• Routhinator@startrek.website
    link
    fedilink
    English
    arrow-up
    55
    arrow-down
    1
    ·
    13 hours ago

    The problem for me is that most Canadian Banks give you the choice of SMS or their shitty adware filled bank app that relies on Google Play Services and wont implement TOTP so I can use a true MFA app. And Im done with being forced to accept user policies I don’t agree with to do shit, and most of all done with Google Play Services on my device 😑

    • oldfart@lemm.ee
      link
      fedilink
      English
      arrow-up
      9
      ·
      7 hours ago

      My bank prides itself being the first in the country to support yubikeys for 2fa. I was so happy until i learned it’s just for logging in, transactions are still confirmed by SMS or their app. And security experts all say it’s better this way, using a regular 2fa solution would be insecure because you wouldn’t know what you’re confirming.

      There really is no hope.

        • oldfart@lemm.ee
          link
          fedilink
          English
          arrow-up
          4
          ·
          2 hours ago

          I’m not defending that madness, but that device doesn’t show who is the recipient. The argument was that this is protection against phishing sites pretending to be a bank, proxying your connection but sending it to a different recipient.

          Makes one wonder how much the user has to fuck up to end in such a scenario, and of it’s really worth transmitting everyone’s financial data in almost plain text over the air for this

    • sugar_in_your_tea@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      9
      ·
      10 hours ago

      This is the main reason I switched to Fidelity here in the US. It’s a brokerage, but it does basic bank things, like checks, debit card, etc, and they support SymantecVIP, which works w/o Google Play Services. TOTP support really isn’t that hard, I don’t understand why banks are so slow in adopting it…

      • ipkpjersi@lemmy.ml
        link
        fedilink
        English
        arrow-up
        6
        ·
        8 hours ago

        The issue is, banks are only going to do what they’re required to do by law. The government is run by dinosaurs who don’t know what computers are, let alone what TOTP is.

        • sugar_in_your_tea@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          8
          ·
          8 hours ago

          No, they’re only going to do what they’re required to do by their insurance. The law is an option, but if insurance costs go way up if they don’t have proper MFA, they’ll get MFA.

        • sugar_in_your_tea@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          3
          ·
          10 hours ago

          They’re fantastic. :)

          The only negative stories I’ve heard are from people who really push the boundaries, like people day trading and whatnot. If you’re a regular user looking for a bank alternative, you should be good.

          Just know their branches don’t really have any banking services, so you can’t go there to withdraw or deposit cash, get a cashier’s check, etc. I keep an account w/ a local institution and transfer money as needed for banking services.

      • Routhinator@startrek.website
        link
        fedilink
        English
        arrow-up
        1
        ·
        10 hours ago

        Now you’ve got me wondering about this for Canada. Would be a pita to move mortgage and investments, but there must be a better way than the big banks.

    • HellsBelle@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      12
      ·
      13 hours ago

      Adding to this that my Canadian bank just updated their app and it doesn’t work with my older phone. So my only option is to use online services with SMS/call verification.

      It’s such a joy to know that my bank, who made $40.670 billion last year, takes care of every customer equally.

      • carpelbridgesyndrome@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        4
        ·
        edit-2
        7 hours ago

        They support USB hardware tokens… but only for the website. Everything else is SMS which kinda defeats the point.

        Annoyingly, other than Vanguard, they are the only financial institution to support USB FIDO tokens