That sounds terrible. I mean, I assume they don't assume liability for bad decisions?
If "the PC" or "the IP address" was not contractually agreed to be an authentication factor (that you thus should protect from unauthorized use), it's a terrible idea to use them for authentication, while also (presumably) putting all liability on the customer.
In France, and I believe it is the case in many countries, in case the customer wants to roll back a transaction, the bank has to give the money back, unless it can prove that the transaction was legitimate.
So basically, they can't put liability on the customer unless 2FA is used. The second factor is usually the credit card PIN.
Banks have to maintain a balance between convenience and risk of fraud.
unless it can prove that the transaction was legitimate.
And what is the standard of evidence for that?
So basically, they can't put liability on the customer unless 2FA is used. The second factor is usually the credit card PIN.
That doesn't sound like a second factor? Or are you talking about POS transactions?
Banks have to maintain a balance between convenience and risk of fraud.
Really, they don't. The bank should never decide to take on risks for me. There is nothing wrong with offering a feature where the customer can select to allow certain transactions without 2FA. There is everything wrong with forcing that feature on customers.
Why would that be a terrible idea? If someone has unauthorized access to my PC and knows my password from the account, he can log in and pay my bills and only the usual amounts, as paying too much would trigger 2FA.
Comments
That sounds terrible. I mean, I assume they don't assume liability for bad decisions?
If "the PC" or "the IP address" was not contractually agreed to be an authentication factor (that you thus should protect from unauthorized use), it's a terrible idea to use them for authentication, while also (presumably) putting all liability on the customer.
In France, and I believe it is the case in many countries, in case the customer wants to roll back a transaction, the bank has to give the money back, unless it can prove that the transaction was legitimate.
So basically, they can't put liability on the customer unless 2FA is used. The second factor is usually the credit card PIN.
Banks have to maintain a balance between convenience and risk of fraud.
And what is the standard of evidence for that?
That doesn't sound like a second factor? Or are you talking about POS transactions?
Really, they don't. The bank should never decide to take on risks for me. There is nothing wrong with offering a feature where the customer can select to allow certain transactions without 2FA. There is everything wrong with forcing that feature on customers.
Why would that be a terrible idea? If someone has unauthorized access to my PC and knows my password from the account, he can log in and pay my bills and only the usual amounts, as paying too much would trigger 2FA.
Because there is a risk associated with it that you didn't agree to.