Standchart eSaver

touchring1

Supremacy Member
Joined
Jul 24, 2003
Messages
8,439
Reaction score
2,524
Actually it's blame OCBC for having such bad scam controls that the standards have to be set for the banking industry because one bank couldn't figure out how to do things properly.

It's normal for SME bank. Cheaper, faster and better. Cut costs on IT.
 

vsvs24

Arch-Supremacy Member
Joined
Feb 3, 2018
Messages
11,345
Reaction score
3,705
Actually it's blame OCBC for having such bad scam controls that the standards have to be set for the banking industry because one bank couldn't figure out how to do things properly.
But at least OCBC paid back all out of goodwill. If it had been DBS could be a different story, judging from reports on the way DBS handle scams nowadays.

And OCBC has learnt their lesson hard and probably spend more on IT. Recent IT changes they did much better and faster than the other 2 banks.
 

sglandscape

Supremacy Member
Joined
Jan 30, 2023
Messages
6,116
Reaction score
2,954
But at least OCBC paid back all out of goodwill. If it had been DBS could be a different story, judging from reports on the way DBS handle scams nowadays.

And OCBC has learnt their lesson hard and probably spend more on IT. Recent IT changes they did much better and faster than the other 2 banks.
I actually find the scam control for OCBC has become too strict now to be overly cautious. However their money lock feature is the best implementation amongst all the banks.

Paying back out of goodwill is one thing, being the cause of an industry reset is the thing that negatively impact consumers in masses in order to reduce the liability of the banks due to scam. Facial recognition, IP address pinning, alternative MFA techniques have been used to reduce such risks but the banks do not actively adopt it due to cost.
 

vsvs24

Arch-Supremacy Member
Joined
Feb 3, 2018
Messages
11,345
Reaction score
3,705
I actually find the scam control for OCBC has become too strict now to be overly cautious. However their money lock feature is the best implementation amongst all the banks.

Paying back out of goodwill is one thing, being the cause of an industry reset is the thing that negatively impact consumers in masses in order to reduce the liability of the banks due to scam. Facial recognition, IP address pinning, alternative MFA techniques have been used to reduce such risks but the banks do not actively adopt it due to cost.
Depends on individual. Nowadays I don't complain about tight controls. I worry not tight enough.

I find DBS too lax. That's why most reports on scam a lot is DBS accounts. And worse is so lax that scammer can take up loan easily. That was an article where reporter tried out taking up loan of all 3 banks.

If only they bring back physical token.
 

sglandscape

Supremacy Member
Joined
Jan 30, 2023
Messages
6,116
Reaction score
2,954
Depends on individual. Nowadays I don't complain about tight controls. I worry not tight enough.

I find DBS too lax. That's why most reports on scam a lot is DBS accounts. And worse is so lax that scammer can take up loan easily. That was an article where reporter tried out taking up loan of all 3 banks.

If only they bring back physical token.
I would encourage ability for customers to choose token of choice (digital, physical or even a security key). Each has pro and cons and the fraud risk differs.

However for less savvy customers, physical token would probably be the safest.
 

wira

Supremacy Member
Joined
May 6, 2000
Messages
5,759
Reaction score
767
I would encourage ability for customers to choose token of choice (digital, physical or even a security key). Each has pro and cons and the fraud risk differs.

However for less savvy customers, physical token would probably be the safest.
any authentication methods that require password entry or OTPs are also easily phished so even with physical tokens, can still fall prey to phishing scams and enter your physical token OTPs in phishing sites.

Still feel most ideal if facial biometric verification eg our singpass facial.
 

sglandscape

Supremacy Member
Joined
Jan 30, 2023
Messages
6,116
Reaction score
2,954
any authentication methods that require password entry or OTPs are also easily phished so even with physical tokens, can still fall prey to phishing scams and enter your physical token OTPs in phishing sites.

Still feel most ideal if facial biometric verification eg our singpass facial.
Yup facial recognition + security key is probably the best practice. I'm highly against SMS or token OTP since it is the weakest of the link too. Sometimes not even sure what the OTP is used for since it's not clear, and requires an additional step to rekey in to a site.
 

twosix

High Supremacy Member
Joined
Nov 27, 2000
Messages
29,637
Reaction score
8,758
Yup facial recognition + security key is probably the best practice. I'm highly against SMS or token OTP since it is the weakest of the link too. Sometimes not even sure what the OTP is used for since it's not clear, and requires an additional step to rekey in to a site.
In thing now is passkey, which can use biometrics for authentication. For a start, setup ur Chrome browser passkey linked to ur iPhone or android phone.
 

ctan84

Banned
Joined
Nov 14, 2017
Messages
8,773
Reaction score
4,990
Yup facial recognition + security key is probably the best practice. I'm highly against SMS or token OTP since it is the weakest of the link too. Sometimes not even sure what the OTP is used for since it's not clear, and requires an additional step to rekey in to a site.
All these banking apps have the option of using thumb print to access leh. Isn't that the safest liao?
 

ctan84

Banned
Joined
Nov 14, 2017
Messages
8,773
Reaction score
4,990
there could be zero day exploits that may be able to compromise it, but usually it should be safe
Im still sticking to my more primitive way of using banking apps for my main accounts on a spare phone that has no communication apps (whatsapp etc) or data plan / sim card. Meanwhile, the banking app on my day to day phone is just a throw away account with a max of $150.
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top