Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What's even the point of all the bullshit with Google play protect if in the end I can access my bank from a web browser. That stupidity is protecting no one


> in the end I can access my bank from a web browser.

If your bank allows you to access all features from a browser, consider yourself lucky. Mine requires the app to authorize any online transaction.


Here in Poland most banks are usable via web browser + SMS for auth.


That's already pretty rare internationally and the odds of it still being the case in five years are zero.


I would argue that SMS is horribly insecure and should never be used for authentication.

https://workos.com/blog/why-sms-mfa-is-insecure


Poland also has the most competitive banking system in the entire Western sphere of influence. You can't compare it to the extremely oligarchic banking system in the United States.


> access my bank from a web browser

Unless you get SMS or some normal TOTP app as 2FA, using the web page usually requires the bank's proprietary app to authorize. So you circle back to the the same issue.


this should be banned…


My bank doesn't allow me to deposit checks digitally without the stupid app. Almost everything else is available on the website.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: