We'd like to remind Forumites to please avoid political debate on the Forum... Read More »
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
TANDEM APP SECURITY CONCERN
Comments
-
Stargunner said:With Tandem you can only transfer money to s linked bank account in the account holder’s name, so you don’t need to be worrying.0
-
Qyburn said:horsewithnoname said:I’ve got facial recognition on mine. If it ain’t my face the app won’t open. Mind you neither would the phone in the first place to get to the app.
what is stopping someone else to using the app to access your account is the fact that you need an access code which is sent to your registered mobile number. Provided you have a SIM lock - as recommended, not just for Tandem - that code arrives on your mobile and thwarts all efforts of the fraudster.
But even if you choose not to have a SIM lock, all they could do is send money to a current account in your name.
1 -
Look after your mobile phone 😁2
-
Qyburn said:Stargunner said:With Tandem you can only transfer money to s linked bank account in the account holder’s name, so you don’t need to be worrying.
A new current account could only be linked if it is in your name. It will be checked by OB, or manually, that it is an account in your name. For either method of checking, access to the account, or at least to a statement for the account, is required. It's not impossible for a fraudster to have that information - though if they do, it's because you failed to protect your information.If you allow the fraudster to access your mobile and your current account data, they could see how much money they can't get their hands on. They also can see which accounts you have linked, together with the sort codes and account number (which are printed on most debit cards and on cheques). But they cannot access those current accounts unless you have been negligent with your login information for the current accounts.All your perceived issues are down to the user being negligent with their login information0 -
Bobby4puddings said:
Up until recently there was a hack that could unlock an Android phone in less than 1 minute without any additional software. Google cured this with with a security patch on Google Pixel phones but not others, they were working on it.0 -
It might be of interest to those worried about the lack of a password in Tandem to read up about FIDO2, the passwordless authentication method coming to more and more of our apps and online accounts. Even Password Managers have now started authentication without passwords, and just about all big players are members of the FIDO allianceAlso worth a read: Why FIDO 2 Represents The Death Knell For PasswordsNote I have no insight into the technology deployed by Tandem (doubt they are using FIDO2) but I am satisified that my money is safe with them, despite the absence of a password..
1 -
Qyburn said:horsewithnoname said:I’ve got facial recognition on mine. If it ain’t my face the app won’t open. Mind you neither would the phone in the first place to get to the app.
I've seen a few posts where people seem to think a biometric logins adds security. It doesn't. What it does is allow access bypassing other measures. So it's for ease of use, rather than security. When my fingerprint doesn't work on my iPhone I can unlock with the passcode. If a third party knew my passcode they could unlock the phone and add their own fingerprint.
Same with banking apps. If I allow TSB to use fingerprints I can login without knowing any account information, but if fingerprint doesn't work I can still access using passwords etc. Two alternative types of security, either one of which lets you in. Not two layers.All true, but use of biometrics does allow for people to use more complex passwords without the inconvenience of having to enter them frequently and/or store them in a manner that they may be more easily observed.What is frustrating is that some of these apps will let you set up a PIN, but it is local to the app and doesn't stop someone reinstalling the app to bypass it.0 -
I've come to the conclusion that carrying a phone around with 30-odd apps that give access to financial institutions' systems holding my money is silly. Not so much the security aspect, I'm happy that the phone and each of the apps is tied down about as hard as they can be, but more from the sheer inconvenience of having to a) re-secure access to those systems that have online access and, b) regaining access to those which are app-only, should I lose access to my phone (for whatever reason).
On a day-to-day basis I only need mobile access to a couple of current accounts (and a Revolut account that it only used for contactless payments) so I have a second phone with just those three apps installed and that's the one that gets out of the house.
Not a cheap option if you want both phones to have OS/security updates for a few years but makes for less anxiety.
2 -
flaneurs_lobster said:I've come to the conclusion that carrying a phone around with 30-odd apps that give access to financial institutions' systems holding my money is silly. Not so much the security aspect, I'm happy that the phone and each of the apps is tied down about as hard as they can be, but more from the sheer inconvenience of having to a) re-secure access to those systems that have online access and, b) regaining access to those which are app-only, should I lose access to my phone (for whatever reason).
1 -
masonic said:
I certainly feel no animosity towards those that required me to jump through some hoops, but it was an eye opener to how differently organisations approach this.2
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 350.4K Banking & Borrowing
- 252.9K Reduce Debt & Boost Income
- 453.3K Spending & Discounts
- 243.4K Work, Benefits & Business
- 597.9K Mortgages, Homes & Bills
- 176.6K Life & Family
- 256.4K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.6K Read-Only Boards