In my opinion, Canadian banks are way overdue to switch to 2FA.
In my opinion, Canadian banks are way overdue to switch to 2FA.
Ironically i signed up with one of the local credit unions in Toronto to take advantage of a high interest savings account for a future tax debt of which I am sitting on the cash for, and found they supported SMS 2FA, and texts when anyone (even me) logged into the account. I wish TD supported this, but then again, as long as their money is backed by the government i don't really care all that much.
1) Many people have had their Gmail account for a long time, starting before SMS-based 2FA was widely known as a security disaster (this is in fact still not widely-known)
2) Google still actively encourages users to add a recovery phone number
3) Users could have added a phone number years ago then forgotten (this was the case with myself)
4) Users often have many websites using their Gmail account for password-reset workflows (this is definitely the case with myself)
All of these combine to make Gmail the ideal hacker entrypoint. See this hack: https://www.reddit.com/r/ethtrader/comments/8klw4f/someone_j...
i would consider the average person to be pretty bad at handling otp backups. how else would you do recovery?
All these things are beyond what the average person wants to worry about, as you say, but HN readers will find it simple. Personally I'm hoping U2F (Yubikeys) are the future, since your average person certainly understands the concept of a key.
I would much prefer to see a second factor like TOTP, U2F, etc as the problems with SMS based second factor are well documented, but I'll take what I can get.
For anyone who wants to set it up you can find it by...
1) Logging into Easy Web
2) Click your name in the top right
3) "Password and security"
I'm not sure I understand why you believe SMS codes as a second factor compromise the security of the password authentication.
Or, sometimes, you don't even need login access; one notable attack has been to the credit-reporting systems, where to unfreeze your credit report (and thereby apply for new credit lines) the reporting agencies require your name, birthdate, SSN, and SMS verification. But if the attacker already has name, birthdate, and SSN... well, that's all they need to get the cellular ISP to redirect the SMS verification, as well.
So I really don't see how this makes security worse.
That’s why proper banks should use 2FA mechanisms that will ask the user to confirm the transaction on a second device (e.g. photoTAN or similar).
Of course, this won’t help against attacks if both devices are compromised or you are using the second factor device to access the system, but it’s still better than TOTP.
And, of course, TOTP is still way better than SMS 2FA or no 2FA.
Unless of course your bank does some proper, additional verification for large volume transfers.
Got a name? And do you recommend them? Long-time RBC customer, which means they treat me terribly. Mortgage is coming up for renewal soon enough.
Accounts can also be used to log in to the CRA website.
"we're not responsible if we get hacked and lose all of your CRA related data to some random hacker... that's your fault"
SMS is not secure for this purpose since there are many attacks which allow you to sniff SMS messages.
I've looked around an account I'm a representative on, and other than passport numbers, not much sensitive personal data.
CIC is still a lot of pen and paper these days, but perhaps it depends on one's immigration pathway...
The bank's information can be used to log into CRA however...
It boggles my mind that institutions with such financial power, fail to employ these practices.
It's clearly not a question of cost..