Ask HN: No major Australian bank even offers an option of 2FA for web, why?
Hard to imagine how this gets past any security audit.
Does anyone know why this is?
Hard to imagine how this gets past any security audit.
Does anyone know why this is?
Historically, there was a period of 10-15 years when these banks had websites, but you couldn't make arbitrary transfers through them. You could read your statements, and you could pay utility bills where the bank trusted the biller. Logins and passwords were appropriate then. The SMS authentication was only introduced later, when the websites could do things that required it. No doubt it made sense to save the SMSes for when they were needed, which was rare before people got used to paying by internet transfer.
By most people's standard the web has only existed since the early 90s' - Mosaic came out in 1993.
I was using online banking for transfers with CommBank and Westpac around the year 2000, IIRC, and I've never been in a situation where I could view but not make transfers using an Australian bank.
I used to work in infosec for governments and banks. Typically, the only way to have these kind of things implemented is by having regulation that enforces it. Banks don’t want to have to foot the bill for 2FA, and they can (as another poster pointed out) claim the user was careless with their password to not have to cover phishing attacks. Most of the time, banks will claim that their user base is in remote locations and SMS-based 2FA is unreliable (believable in Oz), or that they don’t want to “inconvenience their customers”.
The other issue is with choosing a tech. What if the bank picks wrong? What if it has an enormous cost?
A bank in the UK decided to use smartcard/credit card based OTP, and it resulted in the torture and death of one or two foreign students. It’s quite simply safer to wait until you’re regulated to use a specific tech, just so that you can’t be blamed if it backfires.
What exactly are you referring to when you say “website”?
CommBanks 2FA can be disabled tho.
ING still uses a client code, which is written on your card plus a 4+ digit pin code on both Web and app to login.
It will take one decent breech for them to wake up..
Are you sure that was a bank, and not some shady business?
Or do you mean a night deposit box for businesses?
This very much depends on the type of customer.
Consumers pretty much can have their banking password tattooed to their forehead and suffer no repercussions.
If you're an online merchant, it will nearly always be your fault.
More likely is just that they don't care or understand the value of it, and most consumers don't care or understand the value of it.