They used to have an actual object generating numbers, but to save money they moved to SMS, claiming it was to follow an EU regulation (which I've read, and mandates the exact opposite).
Established Dutch banks grudgingly keep their 'readers': small pieces of cheap hardware which can generate OTP's by reading the chip on your debit card and verifying the PIN. It works, but the banks are trying really hard to move everybody to their apps, and they are increasingly making that route the one with less friction (e.g., by selecting the app option as default on every transaction and by making it look like the app is the only way in their communication with the customers without explicitly saying so).
A few of the newer online only banks are simply mandating their apps, making them exclusive to people who own (recent-ish) Android or IOS smartphones.
They aren't going back to SMS though. That's really a thing of the past now.
Not only that, but typically also their device ID features. So, for example, your banking app won't work on LineageOS with some free re-implementations of GApps.
"Open" GApps for custom Android builds are not open re-implementation. It was a middle ground between ROM communities and Google reached some decade ago, to disallow inclusion in the ROM and limit redistribution to forms and channels agreed upon.
I love my card reader (BE) and they can pry it from my cold dead hands.
Every bank app I've looked at here is full of annoying spyware and plugs for third party services. Even on the home screen.
Apparently they do not think anything is wrong with taking an app that is supposed to be your personal wallet, and putting ads in it. Watch you can't turn off, and which keot growing. I complained, but they never did anything. And yes, putting integration for third party services that you can't turn off and which appear right between your own accounts, those are ads, and someone is making money off that.
So I stopped using it. They can go f themselves. It's bad enough that they charge you to hold on to your own money... but worse, they don't even treat you as the customer anymore.
In Sweden it's the same. There are two types, the first one is the one you describe where you put the (chip) Visa / Mastercard / Maestro card. The other kind is just number pad + 7-segment LED. Even when using the (bank cooperation issued) smartphone ID app, you have to first sign some cryptography keys with your hardware fob.
That's interesting. I recently moved to Norway, and first had BankID on mobile, which used GSM level encryption to verify. They're deprecating that now for a regular BankID app. But even though it's supported, I don't think you can get the hardware fobs any more
What frustrates me most is that every bank develops their own shitty-in-their-own-way app for this purpose. There really needs to be an industry standard and then apps like Google Authenticator to exist for this purpose.
I have multiple bank accounts with different banks and upgrading my phone is an absolute nightmare because of apps like this.
It isn’t just banks. 10 years ago I just used TOTP when I wanted 2FA. But now many tech companies are hand-rolling their own MFA. Google Prompts. GitHub Mobile. Microsoft Authenticator. Adobe Account Access. Some of these still support TOTP, but force you to use their app (Google Prompts when a Google app is installed). Others simply removed TOTP to push their app (Adobe).
TOTP was great as I could generate codes on multiple devices and back up my setup codes. Now I’m forced to use my phone, a device that is easily lost or stolen, and restoring a new phone from a backup generally doesn’t transfer the keys for these types of apps (for “security” I guess) so nightmare is probably putting it nicely.
I’m surprised more people aren’t complaining about all of this proprietary/DIY security. Rolling your own is almost always a bad idea - we have open standards for a reason.
We have NFC enabled cards and phones. I guess one could get a challenge from the card's chip with an app if they insist, but the phone can already work as a contactless card over NFC, so one no longer needs the EMV chip.
What data? This is your bank, they already know exactly when what for what amount you're buying because you're doing it with their card. There's no other data they can reasonably get away with collecting.
Comments
My italian bank relies on SMS for 2nd factor.
They used to have an actual object generating numbers, but to save money they moved to SMS, claiming it was to follow an EU regulation (which I've read, and mandates the exact opposite).
Established Dutch banks grudgingly keep their 'readers': small pieces of cheap hardware which can generate OTP's by reading the chip on your debit card and verifying the PIN. It works, but the banks are trying really hard to move everybody to their apps, and they are increasingly making that route the one with less friction (e.g., by selecting the app option as default on every transaction and by making it look like the app is the only way in their communication with the customers without explicitly saying so).
A few of the newer online only banks are simply mandating their apps, making them exclusive to people who own (recent-ish) Android or IOS smartphones.
They aren't going back to SMS though. That's really a thing of the past now.
Not only that, but typically also their device ID features. So, for example, your banking app won't work on LineageOS with some free re-implementations of GApps.
https://wiki.lineageos.org/gapps
https://www.reddit.com/r/degoogle/comments/h06x5i/bank_app_w...
For me, mandating a mobile app is a deal breaker.
"Open" GApps for custom Android builds are not open re-implementation. It was a middle ground between ROM communities and Google reached some decade ago, to disallow inclusion in the ROM and limit redistribution to forms and channels agreed upon.
However, there is a free reimplementation of GApps, namely microG. Not what OP linked to, but it does exist.
I love my card reader (BE) and they can pry it from my cold dead hands.
Every bank app I've looked at here is full of annoying spyware and plugs for third party services. Even on the home screen.
Apparently they do not think anything is wrong with taking an app that is supposed to be your personal wallet, and putting ads in it. Watch you can't turn off, and which keot growing. I complained, but they never did anything. And yes, putting integration for third party services that you can't turn off and which appear right between your own accounts, those are ads, and someone is making money off that.
So I stopped using it. They can go f themselves. It's bad enough that they charge you to hold on to your own money... but worse, they don't even treat you as the customer anymore.
In Sweden it's the same. There are two types, the first one is the one you describe where you put the (chip) Visa / Mastercard / Maestro card. The other kind is just number pad + 7-segment LED. Even when using the (bank cooperation issued) smartphone ID app, you have to first sign some cryptography keys with your hardware fob.
That's interesting. I recently moved to Norway, and first had BankID on mobile, which used GSM level encryption to verify. They're deprecating that now for a regular BankID app. But even though it's supported, I don't think you can get the hardware fobs any more
What frustrates me most is that every bank develops their own shitty-in-their-own-way app for this purpose. There really needs to be an industry standard and then apps like Google Authenticator to exist for this purpose.
I have multiple bank accounts with different banks and upgrading my phone is an absolute nightmare because of apps like this.
It isn’t just banks. 10 years ago I just used TOTP when I wanted 2FA. But now many tech companies are hand-rolling their own MFA. Google Prompts. GitHub Mobile. Microsoft Authenticator. Adobe Account Access. Some of these still support TOTP, but force you to use their app (Google Prompts when a Google app is installed). Others simply removed TOTP to push their app (Adobe).
TOTP was great as I could generate codes on multiple devices and back up my setup codes. Now I’m forced to use my phone, a device that is easily lost or stolen, and restoring a new phone from a backup generally doesn’t transfer the keys for these types of apps (for “security” I guess) so nightmare is probably putting it nicely.
I’m surprised more people aren’t complaining about all of this proprietary/DIY security. Rolling your own is almost always a bad idea - we have open standards for a reason.
We have NFC enabled cards and phones. I guess one could get a challenge from the card's chip with an app if they insist, but the phone can already work as a contactless card over NFC, so one no longer needs the EMV chip.
Mostly because it costs them money and doesn't allow them to collect data.
They wouldn't care that it's not encrypted.
What data? This is your bank, they already know exactly when what for what amount you're buying because you're doing it with their card. There's no other data they can reasonably get away with collecting.
Good point, but maybe the data they don't directly get from banking isn't as heavily regulated ?