Banking - Physical vs Digital Token

wira

Supremacy Member
Joined
May 6, 2000
Messages
5,761
Reaction score
767
i find physical of digital token, no difference in the case of these scams.

if people are gullible and gave their their credentials and otp, even physical token also no use if they still give away the otp.

One thing to take note between the 2 is...
TT case, using token to check in is always faster and it does not depend on yoir mobile signal coverage.
Banks digital token case, need to take note login and token is on the same device. You need to make sure your device (phone) is very secure. Lossing it means you can get impact heavy. Never never assumed no one can break into your phone even you has password to lock it.

yes agree that mobile device now becomes the weakest link as all your sms, email , banking apps and soft token all reside in the same device.
Added peace of mind is even if someone manage to get your phone , they still need to crack your phone passcode and your bank password in order to access your banking accounts.
 

oceanicmanta

Supremacy Member
Joined
Jan 14, 2013
Messages
9,669
Reaction score
1,382
to add new payee, require OTP right ? ... so scammers able to intercept OTP ?? another case of SMS/OTP diversion ?
 

reddevil0728

Great Supremacy Member
Joined
Dec 16, 2005
Messages
66,222
Reaction score
5,840
I always opined that there should be choices of physical or digital token..... who pays for it will be another matter .....
is not just the variable cost.. need to take into fixed cost spread across dunno how many people who is willing to pay to. get physical token... might not be worthwhile to any party.
For example, instead of dis-incentive to stay with physical token, should also try incentive for using digital token .... should not penalise old folks who stay with physical tokens ....
actually they can make it a cut-off by age. similar to like how new zealand phase out smoking.

so once the generation of "old folks" are gone. then no more physical token
 

chiokcc

Arch-Supremacy Member
Joined
Dec 1, 2005
Messages
13,348
Reaction score
1,527
One of the problems I faced with digital token is the requirement of OS version. If my existing mobile phone is still useable, but cannot meet the OS requirement, I am forced to upgrade, even though I have no wish to do so .....
 

reddevil0728

Great Supremacy Member
Joined
Dec 16, 2005
Messages
66,222
Reaction score
5,840
One of the problems I faced with digital token is the requirement of OS version. If my existing mobile phone is still useable, but cannot meet the OS requirement, I am forced to upgrade, even though I have no wish to do so .....
the argument is that, maybe if your phone cannot even meet the OS version, then maybe the security it provides has reached the stage where it is not even "safe" to use the token. so time to change
 

wira

Supremacy Member
Joined
May 6, 2000
Messages
5,761
Reaction score
767
One of the problems I faced with digital token is the requirement of OS version. If my existing mobile phone is still useable, but cannot meet the OS requirement, I am forced to upgrade, even though I have no wish to do so .....
yeah if phone not supported by the bank apps, most likely the phone OS is already not supported by the manufacturer and not advisable to continue using for security reasons
 

keenklee

Arch-Supremacy Member
Joined
Sep 9, 2000
Messages
19,386
Reaction score
6,775
One of the problems I faced with digital token is the requirement of OS version. If my existing mobile phone is still useable, but cannot meet the OS requirement, I am forced to upgrade, even though I have no wish to do so .....
IMHO.
Is it UOB … require Android 8.0 and higher ?
Recently they changed to UOB TMRW.
OCBC and DBS is Android 5.0 and up.
 

wira

Supremacy Member
Joined
May 6, 2000
Messages
5,761
Reaction score
767
i believe google has also stopped support for android 7 and earlier so might be risky to use these old OS since there will be more more security patches and updates.
 

keenklee

Arch-Supremacy Member
Joined
Sep 9, 2000
Messages
19,386
Reaction score
6,775
IMHO.
RSA Token still 6.0 and up.
Microsoft Authenticator also 6.0 and up.
Just hope the need to upgrade is not so fast.
 

pchan2018

Member
Joined
Jul 11, 2018
Messages
100
Reaction score
21
Here's a suggestion to those folks that are not fun of physical token.

Get one of your old phones (pls dont select the oldest one that you cant even install the latest OS patches anymore or apps are not supporting its OS) or buy one of those not high end phones and use it as digital token phone only. No Sim, only wifi and stored away in your computer table. Dont install anything on it other than the digital apps of your banks. No FB, Instagram, youtube, just bare OS plus your digital bank apps. Dont use SMS as OTP if you can manage it. So you know if you receive an OTP, that you didnt trigger, someone is messing with your account.

This way you still somewhat protected that you dont carry with you all your tokens in your phone which for me is a big security risk as well. Its like carrying the keys to your vault with you plus the vault itself everywhere you go. Specially those that have their personal phones as tokens, do you realise anyone can grab you in the street and force you to do online banking at knife/gun point. Happened to my wife (not here in SG, somewhere else). Luckily the thieves back then were not online savvy and they only got her ATM and the pin out of her and made her wait in their taxi while they withdraw from the nearest ATM.

