Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The real problem is not Telegram or WhatsApp, it's the banks that insist on using SMS as a secure authentication channel for authorizing transactions.


The real problem is that there is no alternative to SMS for GSM messaging.

It is one of those protocols that won't die nor get replaced, like email.


WhatsApp and TOTP apps can already replace SMS for verification. The only problem is 2FA providers are still choosing to use SMS.


Not everyone uses WhatsApp or other 3rd party app while SMS is enabled by default on all user phones, even "dumb" ones (still used by many people around the world). I use Signal, many friends use WhatsApp, others Telegram etc. Do you expect a bank to support them all or somehow enforce installation of their app of choice?


They should enforce one app. Since WhatsApp has the correct design and has a billion or more users, I suggest that one.


So when another new, shiny app made by some walled garden company shows app, bank should enforce that instead? My bank is using mobile signature(1) and I think it's way superior to any app, because the encryption part is done inside SIM which has quite good security record. There's simply no way I would trust Facebook (via WhatsApp) with my financial data.

1. https://en.wikipedia.org/wiki/Mobile_signature


It is my understanding that WhatsApp requires Internet access. There is a large portion of mobile phone users for whom that is too expensive.


TOTP can be used with no cell service at all.


yeah, but while email is broken, it isn't THIS broken.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: