Absa moving away from SMS and USSD

I have ABSA accounts and FNB accounts. ABSA internet banking PIN is not the same PIN you use when you do ATM withdrawals and at no point does ABSA expect you to enter that PIN.

But neither is FNB? I'm confused. Your banking pin and your card pin is always different?
 
But neither is FNB? I'm confused. Your banking pin and your card pin is always different?

I've set up my FNB mobile banking app twice in the last 6 months. On each occasion, during the setup process, I had to enter my FNB card number and card PIN, not a separate "e-PIN" used only for Internet or mobile banking.
 
I've set up my FNB mobile banking app twice in the last 6 months. On each occasion, during the setup process, I had to enter my FNB card number and card PIN, not a separate "e-PIN" used only for Internet or mobile banking.

But if you reset your online banking pin you would have to do this same, correct?

Also, how is entering your pin on your phone any different to entering your online banking pin? They both pose the same level of risk.
 
By eliminating SMS, the bank eliminates the risk of sim swops and number porting fraud. It does not make you more secure. You can still have your info phished. But it releases the cellphone network from any liability or risks. So it is not a bad change. But don't somehow think you are now safe.
 
But if you reset your online banking pin you would have to do this same, correct?

Also, how is entering your pin on your phone any different to entering your online banking pin? They both pose the same level of risk.

FNB doesn't use the PIN to log into Internet banking, they have a password. The PIN is, I suppose, to authenticate that you are indeed the cardholder and that you know the card.

I don't have an issue entering an e-PIN on a phone or PC. I have an issue entering a card PIN on a phone or PC.
 
By eliminating SMS, the bank eliminates the risk of sim swops and number porting fraud. It does not make you more secure. You can still have your info phished. But it releases the cellphone network from any liability or risks. So it is not a bad change. But don't somehow think you are now safe.

Its a good move - but they already addressed SIM swap fraud by detecting IMSI changes and locking your profile.
 
By eliminating SMS, the bank eliminates the risk of sim swops and number porting fraud. It does not make you more secure. You can still have your info phished. But it releases the cellphone network from any liability or risks. So it is not a bad change. But don't somehow think you are now safe.

I am safe, cause I cant be phished...
 
I am safe, cause I cant be phished...

I wonder how people, specifically using ABSA Internet banking, got phished? They have that "memorable phrase" screen that shows you a page with a phrase that only you should know - the phishing site would definitely not have that, and this is before you enter your passphrase random characters. So at most they should have only been able to get the access account number and e-PIN
 
I wonder how people, specifically using ABSA Internet banking, got phished? They have that "memorable phrase" screen that shows you a page with a phrase that only you should know - the phishing site would definitely not have that, and this is before you enter your passphrase random characters. So at most they should have only been able to get the access account number and e-PIN

A phishing site (I've looked at them for curiosity sake) normally asks all your info they want, like the full ABSA phrase and phone number and and and
 
A phishing site (I've looked at them for curiosity sake) normally asks all your info they want, like the full ABSA phrase and phone number and and and

That passphrase is more important than people realise. I can see how less technical people get caught out - the banks should do more to educate people on what to look out for
 
I'm finding it hard to care about this because I still can't use their f*****g app because they don't want you to root your phone. Stupid f*****g morons. Even the SnapScan app says that they have detected that your phone is rooted, so you use it at your own risk. Why can't ABSA do this?
 
I'm finding it hard to care about this because I still can't use their f*****g app because they don't want you to root your phone. Stupid f*****g morons. Even the SnapScan app says that they have detected that your phone is rooted, so you use it at your own risk. Why can't ABSA do this?

I suggest you retain the services of this individual:

YV6HAN.gif
 
SureCheck is triggered when clients perform any of the following actions:
About to make a payment
Create a new beneficiary
Set up a recurring payment
Add a new operator
Change your notification details
Update your daily limits
But not when updating a beneficiary? That's even more important.

Still, you have to enter a PIN that should only ever be entered on a device that is secure, like a pin pad, payment terminal or ATM
And why is a device you don't control secure but not one you have in your possession?

Add to that:
- How to check that the SSL cert is healthy
- Why the passphrase is important
- A healthy cert doesn't guarantee identity, only that the connection is secure. Unless they are educating people on that point they're actually doing more harm.
- Important for what? People should know that it's a way for the bank to authenticate themselves and not for the customer so if it's ever asked of the customer they should know to be suspicious.
 
Just ran into a bug that will cause their customers some grief.

If you do a clean install of the OS of the phone that was registered as your authentication device and reinstall the app afterwards, ABSA's system thinks it is a new device, and the verification messages don't come through anymore.

If you then log into IB via a PC and try to do it via the website, it informs you that it requires a push message acknowledgement from the 'original' device before you can add a new one.

You can also not unlink the original device before adding a new one, because that completely messes up the works, and you won't be able to use any banking function again that requires verification unless you visit a branch to sort it out.

The same thing happens when you do a clean install of the OS on a device that was previously registered for online streaming services like Netflix, Showmax and DStv Now. They all think it is a different device and add it to your quota.
 
Last edited:
When you set up your FNB Internet banking app

Don’t know what dodgy app you have but certainly never needed to do that on mine.

Must be Android rubbish.

But how is a PIN any different to a Password? Other than being a must shorter and numeric only password which is therefore less secure.
 
Top
Sign up to the MyBroadband newsletter
X