View Single Post
Posts: 262 | Thanked: 232 times | Joined on Aug 2009
#20
Originally Posted by volt View Post
Although 99% of my interaction with my bank is over internet, that last 1% represents the biggest chunk of money that I will ever spend on anything. That last 1% is by far the most important. For me, anyway.
Good point, but building bad systems should affect your faith in the bank. Personally, I'd at least start investigating alternatives if I was dissatisfied with customer service. If the "bad" bank's offers were significantly better, well, at least I tried...

Originally Posted by volt View Post
Another point for me is that I always use my web bank sitting in front of my PC, with a bunch of papers in front of me. 800x480 and thumb keyboard doesn't do it for me when I need to type in 20 digit KID numbers. I don't know how it is with you guys.
I log in with an 8-digit ID I've memorized and a 4-character one time password (list in wallet, ID not). Once logged in, transactions are authorized with a random reusable 4-character password. The site uses XHTML over HTTPS.

Originally Posted by volt View Post
As to the BankID application (which is actually just one of several java applets I have seen in regard to Norwegian online banking), I suspect it does lift the security somewhat:
I googled a bit, and it seems like the BankID scheme is feature creeped to the max. For simple banking, it doesn't provide security above my bank's, and it introduces new vulnerabilities due to its unnecessary complexity.

And here's the reason for the feature creep:
"The initiative, called BankID, aims to become a national ID infrastructure supporting services such as authentication and digital signatures for the entire Norwegian population."
http://www.nowires.org/Papers-PDF/MitM_SEC2008.pdf

I'd avoid this like the plague.

"We have found cryptographic weaknesses that may indicate security problems, protocol flaws facilitating man-in-the-middle attacks, and implementation errors facilitating strong insider attacks. We also note that the system suffers from severe privacy problems."
http://www.math.ntnu.no/~kristiag/pki/europki.pdf.

Last edited by livefreeordie; 2009-11-17 at 20:39.