Absa moving away from SMS and USSD

No, it is not the same PIN as your bank card. Its a PIN used only for Internet and Mobile banking.
As you can see when you register on your device it clearly states ATM card no and PIN IMG_20170922_194723.jpg
 
There is a big difference between a secure PIN entry device and your phone. A secure PIN entry device contains an encryption module which does not allow an unencrypted PIN to leave the device. A PIN block is sent, not the clear PIN. Your phone might be in your posession, but you don't control the firmware on it - there has been countless examples of dodgy things in operating systems, free apps, etc. Bank infrastructure gets audited - your phone doesn't.
Bank infrastructure gets hacked more easily than the off chance of my pin being sent over an unencrypted connection. I'm more worried about who or what's looking over my shoulder when using an ATM. Your device can only really be insecure if you rooted it.

I am not talking about the password where you are asked to enter random characters every time you log in, I am talking about the phrase you see on the second screen.

Its important because its a phrase that is never asked, it is just displayed on the second page in the autentication process, a phase which you chose and only you and the bank should know - so if a phishing site has an identical looking initial login page, you will know that it is a fake site when you get to the second screen and you don't see your passphrase.
And that's exactly what I'm talking about. Simply telling people that it's important because only they and the bank know it, the why, doesn't cut it. They should be educated on the fact that it should be displayed to them and never asked, the for what part.

Good point, but there should be some sort of warning on the website about this for clients that are doing clean installs on their phones. If you selected Touch ID as the authentication method, then that is not a factor, of course.

I can see that ABSA is going to have a lot of irate customers on their hands shortly.

This will also affect victims of cellphone theft the same way. Now they will also have to visit the bank after replacing their phones.

Us techies and developers do frequent installs of the OS, and it should not be required to visit the bank every single time when doing that.

I have never tried adding more than one device to IB, but it might be possible to re-assign the authentication to another device and then changing it back afterwards (if this is allowed), before doing a clean install.

Otherwise the only way to evade this issue would be to keep your banking and streaming apps on a totally different phone than your daily driver, that never gets reinstalled.

The practicality of that is debatable.
Agreed. Ideally you should get a pin (the salt key) once in the bank and be able to use it to reinstall the app.

What about people who don't have smartphones?
Exactly. Should have the option of a token.
 
In a way, yes. But in other ways not. You can install apps on your phone which might scrape info without you knowing it - you don't have access to the source code of every app you install. Same with using Internet banking on open WIFI somewhere.

The point remains, you don't have to ask for bank PIN for mobile or Internet banking the way FNB does, so if you could eliminate the additional risk of potentially also compromising your bank PIN in addition to everything else, it should be done

Not on IOS you can't. Apps are sandbox ed.

Internet Banking on open wireless is still encrypted, so no go there either.

I'm yet to see FNB ask me for my PIN. It all sounds like a deeply Android problem.
 
Not on IOS you can't. Apps are sandbox ed.

Internet Banking on open wireless is still encrypted, so no go there either.

I'm yet to see FNB ask me for my PIN. It all sounds like a deeply Android problem.

1. Sandbox escape on IOS is trivial. Shame.

2. You probably don't bank with FNB at all. In the app if you change your limits it asks for the pin attached to the primary credit card number on the account. Or you are using mommy's credit card which, as a secondary, doesn't allow you to change anything.

3. Open wireless is still encrypted? Ok. You really don't know much.
 
1. Sandbox escape on IOS is trivial. Shame.

No one app can access another app's data. They only talk to the OS and it's select built-in app functions through API.

Apps also get vetted properly, so it's very highly unlikely such a situation would ever occur on IOS.

2. You probably don't bank with FNB at all. In the app if you change your limits it asks for the pin attached to the primary credit card number on the account. Or you are using mommy's credit card which, as a secondary, doesn't allow you to change anything.

I bank with FNB exclusively thanks, but I have never needed to or just haven't done those things through the App.

I'll specially try it now.

But upon device registration it's never requested my PIN.

3. Open wireless is still encrypted? Ok. You really don't know much.

No your connection through the App is encrypted even though your link isn't. You need to at least attempt to read properly if you want to be so argumentative.

I actually know plenty about all the subjects above, what's with the insane hostility? If you can't converse like an adult...just don't.
 
Last edited:
Nope, just tested.

Changed ATM limit without any PIN requested.

Would you like to try again Mr Using Mommy's Credit Card?
 
Top
Sign up to the MyBroadband newsletter
X