Skip to content

How We Classify Banks #1811

@jamcat22

Description

@jamcat22

Currently, we classify a number of banks as having 2FA, when they only require it for certain transactions, not for logging in to their website. My question is whether or not we should change any of the banks listed below to tfa: No, add an exception to each of them, or find a way to include a transactional flag on the website.

Below is a list of banks that do not currently fall under our definition of 2FA, despite having the tfa flag set to Yes. I'm curious as to how everyone feels we should handle these types of situations with these banks and any additional ones going forward.

  • Barclays UK's PINSentry doesn't qualify for our definition of 2FA, as their website shows that it is only required for certain transactions.
  • Citibank Australia's OTP doesn't qualify for our definition of 2FA, as it seems that they only require it for certain transactions. Their website says:
    You'll need to enter this anytime you want to perform select online transactions or query through Citibank Online.
  • Commonwealth Bank of Australia's NetCode doesn't qualify for our definition of 2FA, as their website states that it's only required for certain transactions.
  • first direct's Secure Key doesn't qualify for our definition of 2FA, as it can be bypassed using a password to login. Their website says:
    ...this doesn't mean you can't access your accounts if you don't have it with you. You can still log on without it and have limited access to Internet Banking by selecting the link at the top of the log on page...
  • HSBC's Secure Key doesn't qualify for our definition of 2FA, as their website shows how you can choose the "Without Secure Key" tab when logging in to bypass 2FA.
  • Nationwide Building Society's card reader doesn't qualify for our definition of 2FA, as the it can be bypassed using a password to login. Their website says:

You can still log in with your memorable data and passnumber, but by using your card reader you may reduce the number of times it's needed to confirm your online transactions.

  • Natwest's card reader doesn't qualify for our definition of 2FA, as they only require the card reader be used for certain transactions. In fact, their website specifically says:
    We will never ask you to use your card reader to log in to Online Banking, and we will never phone you to ask for your card reader details.

  • Santander's SMS-based OTP doesn't qualify for our definition of 2FA, as they only require an OTP for certain transactions. Their website says:
    ...we send these unique codes to your mobile to security check payments that you have recently set up (and) requests you make to amend some important details like your address.

  • State Bank of India's OTP application doesn't qualify for our definition of 2FA, as they only require an OTP for certain transactions.

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionIssue contains a question.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions