Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Paypal will.

Don't quote me on this, but I think banks are starting to lean on "possession of a trusted mobile device" as their two-factor authentication. The basic theory is that I give them a number I can receive SMSes at, and then any time they want to verify that the person operating my web browser is really me, they say "We just sent you a one-time password via SMS. Enter it, resend it, or talk to customer service."

This has significant advantages over dongles from the perspective of the bank: they don't have to get into dongle distribution, and people are probably better at keeping cell phones available than they are at keeping dongles available.



My bank in Australia does this (for any transaction to an account I've never sent money to before). Works prettty well.

I click a button, they SMS a 6 digit code, I enter it, money transferred (or bill paid).


Which bank?


That one. :)

http://www.commbank.com.au for those who don't get the joke.


They will also issue a token for those of us living outside the country.


AFAIK, CBA and Community CPS both do it.


As does NAB.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: