readers ?

    I have a phone with biometrics enabled and don't receive a text each time I open the app - I log in with my fingerprint. The only time I received a code was when I first set up the account (or if I 'log out' of the app). I even checked my texts to ensure I wasn't receiving one in the background which was auto-entered into the code field but that isn't happening.

    Another quick question following the concerns above about about security (and ignoring the gun-to-the-head scenario, which would get around pretty-much any security) - if money can only be sent and received from a linked UK current account in your name (which requires you to log into the other account and authorise the Open Banking request), how would a criminal be able to withdrawn money from the Tandem account ?  

      
  • Qyburn
    Qyburn Posts: 3,497 Forumite
    1,000 Posts Fourth Anniversary Name Dropper
    refluxer said:

    Another quick question following the concerns above about about security (and ignoring the gun-to-the-head scenario, which would get around pretty-much any security) - if money can only be sent and received from a linked UK current account in your name (which requires you to log into the other account and authorise the Open Banking request), how would a criminal be able to withdrawn money from the Tandem account ?  
      
    They probably wouldn't, unless they could link another bank account. But if you're OK with that, it's a bit like saying it's OK for Tandem to have crap security because I rely on my other banks to be secure. There may be other issues, getting even read only access to your Tandem account and to your OB linked accounts allows them to see your private financial information which could help with identity theft or other mischief. 
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.4K Banking & Borrowing
  • 252.9K Reduce Debt & Boost Income
  • 453.3K Spending & Discounts
  • 243.4K Work, Benefits & Business
  • 597.9K Mortgages, Homes & Bills
  • 176.6K Life & Family
  • 256.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.