I never understood why SMS are preferred to OTPs generated offline using credit cards and a card reader, which were fairly popular.
Actually, EU regulations state SMS should be phased out, but banks largely ignore that. SIM cloning is fairly easy...
I never understood why SMS are preferred to OTPs generated offline using credit cards and a card reader, which were fairly popular.
Actually, EU regulations state SMS should be phased out, but banks largely ignore that. SIM cloning is fairly easy...
They clearly just don't see it as a realistic threat, on top of all the other security measures in place (for me it's a password, and also a memorable word that isn't typed on the keyboard, then SMS OTP). It's not a great defence of SMS but perfect is the enemy of good, and SMS is just about ok.
Most hacking stories I hear about seem to happen through social engineering, where people go to great lengths to authenticate themselves for someone over the phone.
One thing that is starting to take hold is banking apps, which once installed can be used to authenticate payment. Again not perfect but better than SMS, and users are increasingly likely to have them installed because of ease of use.
And I think the best answer is government issued digital identity and being able to use that to recover your access to the online services (of course up to you if you wish to make this connection).
And it included that annoying scanning a barcode on screen AND confirming € amount.
And the readers had 2 options. Sign and confirm (?). Why they couldn't incorporate this into the barcode?
It was all done because it definitely lowered mistakes and was more secure than card number and CVV to pay online.
Most online services aren't so worried about a small number of users being SIM-swapped. They are worried about large numbers of users that reused their password across thousands of sites 5 of which had their database dumped.
SMS 2FA isn't about providing individual users a high level of security. It is about providing a baseline level of security for all users.
Some banks, like ING, already refuse to send OTPs by SMS and effectively require using an app. SMS is also bad from a user perspective as it turns your phone into a single point of failure. Also, if you are roaming abroad, SMS delivery is usually slow and unreliable. Imagine going to another country and being unable to validate a credit card transaction.