Different countries have different systems. In Sweden, our “banking app” is not really for doing bank tasks, it’s everywhere in society as a 2FA app. Buying a bus ticket, booking a medical appointment, paying bills, logging in to various government and non-government web sites, signing a contract, etc. They all use the banking 2FA app. It’s really really difficult to have a normal life without this app.
True. I was more talking about “banking apps” being more than seeing the balance of my accounts in a web browser instead of using their app. BankID is used for much more than that.
The system works through a series of redirects. Say if I have to prove my identity to some government website, it offers different authentication methods, one of which is my bank. I 2F authenticate with my bank the way we agreed, then it redirects me back to the originating site.
Different banks offer different systems for 2FA. Most also offer an app. Google services are not always required. If you don’t want to use an app, there are ways; in addition to username/password, usually a SMS for strong auth, or some code from a database that I have for weak auth.
No app, OS-independent.
If my bank forced my to use an app that only works with google services, I’d change banks. As I did, actually.
That’s actually very similar to what we have, minus the option to change to a different bank, since all our banks are using the same 2FA app and there’s not really any other options or at least not better options. This is a very bad system, building our society on a proprietary app from a private company, but… that’s where we are unfortunately. Actually, recently our government has realized this and is developing a neutral state controlled 2FA app, but it will only run under android and iOS, so… yeah.
Unfortunately, at least in my country, it’s getting harder and harder to do banking through a plain old webbrowser. Apps are being pushed hard and afaik all of them use the Google Lock-In API in their Android app. Alternatively I could switch to iPhone, but having had the displeasure of experiencing their crappy hardware and even worse service I’d rather cut my balls off than ever dealing with Apple again.
Many banks nowadays at least try hard to push you to use some kind of app method to verify transactions, in place of other TAN methods.
Though my main bank still lets me use an old-fashioned chip-TAN device, not all banks would do that.
I’m on Graphene OS, and luckily all my other banking apps work on there. I’ve got them isolated in another user profile, seperated from my daily use apps, so only the banking profile gets Google Play services enabled.
Maybe a silly question, but can you not do it in a web browser? It’s what I’ve been doing.
Different countries have different systems. In Sweden, our “banking app” is not really for doing bank tasks, it’s everywhere in society as a 2FA app. Buying a bus ticket, booking a medical appointment, paying bills, logging in to various government and non-government web sites, signing a contract, etc. They all use the banking 2FA app. It’s really really difficult to have a normal life without this app.
It does not require Play Integrity though… yet.
True. I was more talking about “banking apps” being more than seeing the balance of my accounts in a web browser instead of using their app. BankID is used for much more than that.
This also works in abrowser. At least in Finland.
Then we have different systems. How do you prove that you are you online in Finland? Do you use usernames+passwords or some 2FA ID system?
The system works through a series of redirects. Say if I have to prove my identity to some government website, it offers different authentication methods, one of which is my bank. I 2F authenticate with my bank the way we agreed, then it redirects me back to the originating site.
Different banks offer different systems for 2FA. Most also offer an app. Google services are not always required. If you don’t want to use an app, there are ways; in addition to username/password, usually a SMS for strong auth, or some code from a database that I have for weak auth.
No app, OS-independent.
If my bank forced my to use an app that only works with google services, I’d change banks. As I did, actually.
That’s actually very similar to what we have, minus the option to change to a different bank, since all our banks are using the same 2FA app and there’s not really any other options or at least not better options. This is a very bad system, building our society on a proprietary app from a private company, but… that’s where we are unfortunately. Actually, recently our government has realized this and is developing a neutral state controlled 2FA app, but it will only run under android and iOS, so… yeah.
How exactly do you 2FA with the bank without the bank’s 2FA app?
Source, from Finland.
Unfortunately, at least in my country, it’s getting harder and harder to do banking through a plain old webbrowser. Apps are being pushed hard and afaik all of them use the Google Lock-In API in their Android app. Alternatively I could switch to iPhone, but having had the displeasure of experiencing their crappy hardware and even worse service I’d rather cut my balls off than ever dealing with Apple again.
Many banks nowadays at least try hard to push you to use some kind of app method to verify transactions, in place of other TAN methods. Though my main bank still lets me use an old-fashioned chip-TAN device, not all banks would do that.
I’m on Graphene OS, and luckily all my other banking apps work on there. I’ve got them isolated in another user profile, seperated from my daily use apps, so only the banking profile gets Google Play services enabled.
The app is so much more convenient, but it’s something I’m wiling to sacrifice to avoid Google.
And that’s what we need more of, not appification.
The app is so much more convenient, but it’s something I’m wiling to sacrifice to avoid Google.