Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings
Discussion options

Currently, we classify a number of banks as having 2FA, when they only require it for certain transactions, not for logging in to their website. My question is whether or not we should change any of the banks listed below to tfa: No, add an exception to each of them, or find a way to include a transactional flag on the website.

Below is a list of banks that do not currently fall under our definition of 2FA, despite having the tfa flag set to Yes. I'm curious as to how everyone feels we should handle these types of situations with these banks and any additional ones going forward.

  • Barclays UK's PINSentry doesn't qualify for our definition of 2FA, as their website shows that it is only required for certain transactions.
  • Citibank Australia's OTP doesn't qualify for our definition of 2FA, as it seems that they only require it for certain transactions. Their website says:
    You'll need to enter this anytime you want to perform select online transactions or query through Citibank Online.
  • Commonwealth Bank of Australia's NetCode doesn't qualify for our definition of 2FA, as their website states that it's only required for certain transactions.
  • first direct's Secure Key doesn't qualify for our definition of 2FA, as it can be bypassed using a password to login. Their website says:
    ...this doesn't mean you can't access your accounts if you don't have it with you. You can still log on without it and have limited access to Internet Banking by selecting the link at the top of the log on page...
  • HSBC's Secure Key doesn't qualify for our definition of 2FA, as their website shows how you can choose the "Without Secure Key" tab when logging in to bypass 2FA.
  • Nationwide Building Society's card reader doesn't qualify for our definition of 2FA, as the it can be bypassed using a password to login. Their website says:

You can still log in with your memorable data and passnumber, but by using your card reader you may reduce the number of times it's needed to confirm your online transactions.

  • Natwest's card reader doesn't qualify for our definition of 2FA, as they only require the card reader be used for certain transactions. In fact, their website specifically says:
    We will never ask you to use your card reader to log in to Online Banking, and we will never phone you to ask for your card reader details.

  • Santander's SMS-based OTP doesn't qualify for our definition of 2FA, as they only require an OTP for certain transactions. Their website says:
    ...we send these unique codes to your mobile to security check payments that you have recently set up (and) requests you make to amend some important details like your address.

  • State Bank of India's OTP application doesn't qualify for our definition of 2FA, as they only require an OTP for certain transactions.

You must be logged in to vote

Replies: 4 comments · 1 reply

Comment options

Yup, I say all of these updated as tfa: no.
And perhaps add faq section that elaborates on differences between authentication and authorization?

You must be logged in to vote
0 replies
Comment options

You're right. These don't qualify as two-factor.

You must be logged in to vote
0 replies
Comment options

I've had a look at the list of banks... seems very hit and miss, and the vast majority (but certainly not all) utilise some kind of step-up authentication and that we'll have a long, long list of banks that have this. I suspect that without further explanation, attempts to petition these banks to change it will fall on deaf ears. Their staff aren't trained on the difference, or why it matters (and they'll probably just say "we do use two-factor authentication".

Any thoughts on adding adding a stepup property? This would indicate that the service requires a second factor only for certain actions, and perhaps with a link to further information on the difference (this Quora answer actually does a decent job, IMO), and why two-factor authentication is preferable to this.

You must be logged in to vote
0 replies
Comment options

I disagree that not requiring 2FA in some scenarios "doesn't qualify as two factor":

  • Allowing low risk actives without 2FA reduces user inconvenience and boosts adoption of 2FA. Not everyone has a hardware token on each machine and multiple backups. And even with those enabled, my GF complains about all the 2FA I have forced on her accounts.
  • Requiring 2FA for high risk transactions could be used to create a finer grained security model, as malware (etc) can't perform arbitrary transactions after logging in.

2FA shouldn't just be an improved sudo command with arbitrary access to an entire system, it's better if we scope capabilities to specific tasks.

Mandating which tasks is tricky and probably best figured out by a standards body, not an ad-hoc site run by volunteers. That sort of granular detail is probably best expressed as a grading system, not a binary yes/no.

You must be logged in to vote
1 reply
@mxxcon
Comment options

Perfect example of confusing authentication and authorization.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Issue contains a question.
5 participants
Converted from issue

This discussion was converted from issue #1811 on October 05, 2021 22:14.

Morty Proxy This is a proxified and sanitized view of the page, visit original site.