this post was submitted on 19 Sep 2024
60 points (95.5% liked)
Privacy
31974 readers
309 users here now
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
Chat rooms
-
[Matrix/Element]Dead
much thanks to @gary_host_laptop for the logo design :)
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
90% of American commercial services that is.
Online services or many/most European services have more proper 2FA (TOTP, app-based, card reader OTP, etc...)
Can you name me an EU bank that doesn't demand a phone number to signup?
Unfortunately, PSD2 doesn't support TOTP and other strong 2FA solutions, so they all appear to require phone numbers. This is one area where EU is worse than US
That is a completely separate issue from the above commenter.
Also an issue, but indeed a separate issue from using unsecure SMS as TOTP.
I don't follow. Banks are required to use insecure SMS for OTPs by PSD2
My EU bank never ever used my phone number to verify anything. They only used it to contact me on some occasions. 2FA is done through their app.
Oh, right, their closed source app. Thats allowed. So it requires a phone.
So the OTP is still transmitted to satisfy the requirements of PSD2. But TOTP (a more secure system that doesn't transmit the OTP at all) is not allowed.