• Pycorax@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    8
    ·
    edit-2
    15 hours ago

    I’m not sure how it works the way where you live but where I live, the way the banking apps are implemented completely violate MFA. They rely on SMS verification which is absurd since if you’re phone is already compromised, no doubt your SMSes are too. There’s no true multi-device authentication in place and this has led to a huge number of victims being scammed after their devices get compromised by a phishing attack.

    The desktop and phone are both insecure, proper security should not have all your eggs in one basket.

    • DreamlandLividity@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      10 hours ago

      Well, yes. But then again, I would trust my GrapheneOS phone not getting compromised over 3 linux devices. MFA is not some ultimate solutions and it is a pain to use.

      • Pycorax@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 hour ago

        I mean sure, but that’s not the case for the majority of the user base of these banking apps. Is it the most secure? No but it’s way better than it is right now.

        • DreamlandLividity@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          24 minutes ago

          So what is the case for most users? Are normal android phones getting compromised (in a way true 2FA would help) often enough it is an issue? I honestly haven’t seen any statistic regarding this and anecdotally I don’t know anyone whose internet banking was compromised. Whether on phone or desktop.