Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In Sweden we have BankID - a two-factor, two-way authentication using public/private encrypted keys that's bound to a smartphone as a signature.

The process is user-friendly while keeping security high:

- The place where you want to login has to trigger the authentication from their server on every login - and have to be certified for BankID.

- You then have to open the app, enter your fingerprint or 6-pin code before you can enter.

It's available for all state-run services including all banks and post offices.



Unfortunately the BankID has been scammed a lot, where fraudsters have simple asked people on the phone to sign BankID stuff for them. It is far from perfect and in fact the scam here would be possible to do with BankID as well.

https://www.expressen.se/dinapengar/sparande/bedragerier-med...


Sure, I'd assume that social engineering will always work as long as a person has no way to validate who's on the other end.


That's the Mobile BankID, and it gets scammed a lot. The smart-card based BankID is the only acceptable choice IMO


How is that different, since social engineering works there too?


Not as easily. As I understand it, with Mobile BankID, the attacker goes to the bank web site and then asks the victim to authenticate with their BankID app.

With the real BankID, the computer accessing the bank web site needs access to the smart card. Exploitation is still possible of course, but the bar seems higher.


Understood, you can only login at the actual computer, not from anywhere. Should be mandatory for the elderly that are the most targeted victims.


>that's bound to a smartphone as a signature.

Big yikes, that's a no for me.


This is the same system I'm talking about. You can use your smartphone and a PIN, or you can get a hardware dongle. Same authentication API from the banks POV.


OP (a big bank in Finland) is not offering a hardware dongle and I'm considering changing banks because of it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: