Ask HN: Why doesn't any US bank use TOTP MFA? (2024)

Hacker News new | past | comments | ask | show | jobs | submit login
Ask HN: Why doesn't any US bank use TOTP MFA?
18 points by unethical_ban on July 3, 2023 | hide | past | favorite | 22comments

In my experience and in talking with friends, we don't know of a single US bank that uses standard TOTP for their two-factor authentication.

The only 2FA options seem to be SMS, email, or upon occasion proprietary 2FA built into their mobile app (Or Symantec VIP, in the case of USAA).

One argument I've seen is that banks have to balance availability and security to their customers and lots of people wouldn't know how to secure their 2FA codes or backup codes. Fine. Why not have it as an option for those of us competent enough to use the technology? It is more convenient and at least as secure as email 2FA, and better than SMS.

Ask HN: Why doesn't any US bank use TOTP MFA? (2)

not_your_vase on July 3, 2023 | next [–]


It's important to realize that for banks IT is a cost center. They spend only the absolute minimum for IT, because they don't make money with it. I have learned it the hard way, by working for some of them (thought must admit, not in the US). They only spend the absolute minimum on anything IT related - if most customers don't complain about it, and auditors are happy, then it means that it is just perfect.

Ask HN: Why doesn't any US bank use TOTP MFA? (3)

jqpabc123 on July 3, 2023 | parent | next [–]


It's important to realize that for banks IT is a cost center.

Sorry, that argument doesn't float in the overall scheme of things.

TOTP is easy to implement, more secure and costs less to operate than SMS verification --- which is widely supported by banks and in many cases is really nothing more than TOTP codes transmitted across the cell network.

If IT cost was really the issue, TOTP would likely be the universal default option.

Ask HN: Why doesn't any US bank use TOTP MFA? (4)

gtirloni on July 4, 2023 | parent | prev | next [–]


> It's important to realize that for banks IT is a cost center

Is this a US phenomenon? Where I live, banks are routinely promoting how they are more modern due to their tech. It's far from a cost center and has been like that for at least 2 decades now.

Ask HN: Why doesn't any US bank use TOTP MFA? (5)

jqpabc123 on July 4, 2023 | root | parent | next [–]


It's important to realize the time value of money.

"Tech" means faster, easier transfers and processing. This is great for consumers --- but not so great for banks.

Banks make a lot of money from "float" --- the lag time between the initiation of a transaction and it's actual completion. The delay between the point in time where money is withdrawn from the sender's account until it is actually credited to the receiver's account. In many cases, this is a day or more in the US.

Bottom line --- most US banks have billions of dollars just "floating" on their books --- continuously. This is someone else's money that the *bank* can earn free interest on.

"Tech" (aka instant transactions) threatens to eliminate this source of income for banks.

Ask HN: Why doesn't any US bank use TOTP MFA? (6)

verdverm on July 3, 2023 | parent | prev | next [–]


unless it's something like Zelle, where they want to force you to use a mobile app so they can... <insert nefarious conspiracy here>

Ask HN: Why doesn't any US bank use TOTP MFA? (7)

Jtsummers on July 3, 2023 | root | parent | next [–]


> ... <insert nefarious conspiracy here>

... retain customers and their money within bank accounts so they can lend it out and make money off of it.

Turns out it's not very nefarious, just normal profit motive. Banks make money with Zelle that they'd lose if you Venmo'd money to your fitness instructor who kept it in their Venmo rather than immediately depositing it into a regular checking account.

Do people actually have nefarious conspiracy theories about Zelle?

Ask HN: Why doesn't any US bank use TOTP MFA? (8)

verdverm on July 4, 2023 | root | parent | next [–]


Why can't I use zelle in a browser? I would use it if I could, but they require a mobile app. Why?

Ask HN: Why doesn't any US bank use TOTP MFA? (9)

Jtsummers on July 4, 2023 | root | parent | next [–]


That's not a technical limitation, that's a choice of your bank (and apparently mine). Critically, though, Zelle is competing with Venmo (in particular) and other mobile-only or primarily-mobile apps. Working within the same environment is "good enough" from the perspective of most banks.

Ask HN: Why doesn't any US bank use TOTP MFA? (10)

joezydeco on July 4, 2023 | root | parent | prev | next [–]


Chase lets you Zelle from the browser.

Ask HN: Why doesn't any US bank use TOTP MFA? (11)

blimpy on July 7, 2023 | root | parent | next [–]


Capital One does too. I’ve used Zelle through Capital One’s website for years, and have never had the mobile app installed.

Ask HN: Why doesn't any US bank use TOTP MFA? (12)

verdverm on July 4, 2023 | root | parent | prev | next [–]


Since when? This is not my experience

Ask HN: Why doesn't any US bank use TOTP MFA? (13)

joezydeco on July 4, 2023 | root | parent | next [–]


Just logged into my account and it's there. I don't know when it was introduced.

Ask HN: Why doesn't any US bank use TOTP MFA? (14)

verdverm on July 5, 2023 | root | parent | next [–]


Have you tried to use it?

I know the link is there, but last time it took me to pages where you were instructed to install the app

Ask HN: Why doesn't any US bank use TOTP MFA? (15)

joezydeco on July 5, 2023 | root | parent | next [–]


There's verbiage all over the site about a "new look" so maybe it is rolling out slowly to sections of the customers.

Mine currently looks like this: https://imgur.com/a/iFDVVwl

Ask HN: Why doesn't any US bank use TOTP MFA? (16)

D7wEQ on July 5, 2023 | prev | next [–]


I think it's both the security vs availability balancing act and the view of IT as a cost center.

