Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The readers cost money and people lose them. I still have one for one bank but otherwise it's SMS everywhere.

They clearly just don't see it as a realistic threat, on top of all the other security measures in place (for me it's a password, and also a memorable word that isn't typed on the keyboard, then SMS OTP). It's not a great defence of SMS but perfect is the enemy of good, and SMS is just about ok.

Most hacking stories I hear about seem to happen through social engineering, where people go to great lengths to authenticate themselves for someone over the phone.

One thing that is starting to take hold is banking apps, which once installed can be used to authenticate payment. Again not perfect but better than SMS, and users are increasingly likely to have them installed because of ease of use.



At least here, SIM cloning is a very popular attack.


Where is here? We can't see your geo coordinates :p


As per my parent post, here = EU.


Maybe your country. You do not speak for all of the EU.


Passkeys.


Not a portable format, yet.


at most relying parties you can create multiple passkeys, so this is IMO a good solution until portability might be better


Never will be. Attestation is part of the spec and portability isn't. They are incompatible features.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: