Re: 2-Factor Authorization Methods

[email protected] Thu, 03 Jun 2021 18:49:27 -0500
Newsgroups alt.computer.security
Organization A noiseless patient Spider
Message-ID <[email protected]>
On Thu, 3 Jun 2021 23:16:08 -0000 (UTC), William Unruh
<[email protected]> wrote:

>On 2021-06-03, [email protected] <[email protected]> wrote:
>> On Thu, 3 Jun 2021 19:13:39 -0000 (UTC), William Unruh
>><[email protected]> wrote:
>>
>>>...
>>>>>
>>>>>I think he is comparing two separate 2-factor methods. On is Symantec's
>>>>>and one is where the other end sends you a text message that you have to
>>>>>respond to.
>>>>>
>>>>>I am not sure, but that is how I read his sentence (It is sufficiently
>>>>>vague that it could mean anything)..
>>>>>So, as I read it,  it is not a comparison of a one (or zero)  factor vs two factor but different
>>>>>2factor methods.
>>>>>
>>>>
>>>> I'm no tech nor security expert.  What I thought he was asking was two
>>>> step authentication really needed over "plain vanilla SMS text
>>>> message".
>>>>
>>>> Now that I read it again, I see he is already using 2 step stuff, but
>>>> asking for info comparing two different methods.
>>>>
>>>> I think he better do as his "financial institution" wishes.
>>>>
>>>
>>>I think he has no choice, without changing banks. But in comparing the
>>>two, he really needs to give us more information. The current procedure
>>>is completely undefined. It may be that that they used to use the sms
>>>version, and they are now forcing him to use the app instead "because it
>>>is more secure". That claim is pretty hard to verify, since the app is
>>>almost certainly proprietary and secret. Many claimed methods are, I
>>>suspect, actually very weak.
>>
>> My wife signed up with our bank and credit card holder for really
>> great idea. Every transaction made on our bank or credit card account
>> is sent via e-mail right after being made. Crooked nonsense can be
>> nipped in the bud immediately.  I don't think there is a security
>> method around that some hackers or other cannot - will not break.  
>
>If they can get into the account, they can change the email address to
>which those transactions are mailed. 

Let's face it, there is no such thing as 100 security with any system.
Chances are with the system our bank has we are protected more than is
the vast majority of people. 

>> What it boils down to is the account holder cannot live in denial or
>> ignorance of the facts regarding the destructive ways of hackers. The
>> real and final responsibility lies with the account holder.  Like it
>> or not - time consuming or not - pay attention daily - or like my wife
>> does, check hourly.  :o)
>
>Sorry, but that is sort of making it backwards. People simply do not
>have the time, knowledge or energy to keep keeping track. If you wife
>has nothing else to do in her life, I guess checking hourly is OK. But
>that is not typical of people in the world. 

True. But this method our bank has does not take any knowledge of
computer stuff.  Most people won't use it simply because they are in
denial that such a thing can happen to them. Well, if you could talk
with those who have gone through this, their first words would
probably be, "I never dreamed this could happen to me. I thought this
only happened to people in the news."

Well, they made the news that day.

The remark about my wife checking hourly was a bit of an exaggeration.
That's why I added the :o) at the end of it. But she does check at
least 3 or 4 times daily.  She's just that way.  Neither of us trusts
the world at large these days.

>The bank has your money and it is on them to ensure that the money is
>given only to you. They of course would like to get rid of that
>responsibility. What do they care if your money is given to some crook,
>and by handing you the responsibility they are no longer forced to care. 

There are laws covering that amount of egregious greed.

>There was a famous case in the UK ( which was I think the first country
>in the world to institue ATMs). One person suddenly discovered that a
>bunch of money disappeared from his account. He complained to the bank.
>They had him arrested and he was convicted and thrown into jail for
>trying to defraud the bank, since he must have given his password to
>someone to remove the money or he himself took it and was now trying to
>get money from the bank by fraud. 
>When Ross Anderson (a Security expert at Cambridge) he helped head an
>appeal which, since the bank claimed that their security was foolproof,
>demanded that the bank reveal the details of their security. They
>refused, and the appeal succeeded. But the banks keep trying to say
>"It's your fault".

I'm an American citizen.  I don't want to discuss other countries such
as the UK in which if someone beats the hell out of someone breaking
into his home, he's the one who goes to jail.  I read such outlandish
denials of human rights time after time regarding the UK.  Matter of a
fact, we presently have a lot of treasonous bastards trying to take
our country in the same direction.