I still prefer the physical tokens as for me its more secured than my phone that has no anti virus, anti malware and can easily be hacked or worst cloned or sim swap scam. I read a news back then (again not here in Singapore), that some of the unscrupulous folks managed to work with the telco company. What he did is he transferred the customer number to his phone and from there got the customer bank accounts credentials resetted as the pins were already being sent to the culprits phone. While the customer all this time was thinking its a phone or carrier problem thats why he wasnt getting any carrier signal. By the time he went to the telco company its too late, his accounts were drained already.
 

sohguanh

Supremacy Member
Joined
Jul 10, 2010
Messages
9,462
Reaction score
3,202
Here's a suggestion to those folks that are not fun of physical token.

Get one of your old phones (pls dont select the oldest one that you cant even install the latest OS patches anymore or apps are not supporting its OS) or buy one of those not high end phones and use it as digital token phone only. No Sim, only wifi and stored away in your computer table. Dont install anything on it other than the digital apps of your banks. No FB, Instagram, youtube, just bare OS plus your digital bank apps. Dont use SMS as OTP if you can manage it. So you know if you receive an OTP, that you didnt trigger, someone is messing with your account.

This way you still somewhat protected that you dont carry with you all your tokens in your phone which for me is a big security risk as well. Its like carrying the keys to your vault with you plus the vault itself everywhere you go. Specially those that have their personal phones as tokens, do you realise anyone can grab you in the street and force you to do online banking at knife/gun point. Happened to my wife (not here in SG, somewhere else). Luckily the thieves back then were not online savvy and they only got her ATM and the pin out of her and made her wait in their taxi while they withdraw from the nearest ATM.

I still prefer the physical tokens as for me its more secured than my phone that has no anti virus, anti malware and can easily be hacked or worst cloned or sim swap scam. I read a news back then (again not here in Singapore), that some of the unscrupulous folks managed to work with the telco company. What he did is he transferred the customer number to his phone and from there got the customer bank accounts credentials resetted as the pins were already being sent to the culprits phone. While the customer all this time was thinking its a phone or carrier problem thats why he wasnt getting any carrier signal. By the time he went to the telco company its too late, his accounts were drained already.
The problem with this approach for ppl with different bank account if all use physical token wow imagine the hassle. I know as I used to have so many different bank physical token then some no battery need contact CS issue new one etc. Later all become app based centralized on one phone different banking apps.

I guess no solution can satisfy all user needs. For security with app based is to diversify your funds in different bank accounts each not holding too much. For ppl who only have 1 or 2 bank account I strongly advised physical token cuz your funds concentrated in one. Lost once lost all super heart pain!
 

fr33d0m

Master Member
Joined
Jan 8, 2008
Messages
3,709
Reaction score
729
Here's a suggestion to those folks that are not fun of physical token.

Get one of your old phones (pls dont select the oldest one that you cant even install the latest OS patches anymore or apps are not supporting its OS) or buy one of those not high end phones and use it as digital token phone only. No Sim, only wifi and stored away in your computer table. Dont install anything on it other than the digital apps of your banks. No FB, Instagram, youtube, just bare OS plus your digital bank apps. Dont use SMS as OTP if you can manage it. So you know if you receive an OTP, that you didnt trigger, someone is messing with your account.

This way you still somewhat protected that you dont carry with you all your tokens in your phone which for me is a big security risk as well. Its like carrying the keys to your vault with you plus the vault itself everywhere you go. Specially those that have their personal phones as tokens, do you realise anyone can grab you in the street and force you to do online banking at knife/gun point. Happened to my wife (not here in SG, somewhere else). Luckily the thieves back then were not online savvy and they only got her ATM and the pin out of her and made her wait in their taxi while they withdraw from the nearest ATM.

I still prefer the physical tokens as for me its more secured than my phone that has no anti virus, anti malware and can easily be hacked or worst cloned or sim swap scam. I read a news back then (again not here in Singapore), that some of the unscrupulous folks managed to work with the telco company. What he did is he transferred the customer number to his phone and from there got the customer bank accounts credentials resetted as the pins were already being sent to the culprits phone. While the customer all this time was thinking its a phone or carrier problem thats why he wasnt getting any carrier signal. By the time he went to the telco company its too late, his accounts were drained already.
The gunmen knew you have enabled digital token? LOL.

You can carry your key but you don’t have to tell anyone.
 

keenklee

Arch-Supremacy Member
Joined
Sep 9, 2000
Messages
19,386
Reaction score
6,775
The problem with this approach for ppl with different bank account if all use physical token wow imagine the hassle. I know as I used to have so many different bank physical token then some no battery need contact CS issue new one etc. Later all become app based centralized on one phone different banking apps.

I guess no solution can satisfy all user needs. For security with app based is to diversify your funds in different bank accounts each not holding too much. For ppl who only have 1 or 2 bank account I strongly advised physical token cuz your funds concentrated in one. Lost once lost all super heart pain!
IMHO.
At the end of the day, it depends on how much the hassle is worth. 10k, 20k, 50k, 100k, ...
 

reddevil0728

Great Supremacy Member
Joined
Dec 16, 2005
Messages
66,222
Reaction score
5,840
with the recent sms phishing scam. i reckon they gonna push more to mobile auth rather than rely on physical token with sms.
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top