Banking - Physical vs Digital Token

mikelee7900

Member
Joined
Dec 17, 2021
Messages
109
Reaction score
20
Nothing beats token on 2 physical devices.
I believe so too, so if we are using smartphone to access online banking, then it makes sense that the token should not be using our smartphone, and I prefer a separate hardware token to provide OTP etc rather than receiving on my smartphone because as consumers we are not security experts and we will never know whether our phones have been hacked, been planted with spyware/malware/etc.
 

mikelee7900

Member
Joined
Dec 17, 2021
Messages
109
Reaction score
20
An individual's own diligence is their last line of defence, so people have to be responsible for themselves and can't be overly reliant on others.
No amount of own diligence will beat sloopy backend servers where hackers can get hack and get in and then their money lost. So banks and telcos do have a lot of responsibilities to ensure that their systems are really secure.
 

reddevil0728

Great Supremacy Member
Joined
Dec 16, 2005
Messages
66,217
Reaction score
5,838
No amount of own diligence will beat sloopy backend servers where hackers can get hack and get in and then their money lost. So banks and telcos do have a lot of responsibilities to ensure that their systems are really secure.
that's for sure. it's about risk-based approach.

in the past is paper based then in local drive, then in cloud.

just be prepared for changes
 

fr33d0m

Master Member
Joined
Jan 8, 2008
Messages
3,709
Reaction score
729
Just bring back physical token ....
It is not a big ask as long as the consumers are willing to bear the cost to issue tokens. Whatever tokens the backend of the banks does not care. What matters to the banks are cost to issue them.
 

reddevil0728

Great Supremacy Member
Joined
Dec 16, 2005
Messages
66,217
Reaction score
5,838
It is not a big ask as long as the consumers are willing to bear the cost to issue tokens. Whatever tokens the backend of the banks does not care. What matters to the banks are cost to issue them.
Yep. It will likely make it onerous for people to own the physical token.
 

cscs3

Arch-Supremacy Member
Joined
Jun 4, 2000
Messages
21,733
Reaction score
133
I believe so too, so if we are using smartphone to access online banking, then it makes sense that the token should not be using our smartphone, and I prefer a separate hardware token to provide OTP etc rather than receiving on my smartphone because as consumers we are not security experts and we will never know whether our phones have been hacked, been planted with spyware/malware/etc.
Alternatively like UOB, some functions required you to enter ATM pin as a second verification.
 

CrashWire

Supremacy Member
Joined
Nov 28, 2000
Messages
5,931
Reaction score
801
No amount of own diligence will beat sloopy backend servers where hackers can get hack and get in and then their money lost. So banks and telcos do have a lot of responsibilities to ensure that their systems are really secure.
Ledgers can be rolled back, and customers will never lose money in this case because MAS will always want to ensure that there's confidence in our banking systems.
 

yuzu28

Supremacy Member
Joined
Jul 16, 2010
Messages
5,393
Reaction score
2,967
Alternatively like UOB, some functions required you to enter ATM pin as a second verification.
But doesn't this subject your ATM pin to 3rd party? I think backend somehow there's a system that can detect multiple entries of certain password, meaning these pins are collected somewhere.

Ocbc has the most stupid system cos their internet banking and atm pin are the same. Dbs internet banking also using pin.
 

reddevil0728

Great Supremacy Member
Joined
Dec 16, 2005
Messages
66,217
Reaction score
5,838
But doesn't this subject your ATM pin to 3rd party? I think backend somehow there's a system that can detect multiple entries of certain password, meaning these pins are collected somewhere.

Ocbc has the most stupid system cos their internet banking and atm pin are the same. Dbs internet banking also using pin.
Can change the pin what
 

qsgsgs

Senior Member
Joined
Feb 19, 2005
Messages
1,646
Reaction score
404
Digital tokens are 1.5FA . The same device should not be used to get the OTP/approval. Physical tokens which uses FIDO2 like Yubikey are the best but banks here are so slow to implement it.
 

cscs3

Arch-Supremacy Member
Joined
Jun 4, 2000
Messages
21,733
Reaction score
133
Ocbc is same. The one i quoted said 2nd verification for uob i atm pin.
Yes UOB one certain function they will 2nd verification which is ATM pin. So never set ATM pin same as your internet banking password.

OCBC system before this scam is xompletely screw. Found out aometime SEP 2020 they wrote to some customer to change login ID from short simple to complex one. However, seem some lack in this area. You can continue to login mobile app with the old short ID! This is to say your account probably has 2 iDs. This was confirm by their call center. They put it as convenient for customer to login.
 

cscs3

Arch-Supremacy Member
Joined
Jun 4, 2000
Messages
21,733
Reaction score
133
But doesn't this subject your ATM pin to 3rd party? I think backend somehow there's a system that can detect multiple entries of certain password, meaning these pins are collected somewhere.

Ocbc has the most stupid system cos their internet banking and atm pin are the same. Dbs internet banking also using pin.
The last part not sure if true, but I happen to have same pin for both internet banking and ATM.
In any case, the safer way to move out till MAS step in to monitor their operation. Their call center is a key issue to these scam. The long delay really gives these scammer has lots of time to get more money out from your account.

By the way, confirmed by someone. They only compensate those who click the ams scam. FaceBook scam will not be compensated.
 

cscs3

Arch-Supremacy Member
Joined
Jun 4, 2000
Messages
21,733
Reaction score
133
U want to change pin everytime u use to reduce the possibility that it floats in the internet?
Dont think is pin issue alone. Bank system to prevent multiple transfer to same accout should be detected just like other banks.
Usually this is set to more verification is required if similar transaction is 3 or more.
 
Last edited:

wira

Supremacy Member
Joined
May 6, 2000
Messages
5,760
Reaction score
767
The last part not sure if true, but I happen to have same pin for both internet banking and ATM.
In any case, the safer way to move out till MAS step in to monitor their operation. Their call center is a key issue to these scam. The long delay really gives these scammer has lots of time to get more money out from your account.

By the way, confirmed by someone. They only compensate those who click the ams scam. FaceBook scam will not be compensated.
pretty sure can set internet banking pin to be different from atm pin .
in fact that should be a hygiene to set different pins.

i suspect most of the ocbc scam victimes internet banking pin and atm pin is the same , thats why fraudster only need to phish user id + pin + sms otp to setup the digital token since atm pin is same pin
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top