Skip to content

Comment on Monzo urges 480k customers to change their pin numbers

Comments

As someone who is fully drunk on Monzo kool-aid, well done to them on (a) identifying the problem and (b) immediately telling customers what to do.

Imagine how long this would have been an issue if it had happened at Barclays or TSB.

To use this news to belittle their competition about a hypothetical event seems like a dangerous form of kool-aid fanboyism.

I think we can safely applaud Monzo for their transparency in stark contrast to the opaque nature of "traditional" banks.

I find it bizarre how people aren't giving Monzo more of a hard time over this. This is a security blunder of the highest order. Saying sorry in a cutesy email after the fact doesn't in any way make up for it.

Probably because it's not a "security blunder of the highest order".

Equifax was a "security blunder of the highest order". This is an it-happened-to-Facebook-and-Google "shit, some sensitive info ended up in internal logs" blunder where there's no reason to suspect the PINs actually leaked out of the company. And even if they did, a PIN on its own is not sensitive information - unlike a password, it's just a 4 digit number, there's only 10000 of them. And unlike SSNs, they can be changed. I can tell you my PIN is 1077 and what on earth are you going to do with that information?

This is a security blunder of the highest order.

No information was leaked... it's really kind of a non-issue. Monzo's approach is radical transparency. Any other bank probably would have never said anything.

Monzo's approach is radical transparency.

How can you be sure of that?

Barclays have surprised me with how good their tech seems to be

Really? They can't join a Barclaycard with a checking account because the former was opened through the internet and not from the store (Their words.) Plus they don't allow installing the Barclay's mobile app if you are running Lineage OS and openGapps despite passing safetyNet. Last but not least the web log in process for Barclaycard is security theatre. Split into 2+ steps but all knowledge based, ie still only 1 factor but annoying to use.

Lineage OS and openGapps despite passing safetyNet

I don’t know what any of these words mean, and I’m relatively technical

The sign-in I use requires a password (something you know) and a OTP generated by an irretrievable key, eg, something I have.

I believe LineageOS used to be called Cyanogenmod, and it's a fully free/open source implementation of Android. openGapps is Google Apps (like Maps) that you can install without having the Play Store.

Using LineageOS lets you do many more awesome things with your device, but financial apps (and even some apps like bus ticket apps) often don't work on this setup because it's viewed as insecure.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.