logoalt Hacker News

zkmontoday at 1:40 PM2 repliesview on HN

> My banking app requires, on average, three FaceID logins before the 3D Secure confirmation view appears.

That's a different, equally big problem. Security mafia at every company will continue to rule everything and everyone. They do not have goals or constraints that are tied to productivity and user experience.

We are heading to a situation where the security teams are causing much more damage compared to the possible attack vectors. While this damage is real and certain, the damage due to attack vectors is only hypothetical.

Ofcourse, we do need security. But currently no one including CEO can dare to define how much security is needed. On top of that, regulators do their own share of damage, piling up regulations. No one takes any risk. They will ask you to tie yourself down until you can't move. Your mobility is not their problem.


Replies

cmiller1today at 1:42 PM

Perhaps its a slight overcorrection but it's better than the past where an online shop I gave my credit card info to would reply to a forgotten password request with an e-mail with my password in it in plaintext. Security used to be awful and people suffered because of it.

show 1 reply
inigyoutoday at 2:32 PM

One thing you can do to fight back is show up at their branches with complaints. You can engineer this intentionally. Have a bank that doesn't support Graphene? Show up with your Graphene phone and be like "it says my phone isn't allowed. Fix this or I'm closing my account" and there's a 50% chance they will turn off phone hardware attestation for your account or give you a physical 2FA token and if they don't it will show up in their metrics.