Hacker News new | past | comments | ask | show | jobs | submit login

Yikes! Banks need to start supporting other 2FA methods such as TOTP or U2F



Some do, but their backend systems are still vulnerable. Most folks here on HN would not believe me if I said that many of the back-end systems do not use encryption. There are still many automation jobs that use clear-text FTP on the WAN and for some jobs, even across the internet.



Yeah, this list is still pitiful: https://twofactorauth.org/#banking


Some do. Of the four banks where I currently have accounts, only one uses SMS-based 2FA codes; the other three all provide chip-and-pin card readers or similar gadgets to generate transaction-specific auth codes.


and, the banks that support 2FA need to figure out a way to keep supporting their data subscription services. there is no good OFX for 2FA




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: