Remix.run Logo
Reddit_MLP2 2 days ago

sadly it seems like most of the banks I use still enforce antiquated password rules, no MFA and rely on stupid questions most of which can easily be guessed from public records.

vitorgrs 2 days ago | parent | next [-]

That might change on the country. At least here in Brazil, all logins require some sorth of MFA.

This changes by banks, some send code to our phone number (thought WhatsApp or SMS), others send SMS+email + face ID. All of them require at least the face ID. Some biggest banks requires you to go to ATM to authorize app access. You insert your card, password and authorize there.

There's Mercado Pago, which supports passkeys and standard MFA too. So you can store on bitwarden even.

bdamm 2 days ago | parent | prev | next [-]

Just the other day I was creating an ID on a government web site, which offered a list of security questions such as "Title of your favorite movie" or "Someone that you admired as a child" and the answer was not allowed to have any spaces.

Just absurd.

enobrev 2 days ago | parent [-]

Security questions have always been ridiculous, but I'll especially never understand how "favorite [thing]" ever made it to production anywhere. "Favorite movie" can change multiple times in the same conversation.

thevinter 2 days ago | parent [-]

Still better than the government (!!!) website that a few days ago gave me the option of using "What's the name of the company you first worked at?"

Melatonic 2 days ago | parent | prev | next [-]

You can also just put any answer into the question as long as you will remember it.

edwinjm 2 days ago | parent [-]

It should work for all people and not depend on these “tricks”.

account42 2 days ago | parent | prev | next [-]

Yet they still work and people generally don't have their accounts stolen. Why? Because security is more than technology. Stealing a bank account is illegal and you will be prosecuted for it.

marysol5 2 days ago | parent [-]

hahahahahahahahahahahahahahahahahahahahahahahahahaha

Nobody hacks because that's illegal

account42 a day ago | parent [-]

The optimum amount of hacks is not zero.

thrixton 2 days ago | parent | prev [-]

No doubt preaching to the Choir here but I just generate a new pass phrase and store it in Bitwarden. If course for the non HN audience, much more confusing and dangerous.