Absa moving away from SMS and USSD

FNB doesn't use the PIN to log into Internet banking, they have a password. The PIN is, I suppose, to authenticate that you are indeed the cardholder and that you know the card.

I don't have an issue entering an e-PIN on a phone or PC. I have an issue entering a card PIN on a phone or PC.

Why does it matter?

They would need to steal your card to make any use of that PIN.
 
But not when updating a beneficiary? That's even more important.

You have never been able to update the account number when updating a beneficiary.

Just ran into a bug that will cause their customers some grief.

If you do a clean install of the OS of the phone that was registered as your authentication device and reinstall the app afterwards, ABSA's system thinks it is a new device, and the verification messages don't come through anymore.

^ This is going to be an annoying issue.
 

Yes I am aware.

But in this case it’s kind of in reverse and the poster should really be as concerned about one as they are of the other.

And sure although Microsoft logic is sound in the sense of locking out a single device it’s inherently more insecure as Joe Average will now use “1111” for a PIN instead of “Password123” or even worse if the Microsoft Account creation forces a complex password.

So basically in trying to protect the idiots from themselves they blow it all wide open.

Not to mention that in many cases with filthy hands and regular use the PIN keys would be quite apparent from looking at the keyboard.
 
Last edited:
Just ran into a bug that will cause their customers some grief.

If you do a clean install of the OS of the phone that was registered as your authentication device and reinstall the app afterwards, ABSA's system thinks it is a new device, and the verification messages don't come through anymore.

If you then log into IB via a PC and try to do it via the website, it informs you that it requires a push message acknowledgement from the 'original' device before you can add a new one.

You can also not unlink the original device before adding a new one, because that completely messes up the works, and you won't be able to use any banking function again that requires verification unless you visit a branch to sort it out.

The same thing happens when you do a clean install of the OS on a device that was previously registered for online streaming services like Netflix, Showmax and DStv Now. They all think it is a different device and add it to your quota.
Well not really a bug and I would expect it to work like this. It's no use to have 2FA when someone can just use your details to install it on a clean device.
 
I have ABSA accounts and FNB accounts. ABSA internet banking PIN is not the same PIN you use when you do ATM withdrawals and at no point does ABSA expect you to enter that PIN.

except absa does when you register and they want your account number and pin.
 
And why is a device you don't control secure but not one you have in your possession?

There is a big difference between a secure PIN entry device and your phone. A secure PIN entry device contains an encryption module which does not allow an unencrypted PIN to leave the device. A PIN block is sent, not the clear PIN. Your phone might be in your posession, but you don't control the firmware on it - there has been countless examples of dodgy things in operating systems, free apps, etc. Bank infrastructure gets audited - your phone doesn't.

Important for what? People should know that it's a way for the bank to authenticate themselves and not for the customer so if it's ever asked of the customer they should know to be suspicious.

I am not talking about the password where you are asked to enter random characters every time you log in, I am talking about the phrase you see on the second screen.

Its important because its a phrase that is never asked, it is just displayed on the second page in the autentication process, a phase which you chose and only you and the bank should know - so if a phishing site has an identical looking initial login page, you will know that it is a fake site when you get to the second screen and you don't see your passphrase.
 
Don’t know what dodgy app you have but certainly never needed to do that on mine.

Must be Android rubbish.

But how is a PIN any different to a Password? Other than being a must shorter and numeric only password which is therefore less secure.

Happens as far as I know on all mobile platforms, but definitely on Android
 
Why does it matter?

They would need to steal your card to make any use of that PIN.

It matters because in the banking world its very hard to steal the PIN - they have to have some camera mounted in the ATM or someone has to physically see you enter it. Once its entered, its not in the clear anymore as its sent upstream to the issuing bank.

Also, with fallback, you can steal the track data (in a few seconds in fact) and clone the card easily, fool the card reading device into thinking the chip on the card is broken and do a fallback magstripe card read.
 
No, it is not the same PIN as your bank card. Its a PIN used only for Internet and Mobile banking.

Have no problem entering my bank card pin into it. If you do have a problem with it, then don't bank with FNB, easy as that.

If FNB had some different e-pin I'd probably have forgotten it long ago (so I'd be forced to keep it saved somewhere) or it would be the same as the card pin anyway, because the only time I'd use it is the now and then in a blue moon that I need to load and setup the FNB app.
 
It matters because in the banking world its very hard to steal the PIN - they have to have some camera mounted in the ATM or someone has to physically see you enter it. Once its entered, its not in the clear anymore as its sent upstream to the issuing bank.

Also, with fallback, you can steal the track data (in a few seconds in fact) and clone the card easily, fool the card reading device into thinking the chip on the card is broken and do a fallback magstripe card read.

And why can't they just use some fake POS device to steal your pin AND clone the magstripe?
 
Have no problem entering my bank card pin into it. If you do have a problem with it, then don't bank with FNB, easy as that.

If FNB had some different e-pin I'd probably have forgotten it long ago (so I'd be forced to keep it saved somewhere) or it would be the same as the card pin anyway, because the only time I'd use it is the now and then in a blue moon that I need to load and setup the FNB app.

Also understand that if you get hit with fraud and someone compromised your card PIN you will have a very hard time getting your money back.

Fine if you don't have an issue with it - just understand why its a security risk. I think FNB also allows you to change your card PIN via the Internet banking app - which is also a security risk for the same reason.

I only bank with FNB because I have an FNB bond.
 
Also understand that if you get hit with fraud and someone compromised your card PIN you will have a very hard time getting your money back.

Fine if you don't have an issue with it - just understand why its a security risk. I think FNB also allows you to change your card PIN via the Internet banking app - which is also a security risk for the same reason.

I only bank with FNB because I have an FNB bond.

And I only bank with FNB for ebucks, so at worst they can steal up to my credit card limit and the R5000 I might eventually have in the savings pocket.

If they get into my Capitec it's more of an issue but not a total train smash either.
 
Well not really a bug and I would expect it to work like this. It's no use to have 2FA when someone can just use your details to install it on a clean device.

Good point, but there should be some sort of warning on the website about this for clients that are doing clean installs on their phones. If you selected Touch ID as the authentication method, then that is not a factor, of course.

I can see that ABSA is going to have a lot of irate customers on their hands shortly.

This will also affect victims of cellphone theft the same way. Now they will also have to visit the bank after replacing their phones.

Us techies and developers do frequent installs of the OS, and it should not be required to visit the bank every single time when doing that.

I have never tried adding more than one device to IB, but it might be possible to re-assign the authentication to another device and then changing it back afterwards (if this is allowed), before doing a clean install.

Otherwise the only way to evade this issue would be to keep your banking and streaming apps on a totally different phone than your daily driver, that never gets reinstalled.

The practicality of that is debatable.
 
Last edited:
Yes, they can, and they do. Either that, or a skimming device installed in an ATM

Which is why my Internet Banking app on my phone or tablet is infinitely more secure as it's completely within my control.
 
Which is why my Internet Banking app on my phone or tablet is infinitely more secure as it's completely within my control.

In a way, yes. But in other ways not. You can install apps on your phone which might scrape info without you knowing it - you don't have access to the source code of every app you install. Same with using Internet banking on open WIFI somewhere.

The point remains, you don't have to ask for bank PIN for mobile or Internet banking the way FNB does, so if you could eliminate the additional risk of potentially also compromising your bank PIN in addition to everything else, it should be done
 
Top
Sign up to the MyBroadband newsletter
X