Skip to content

Update Capital One #8571

Description

@Damariobros

Site name

Capital One

Site URL

https://capitalone.com

Update reason

The methods of 2FA that it supports have changed.

Additional information

Capital One supports using your Capital One credit and debit cards as NFC security keys to sign into the mobile app. The proprietary implementation is called AirKey, and should be considered as proprietary hardware 2FA.

It should be noted that AirKey is only available on the mobile app and only on devices with NFC.

It should be noted that deactivated cards which were not marked as stolen can still be used to sign in with AirKey, though it is unclear if this is temporary or indefinite. Old cards should therefore be either kept safe as a backup key or have the chip destroyed. This is not documented but is nonetheless present in Capital One's implementation. I experienced this firsthand when CapitalOne deactivated my Master Card and switched me to Discover; I was able to sign in with the deactivated Master Card.

It should also be noted that Capital One App push notifications are only available for use when signing in on the web.

It should also be noted that Capital One only invokes 2FA on "suspicious" sign-ins, i.e. when signing in from a VPN or from a different location. The criteria for "suspicious" sign-ins is unclear.

Issue Eligibility

  • The issue I'm creating is not a duplicate of an existing issue.
  • The issue I'm creating is not a duplicate of an existing pull request

Metadata

Metadata

Assignees

No one assigned

    Labels

    update siteIssue/PR updates information about a site in the repo.

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions