Why the FNB app needs your location data for payments

FNB is definitely downgrading security.

Two factor authentication via email is now deprecated as of this month, and needs to be done via SMS.
I'm unhappy about that.

Email I can control. I own the mail servers, and have complete faith in my security.
SMS is inherently insecure.
You can't control email.
Email is easy to intercept.
Email is not secure - unless you use pgp
Email is not real time
Trust me on this, ... I was an email sysadmin
2FA should be done via an app. Email and SMS are too easy to compromise.
Current versions of FNB App does the 2FA
The aim is to move from email and SMS to FNB App 2FA.
 
Last edited:
Ive been with FNB since the Bob T card with Barclays days in early 80s
Always been very happy with them, never hassles, even have a great bond under prime and I didnt even ask for it

But the time is coming to move to Capitec soon, the benefits with FNB on my poor salary just isn't making sense anymore, was enjoying Level 5 eBucks now I make 40 bux a month on level 3, doesn't even cover my Gold cards monthly bills.

Anyways, Im drinking and posting this on the wrong thread, sorry
 
That seems like a tedious solution for something that can be solved with scanning a QR code of the recipient? Who here has ever used that feature? Seems like some super niche bollocks...I can't imagine a situation where I need a list of GPS-local people to easily pay.
Geo Pay actually works very well and not tedious at all - allows you to receive OR pay another FNB App user.
I use it to pay friends or receive money when we pool a payment.
QR Codes work well for merchants.

FNB App also supports:
  • Tap to Pay (using NFC)
  • Scan to Pay (QR Code)
  • Pay to Cell Number (looks up FNB Acct)
  • Send Money to eWallet
  • Global Payments
  • Scheduled Payments
And normal beneficiary payments

New features added regularly.
 
How does using location data = a lack of security understanding?
FNB have different security models built by different vendors. There isn't any unified way of connecting their disparate systems. So in their app, because they can't rely on the security of other components of their ecosystem they have to rely on GPS to confirm that the likely hood of you being you is high. Should your location change, they will assume your account is compromised.

For example the 2FA you use in the browser to perform actions isn't needed by their API. The 2FA token is checked ONLY in the browser. The result is that if you are able to interact with their API via a script, you can totally bypass their 2FA checks.

Using GPS on device gets around this. But it probably means that their API is taking in a longitude/latitude which you can add via REST parameters. The security is POO.
 
I believe this is part of AML (Anti Money Laundering). Think cross border and as such cross jurisdictions.
 
So you no longer approve certain transactions via the app?
You don't need location services to be on when you approve web transaction via the app which makes me wonder why they're insisting on it for mobile phone transactions.

It was Bwana, wasn’t it?
No :p I did start a thread on it but that's it.
 
You can't control email.
Email is easy to intercept.
Email is not secure - unless you use pgp
Email is not real time
Trust me on this, ... I was an email sysadmin

Current versions of FNB App does the 2FA
The aim is to move from email and SMS to FNB App 2FA.
Is there a link to a successful breach of a client's banking by hijacking DNS, changing MX records or plaint-text email interception by sitting between the sending and receiving SMTP Server to get the OTP? Also considering a large portion of the population doesn't run FreeBSD under their desk for email anymore, they're using Gmail, Office365 etc.

Because there are a ton of examples of banking fraud done by SMS 2FA breaches due to to sim card cloning and other means.

And having the bank's app do the 2FA is fine, but in some cases it doesn't work. I've had at least 2 of the major banks apps just never get back to me with an OTP or Transaction Confirmation. I don't mind the use of the phone app, but there should be a fallback. And email makes a great fallback.
 
Is there a link to a successful breach of a client's banking by hijacking DNS, changing MX records or plaint-text email interception by sitting between the sending and receiving SMTP Server to get the OTP? Also considering a large portion of the population doesn't run FreeBSD under their desk for email anymore, they're using Gmail, Office365 etc.

Because there are a ton of examples of banking fraud done by SMS 2FA breaches due to to sim card cloning and other means.

And having the bank's app do the 2FA is fine, but in some cases it doesn't work. I've had at least 2 of the major banks apps just never get back to me with an OTP or Transaction Confirmation. I don't mind the use of the phone app, but there should be a fallback. And email makes a great fallback.
FNB's 2FA is only in the client, not on their API.
 
That seems like a tedious solution for something that can be solved with scanning a QR code of the recipient? Who here has ever used that feature? Seems like some super niche bollocks...I can't imagine a situation where I need a list of GPS-local people to easily pay.
I think they have the QR code solution for SMEs.

I've used the geopay a few times - it's actually pretty nifty.
The receiver and sender both have to be online on the app simultaneously, and obviously near each other geographically.
 
Pass here too. I uninstalled the FNB App a few days ago.

I open up my web browser to use online banking now.
If I uninstall the app, FNB starts charging me 50c for each transaction notification, so I'm pretty much forced to have it.

I'm happy to grant the app access to my location, except as a rule location services are disabled on all my devices. Doing this actually IMPROVES security FNB, as it helps stop phishing adware from using your location to make their fraudulent pages more convincing.

At any rate, I never use the app to perform transactions, always use my PC, so this issue doesn't affect me.
 
that FNB does not share any of the location data with third parties.

Yeah, right. Share vs sell? FNB is part of the Social Dilemma.
They don't want you to use cash, when you shop, because when you swipe, they know your location. Now, they know your location when you're doing online payments too. They do seem to want to thoroughly know ones habits.
 
FNB ... have to rely on GPS to confirm that the likely hood of you being you is high. Should your location change, they will assume your account is compromised.
Assumed compromised, and therefore blocked?
Great feature for going on a business trip or a holiday on the other side of the country, then?
 
Last edited:
We give up additional aspects of our privacy daily in the name of safety. Yet safety keeps declining. Only the honest are left wasting their days with red tape and bureaucracy. Syndicates already have or will just switch to web browsers or any other means to circumvent measures.
 
You can't control email.
Email is easy to intercept.
Email is not secure - unless you use pgp
Email is not real time
Trust me on this, ... I was an email sysadmin
@system32

Why can't you control email?

Email is not easy to intercept.
How are you going to intercept my email?

I'm interested.

I control the mx records for my domain. Sender looks up mx records to know who to send to.
connects to the server listed directly. Depending on which of my mail servers it connects to it either stores, or forwards to the correct server.

Are you saying you have control of one of the mail servers involved? At least on the FNB side, I can see some issues which might tilt that your way (detailed below), as mail passes through what appears to be at least two 3rd parties. (Bidvest and enterprisedd)


Email is not secure - unless you use pgp
It's certainly far more secure than sms.
FNB's servers negotiate TLS over DKIM for communications between their server and mine, so its secured between A->B - i.e. you can't sniff the traffic usefully in the event you were in between their network and mine. Their Signatures verify for their messages.

They also publish SPF so I can verify the sender. Although they have in the past screwed that up. As I've let them know once or twice when thats failed.

Received-Spf: pass (([my server]: SPF record at fnbstatements.co.za designates 41.170.90.242 as permitted sender)

What I don't like is that they use a 3rd party for emails.

EnterpriseDD
"Join the EDD Generation. Document Delivery Transformed. With its remarkably accurate, efficient and secure document delivery system, EDD will radically transform your..."

Received: from unknown (HELO relay236.enterprisedd.com) (41.170.90.242) by ([my server] with SMTP; 8 Nov 2020 18:55:52 +0000

Received: from EDD-ZACheque-01.jhb.bidvestdata.co.za (Not Verified[10.0.0.211]) by relay236.enterprisedd.com id <B5fa83f1e0001>; Sun, 08 Nov 2020 20:55:26 +0200

Received-Spf: pass ([my server]: SPF record at fnbstatements.co.za designates 41.170.90.242 as permitted sender)

<[email protected]>

That email server also handles other mails for other clients in addition to FNB. - eg enterprisedd.com 's mail.

dig mx enterprisedd.com

; <<>> DiG 9.11.5-P4-5.1+deb10u2-Debian <<>> mx enterprisedd.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 51527
;; flags: qr rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;enterprisedd.com. IN MX


;; ANSWER SECTION:
enterprisedd.com. 14400 IN MX 15 relay236.enterprisedd.com.
enterprisedd.com. 14400 IN MX 15 relay246.enterprisedd.com.
enterprisedd.com. 14400 IN MX 5 za-smtp-inbound-1.mimecast.co.za.
enterprisedd.com. 14400 IN MX 5 za-smtp-inbound-2.mimecast.co.za.


To be honest I'm not quite sure why FNB doesn't handle their own mails. Would be safer.
I should ask them.


Email is not real time
So what?

Neither is sms, and nor is their app push.

Trust me on this, ... I was an email sysadmin.
Good for you. I also maintain my own email servers, and I disagree with you.



Is there a link to a successful breach of a client's banking by hijacking DNS, changing MX records or plaint-text email interception by sitting between the sending and receiving SMTP Server to get the OTP? Also considering a large portion of the population doesn't run FreeBSD under their desk for email anymore, they're using Gmail, Office365 etc.

Because there are a ton of examples of banking fraud done by SMS 2FA breaches due to to sim card cloning and other means.

And having the bank's app do the 2FA is fine, but in some cases it doesn't work. I've had at least 2 of the major banks apps just never get back to me with an OTP or Transaction Confirmation. I don't mind the use of the phone app, but there should be a fallback. And email makes a great fallback.

This ^^^^^^^
 
Top
Sign up to the MyBroadband newsletter
X