South Africa’s biggest forum. Discuss, discover, and connect with thousands of members.
Bank infrastructure gets hacked more easily than the off chance of my pin being sent over an unencrypted connection. I'm more worried about who or what's looking over my shoulder when using an ATM. Your device can only really be insecure if you rooted it.There is a big difference between a secure PIN entry device and your phone. A secure PIN entry device contains an encryption module which does not allow an unencrypted PIN to leave the device. A PIN block is sent, not the clear PIN. Your phone might be in your posession, but you don't control the firmware on it - there has been countless examples of dodgy things in operating systems, free apps, etc. Bank infrastructure gets audited - your phone doesn't.
And that's exactly what I'm talking about. Simply telling people that it's important because only they and the bank know it, the why, doesn't cut it. They should be educated on the fact that it should be displayed to them and never asked, the for what part.I am not talking about the password where you are asked to enter random characters every time you log in, I am talking about the phrase you see on the second screen.
Its important because its a phrase that is never asked, it is just displayed on the second page in the autentication process, a phase which you chose and only you and the bank should know - so if a phishing site has an identical looking initial login page, you will know that it is a fake site when you get to the second screen and you don't see your passphrase.
Agreed. Ideally you should get a pin (the salt key) once in the bank and be able to use it to reinstall the app.Good point, but there should be some sort of warning on the website about this for clients that are doing clean installs on their phones. If you selected Touch ID as the authentication method, then that is not a factor, of course.
I can see that ABSA is going to have a lot of irate customers on their hands shortly.
This will also affect victims of cellphone theft the same way. Now they will also have to visit the bank after replacing their phones.
Us techies and developers do frequent installs of the OS, and it should not be required to visit the bank every single time when doing that.
I have never tried adding more than one device to IB, but it might be possible to re-assign the authentication to another device and then changing it back afterwards (if this is allowed), before doing a clean install.
Otherwise the only way to evade this issue would be to keep your banking and streaming apps on a totally different phone than your daily driver, that never gets reinstalled.
The practicality of that is debatable.
Exactly. Should have the option of a token.What about people who don't have smartphones?
In a way, yes. But in other ways not. You can install apps on your phone which might scrape info without you knowing it - you don't have access to the source code of every app you install. Same with using Internet banking on open WIFI somewhere.
The point remains, you don't have to ask for bank PIN for mobile or Internet banking the way FNB does, so if you could eliminate the additional risk of potentially also compromising your bank PIN in addition to everything else, it should be done
Not on IOS you can't. Apps are sandbox ed.
Internet Banking on open wireless is still encrypted, so no go there either.
I'm yet to see FNB ask me for my PIN. It all sounds like a deeply Android problem.
1. Sandbox escape on IOS is trivial. Shame.
2. You probably don't bank with FNB at all. In the app if you change your limits it asks for the pin attached to the primary credit card number on the account. Or you are using mommy's credit card which, as a secondary, doesn't allow you to change anything.
3. Open wireless is still encrypted? Ok. You really don't know much.