• cron@feddit.de
      link
      fedilink
      arrow-up
      0
      ·
      6 months ago

      IMO this is one example of the countless stupid rules banks force on its customers in the name of security.

      • No VPN
      • Smartphone app only protectable with a four digit pin
      • Access from rooted phones not permitted (but windows PC is ok)
      • Maximum password length enforced

      There are many more, feel free to add some mire stupid ideas.

    • Kairos@lemmy.today
      link
      fedilink
      arrow-up
      0
      ·
      6 months ago

      Bank doesn’t allow use if connection is originating from VPN. It’s really stupid because passwords exist.

  • wahming@monyet.cc
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    6 months ago

    There’s no reason a VPN would increase your security, and many reasons why the bank would discourage the use of VPNs to access their systems

    • null@slrpnk.net
      link
      fedilink
      arrow-up
      0
      ·
      6 months ago

      There’s no reason a VPN would increase your security

      So there’s no benefit to using one to tunnel to your home network while on a public network at a cafe?

      • wahming@monyet.cc
        link
        fedilink
        English
        arrow-up
        0
        ·
        6 months ago

        It would be nice if we were taking comments in context. In this case, WE’RE TALKING ABOUT A BANKING APP.

          • wahming@monyet.cc
            link
            fedilink
            English
            arrow-up
            0
            ·
            edit-2
            6 months ago

            Why are you tunnelling to your home network to use a banking app?

            Your banking app, if it was decently written by a sane programmer, should be entirely immune to any MitM attacks that a VPN would allay. Thus you would not be receiving any major benefit from using a VPN with your banking app. On the other hand, there is significant security value in the bank being able to see the actual IP of connecting clients.

            • null@slrpnk.net
              link
              fedilink
              arrow-up
              0
              ·
              edit-2
              6 months ago

              I’m not tunnelling to my home network in order to use the banking app. I’m tunnelling to my home network as part of my general way of accessing the internet. My banking app isn’t the only thing running on my phone while I use it.

              I don’t want to have to turn it off just to use the banking app.

              if it was decently written by a sane programmer

              Better hope it is then, I guess.

              On the other hand, there is significant security value in the bank being able to see the actual IP of connecting clients.

              Can you expand on that?

              • wahming@monyet.cc
                link
                fedilink
                English
                arrow-up
                0
                ·
                edit-2
                6 months ago

                On the other hand, there is significant security value in the bank being able to see the actual IP of connecting clients.

                Can you expand on that?

                Security analysis. If you used your card in country A 5 minutes ago, logging in from country B across the world should realise a red flag. That’s a very basic example, but advanced versions can be extremely accurate.

  • theshredder744@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    6 months ago

    I hate this fucking app, and I hate their website even more. I wasn’t allowed to us hyphens in my password.

    More than anything I hate that banks make me I replace my 20-character password with a 4-digit pin for the mobile app.

    I would go out of my way to make an account with a bank that takes security more seriously. Sigh.