Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't know, but I agree it seems foolish.

I also loathe that US banks don't use standard TOTP (which they could implement for free) but instead only offer SMS or app-based Symantec tokens, which are either insecure or impossible to backup.



My bank uses TOTP with pin.


Like, Google authenticator/generic TOTP?


Yes. Many credit unions use that platform as well.

Bigger banks meet the minimum standard for regular users and often hard tokens for bigger customers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: