Comment on We're in a very verify-happy era of technology
hedgehog@ttrpg.network 3 months ago
It sounds like your bank is doing MFA (multi-factor authentication) correctly, and that’s a good thing, because it sure would be obnoxious to have to verify all that information just to view your balances, and it’s a higher risk activity to allow someone to transfer funds than to view your balances.
If the dealership didn’t verify your identity and someone else made changes to your lease, would you have a problem with that?
You don’t have to use an authenticator on your phone. You can use a password manager like Bitwarden (their $10/year premium plan, or their $40/year family plan) that supports saving TOTP and auto-filling them from a browser extension (click to copy or you can have it automatically copied to the clipboard after you auto-fill the password). It also supports passkeys and you can avoid getting locked into a single ecosystem that way.
brossman@infosec.pub 3 months ago
adding on to this, the bank isn’t doing just mfa, it’s likely also doing risk-based authentication. logging in and viewing funds isn’t that risky, but moving money around is much riskier, even in the same account. so you have to provide stronger evidence that it’s you requesting the action.