From a cynical, cost-oriented point of view, they don't care how free LinOTP, PrivacyIDEA, or any of the libraries that implement TOTP are. They're starting a death march project to license the most expensive proprietary software they can get, then spend a truckload of money on consulting/contractors to finish the job, and finally bleed money on a bunch of maintenance contracts. Once it's in place, they have to deal with the support burden of helping people recover their accounts. Much of that is transferred to email/phone providers since for the average person, it takes a special kind of negligence to irrecoverably lose an email address or phone number. TOTP seeds and backup codes are a bit easier to lose.

On the more optimistic side, it's probably a coverage and time thing. My guess is that around when banks started to get interested in securing their on-line banking offerings it was in that time before smartphones were widespread and OTPs required physical tokens. IIRC HOTP and TOTP didn't get standardized as RFCs until 2005 and 2011 respectively. Smartphone penetration wasn't at 50% in the US until around 2013. While TOTP would be objectively superior, mail/sms two-step is better than single factor auth, so the banks probably just went with what they felt would remove the most barriers to adoption. Plus the sales and marketing people (NOT cost centers) would have been sending emails and texts out to people for years already.

Ask HN: Why doesn't any US bank use TOTP MFA? (17)

kobalsky on July 7, 2023 | prev | next [–]


Wells Fargo’s CEO portal gives you a choice between their app and hardware RSA tokens, I have one with their logo like this https://decovar.dev/blog/2018/09/09/wells-fargo-2fa/

Ask HN: Why doesn't any US bank use TOTP MFA? (18)

Xorakios on July 4, 2023 | prev | next [–]


Most banks can't use TOTP because union agreements prohibit their members from using it.

Schools First in California, City National Bank of Beverly Hills, and all military credit unions use TOTP.

Ask HN: Why doesn't any US bank use TOTP MFA? (19)

oftenwrong on July 5, 2023 | parent | next [–]


Why do the union agreements prohibit TOTP?

Ask HN: Why doesn't any US bank use TOTP MFA? (20)

garbagecoder on July 3, 2023 | prev | next [–]


But what’s in the USAA app is TOTP…

Ask HN: Why doesn't any US bank use TOTP MFA? (21)

unethical_ban on July 4, 2023 | parent | next [–]


True, it's the closest I've seen. Actually yes, it is TOTP though on the backend it's Symantec VIP.

Which makes it the best out of the bunch by this metric. But why not a generic TOTP like any other site?

My broader point is about how simple and generic and yet effective this tech is. Every bank has a proprietary or inferior form of 2FA. In 2023, I'm surprised it isn't more advanced.

Ask HN: Why doesn't any US bank use TOTP MFA? (22)

4hEn on July 4, 2023 | prev | next [–]


Maybe banks want a phone number they can track.

Ask HN: Why doesn't any US bank use TOTP MFA? (23)

Spooky23 on July 3, 2023 | prev [–]


Email and SMS are legacy. Some banks do use TOTP the same way.

The issue with TOTP is that it’s a shared secret, not a second factor. TOTP auth is two step.

Ask HN: Why doesn't any US bank use TOTP MFA? (24)


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
Ask HN: Why doesn't any US bank use TOTP MFA? (2024)
Top Articles
What is the Best Market Entry Strategy for India - Enterslice
MCC 7399 - Noire
Radikale Landküche am Landgut Schönwalde
Skyward Sinton
Chambersburg star athlete JJ Kelly makes his college decision, and he’s going DI
Truist Park Section 135
Alpha Kenny Buddy - Songs, Events and Music Stats | Viberate.com
Craigslist Free Grand Rapids
Tight Tiny Teen Scouts 5
Connexus Outage Map
Dexter Gomovies
Burn Ban Map Oklahoma
Craigslist Panama City Fl
Xomissmandi
Gemita Alvarez Desnuda
Pekin Soccer Tournament
1v1.LOL - Play Free Online | Spatial
Why Is 365 Market Troy Mi On My Bank Statement
Morristown Daily Record Obituary
Hdmovie2 Sbs
ABCproxy | World-Leading Provider of Residential IP Proxies
Heart Ring Worth Aj
Chase Bank Pensacola Fl
Pocono Recird Obits
Craigslist Maryland Trucks - By Owner
Reviews over Supersaver - Opiness - Spreekt uit ervaring
Jordan Poyer Wiki
Macu Heloc Rate
Jcp Meevo Com
Craiglist.nj
Catchvideo Chrome Extension
Unity Webgl Car Tag
Purdue Timeforge
Soiza Grass
Gideon Nicole Riddley Read Online Free
Chase Bank Cerca De Mí
Today's Gas Price At Buc-Ee's
Los Garroberros Menu
How much does Painttool SAI costs?
Ferguson Employee Pipeline
Lcwc 911 Live Incident List Live Status
Weekly Math Review Q2 7 Answer Key
Craigslist Central Il
فیلم گارد ساحلی زیرنویس فارسی بدون سانسور تاینی موویز
Why Are The French So Google Feud Answers
Gon Deer Forum
Rocket League Tracker: A useful tool for every player
Plasma Donation Greensburg Pa
Basic requirements | UC Admissions
Latest Posts
Article information

Author: Duane Harber

Last Updated:

Views: 6692

Rating: 4 / 5 (51 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Duane Harber

Birthday: 1999-10-17

Address: Apt. 404 9899 Magnolia Roads, Port Royceville, ID 78186

Phone: +186911129794335

Job: Human Hospitality Planner

Hobby: Listening to music, Orienteering, Knapping, Dance, Mountain biking, Fishing, Pottery

Introduction: My name is Duane Harber, I am a modern, clever, handsome, fair, agreeable, inexpensive, beautiful person who loves writing and wants to share my knowledge and understanding with you.