EasyEquities CEO thinks that 2 factor authentication is not worth the effort

kingkong

New Member
Joined
Aug 10, 2017
Messages
1
Reaction score
0
Various Twitter users have complained about getting emails to reset their password and have been asking for 2 factor authentication. His response as the CEO was disappointing to say the least. Refer to the screenshots. First it was securities lending launch and now this I’m now inclined to moving to a different platform. What are some decent alternatives?
7CE15677-868A-476B-A3D9-951121D785CC.jpeg3463C4F4-88BF-4046-AB0C-A1CFD35962BE.jpeg517D978F-C65B-46EB-B42D-099CF2A0A8D2.jpeg
 
It's not really he is correct.

Maybe just if you wish to change your banking details, but not for normal transactions.
 
Sell every position, trigger all the capital gains, buy into an Africa Property ETF because **** you....or the bitcoin fund.
 
It's not really he is correct.

Maybe just if you wish to change your banking details, but not for normal transactions.

If somebody gets into your account they have access to details such as tax numbers, income bands, address details and other personally identifiable information. They also have access to your account history.

It's enough for a smart attacker to cause serious harm especially if you consider their target user base. If I was a betting man I'd say the password these people use for their EE accounts is the same password they use on many other platforms and services. That and a little bit of social engineering and they are you.

And if your account does get compromised Charles can shrug it off and say "not my problem your password wasn't strong enough/got leaked".

It's just a pretty messed up stance to have to say "nothing can be done that we can't undo" when referring to people's life savings. They're dealing with my money and the guy in charge is coming across as an apathetic penny pincher.
 
I have to agree, it is a freaking pain in the butt. Specially when there are delays.


But shouldn't it be the users choice if the want the extra level of security or not?
 
Sell every position, trigger all the capital gains, buy into an Africa Property ETF because **** you....or the bitcoin fund.
Exactly this + access to your personal information. I get his point that they wont be able to take the money out, but its like letting strangers walk through your house but they cant take anything, why would i want that to be an option in the first place.
 
shouldn't it be the users choice
No.

Because 90% of them aren't qualified to handle a spoon, let alone protect themselves from nefarious actors.

Then they whine and biatch when the inevitable happens and suddenly it's all "why aren't you doing more to protect us!?". Fark that noise.
 
No.

Because 90% of them aren't qualified to handle a spoon, let alone protecting themselves from nefarious actors.

Then they whine and biatch when the inevitable happens and suddenly it's all "why aren't you doing more to protect us!?". Fark that noise.
And 8% of those that think they are qualified have no idea what they are doing.
 
And 8% of those that think they are qualified have no idea what they are doing.
How, exactly, is 2FA complicated?

How is the trade-off of a few seconds to confirm access such a major burden vs the impact of having your account breached?

Anyone arguing against 2FA, especially around financial tools, is a raving loon.
 
Sell every position, trigger all the capital gains, buy into an Africa Property ETF because **** you....or the bitcoin fund.
What motivation would a "hacker" have to do that?

Your account is only at risk if they can get money out. Nobody is just going to troll you like that.
 
2FA should be a choice, and a available option. However, 2FA shouldn't be limited to one method only. Accessibility to login should always be available, alternative 2FA methods, and when not possible, recovery keys are a requirement.
 
Well Charles, give me your username + password real quick and let's put your "what damage can really be done?" to the test.
Well, if you got those 2 things then I just need your cellphone and then I can hack yours ? Where is thing going?
 
Sell every position, trigger all the capital gains, buy into an Africa Property ETF because **** you....or the bitcoin fund.

Exactly this + access to your personal information. I get his point that they wont be able to take the money out, but its like letting strangers walk through your house but they cant take anything, why would i want that to be an option in the first place.

Also to add: they could transfer your funds from your TFSA to your taxable brokerage thus messing up your TFSA lifetime allowance going forward (imagine if you've been maxing out since 2015! Oops, no longer tax free. And as much as they claim they could undo it, what if it happens en masse? SARS doesn't care that EE told you they'd sort it out if your It3s shows a withdrawal or an over the limit redeposit). Last I checked interaccount transfers (same user) don't need to be banked first so they wouldn't even need to change banking details to do this.

What motivation would a "hacker" have to do that?

Your account is only at risk if they can get money out. Nobody is just going to troll you like that.

You're absolutely right. Above that though, you'd be surprised what kind of things hackers get up just to prove a point about lax security on widely used platforms (and not necessarily with the objective to scam people, although the identity theft argument is pretty solid since EE literally has all the information needed). EE have already shaken up the industry and the biggest detractors have always wondered about ownership/security. A hack with material consequences for the clients would be the nail in the coffin, even if no funds were withdrawn. It's a relatively small probability event but with catastrophic consequences. The risk should be mitigated (2FA at least as an opt-in) and left at the discretion of users. But again, you're right. Financial incentive is lacking.
 
Top
Sign up to the MyBroadband newsletter
X