Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Are you European? I only ask because my friend in London is the only person I've ever heard of using such a device.

Unfortunately, such a thing seems all but unheard of here in Canada.

Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. I have noticed that when I login from a new computer (for example, when I visit my parents), the site uses one of my challenge questions to ensure it's really me. I guess that's something, although I really don't know the exact circumstances that trigger the challenge.



The weird thing is that Blizzard will cheerfully sell you a $7 hardware token to protect your imaginary WoW gold and equipment, but I don't know of any US banks that offer one to protect your actual money.


Paypal will.

Don't quote me on this, but I think banks are starting to lean on "possession of a trusted mobile device" as their two-factor authentication. The basic theory is that I give them a number I can receive SMSes at, and then any time they want to verify that the person operating my web browser is really me, they say "We just sent you a one-time password via SMS. Enter it, resend it, or talk to customer service."

This has significant advantages over dongles from the perspective of the bank: they don't have to get into dongle distribution, and people are probably better at keeping cell phones available than they are at keeping dongles available.


My bank in Australia does this (for any transaction to an account I've never sent money to before). Works prettty well.

I click a button, they SMS a 6 digit code, I enter it, money transferred (or bill paid).


Which bank?


That one. :)

http://www.commbank.com.au for those who don't get the joke.


They will also issue a token for those of us living outside the country.


AFAIK, CBA and Community CPS both do it.


As does NAB.


Bank of America and Paypal will.

Most banks use the "you only get to try three times before your account is locked" method of security. It's pretty hard to bruteforce a password with only three attempts before you have to call customer service. At that point, you might as well print out a fake driver's license, walk into a branch, and ask to close "your" account.


E*TRADE offers this for free if you have a high enough balance ($5K?) between accounts. Unfortunately, our good friends at Mint.com have no way to deal with two-factor auth, so in my informal polls, all my friends who were using two factor switched back to password only so they could use Mint's reporting features.


SOP for Citibusiness accounts.


The chips are most likely for EMV[1], which essentially puts some intelligence on the card in the form of an IC chip, and allows the card to make approve/deny decisions based on rules of the issuing bank. With EMV cards, the transaction is more like a negotiation, and the card may reject at any point.

Of course, like anything, there will be vulnerabilities, and in the interests of usability, some issuing banks will relax restrictions.

Because of the crypto involved in the back and forth communication between hardware and card, EMV transactions piss off a lot of customers, it can easily take 2-3 times more time to process a transaction when compared to a mag-swipe.

Though it does reduce the chance of your card getting skimmed. (Skimming is where your details are captured during the swipe. Yes, a swipe through the appropriate device reveals all the information required to completely duplicate the card.)

[1] http://en.wikipedia.org/wiki/EMV


Actually, in Norway there are some banks that use the credit card chip for two factor authentication (the same which is used for EMV). You put the card into a small "reader" with a display, and out pops a number that you use when logging into the online bank. Most banks however use a dedicated device with a time-based one time password.

I'm not sure why, but I've seldom seen EMV transactions take longer than a regular swipe, but this might be because both 1 second * 3 is still not that big of a deal. (Or for all I know, it might be because they are only validating the credit card number..)

The interesting thing is that skimming is still possible, at least in Norway. It still happens that there is some kind of communication problem with the EMV system, and swiping the card is the fallback option. I guess this option will be turned off as soon as it works "all the time" and they can remove the magnetic stripe.


> there will be vulnerabilities

Correct, in fact there already are. Most of those will require at a minimum a hardware hack or access to transactions 'in progress' (modified terminals) and will usually only gain access to the data that is stored on the magnetic stripe, not to the other data stored on the chip (the chip contains a duplicate of the stripe data and some other data only available on the chip and not sent out over the wire used in challenge/response fashion).

The system is not 100% secure but is a bit better than just having a password and the fact that it requires access to the original card makes it a lot harder still (those cards can be stolen though, and combined with a bit of hardware and a 'yes' card (a card that always responds 'transaction authorized') you could fool online payment terminals).

But that's still a step removed from gaining complete control of a bank account using web based banking and a password.


> Our debit and credit cards are being replaced with cards with chips embedded

Do you want to know something scary about that. We've had Chip and PIN as the de-facto standard in the UK for some years now (although I do remember it coming in).

The really scary thing is; my parents remember it being widely used in Germany in the late 80's.

Has it really taken that long to get to Canada?


Chip and Pin in the late 80s in Germany?

It is true that paying in stores with my German ATM card and its PIN was nothing new when I got my first bank account in the mid-90s. However, that system used the magnetic stripe of the card (which is why skimming is still so attractive here); smart-card chips on bank cards were introduced a lot more recently.


I only have my parents recollections about this (we lived in Germany in the late 80's, but I was 0 & so can't recall ;)) - possibly it was swipe & pin, I'd have to ask.

But when the Chip 'n Pin system came in here in the UK my Dad's first comment was "oh, they were using that in Germany in '87/88"


In Canada, Debit has always been swipe and PIN, but Credit is only recently becoming chip and PIN.


> Are you European?

Yes, working from NL at the moment.

> Unfortunately, such a thing seems all but unheard of here in Canada.

That sucks!

> Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online.

Ok.

> I have noticed that when I login from a new computer (for example, when I visit my parents), the site uses one of my challenge questions to ensure it's really me.

So the bank likely either keeps a record of 'known' IP addresses for you or they keep a cookie on the computer that they use to identify a computer that you've used at least once.

How annoying. It's interesting how we berate POF for not following 'best practices' but even institutions such as banks could do a whole lot better to protect their and their customers best interests.

Are you liable for fraud committed with your account online?

Or would the bank indemnify you if your password were used to clean out your accounts?


>> Are you European?

>Yes, working from NL at the moment.

Same here.

With one bank I must use the hardware token solution (and I am able to use any device, not just the one issued to me). With another bank I must register my mobile telephone number with them and they send me a text with an authorisation token whenever I need one.

I much prefer the hardware solution even though it is a major inconvenience when travelling light.


>Are you liable for fraud committed with your account online?

Not with TD Canada Trust, to an extent:

"As set out in our account agreements, you are responsible for maintaining the care, control and confidentiality of your Access Card number, Connect ID, and passwords. TD Bank Financial Group is not responsible for unauthorized access to accounts online or losses that occur as a result of you voluntarily disclosing your Access Card number, Connect ID, or passwords, or the careless or improper handling, storing or disclosure by you of this information. In the event of loss, theft, misuse or compromise of your Access Card, Connect ID, and/or passwords, you must notify TD Bank Financial Group immediately."[1]

The "Known IP" is a bit more complicated. I was travelling through South America recently, and could always access it from my phone. However, accessing from a hostel or internet cafe required answering a security question.

http://www.td.com/privacyandsecurity/guarantee.jsp


Are you liable for fraud committed with your account online?

Or would the bank indemnify you if your password were used to clean out your accounts?

Honestly, I have no idea. I really should look into the fine print in the online TOS/Rules&Regs.


The system we use here has it's own vulnerabilities (after all, if your card is stolen and the pin is known then any token can be used to authorize transactions, and there are known ways to attack the card electronically) but it makes it at least a little bit harder.

On top of that we do have indemnification.

Combating electronic banking fraud is an ever lasting game of leap frog, it looks like the banks are at least one step too far behind. At least they have the extra challenge question, I hope you made them hard enough :)


Odd. It seems like almost every big bank in Asia has them by now. I would have thought their use is widespread world over.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: