BugsBunny58
Junior Member
- Joined
- Apr 9, 2012
- Messages
- 65
- Reaction score
- 8
Nice, mine is in as well
blame all those scammers haiz. make our lives difficultonly those facing issues will complain and post.
Prolly alot more others no issues like me.
Actually it's blame OCBC for having such bad scam controls that the standards have to be set for the banking industry because one bank couldn't figure out how to do things properly.blame all those scammers haiz. make our lives difficult
Nice, mine is in as well
yeah..u guys referring to some special invite is it?
my normal esaver march BI end of march already come in.
Actually it's blame OCBC for having such bad scam controls that the standards have to be set for the banking industry because one bank couldn't figure out how to do things properly.
But at least OCBC paid back all out of goodwill. If it had been DBS could be a different story, judging from reports on the way DBS handle scams nowadays.Actually it's blame OCBC for having such bad scam controls that the standards have to be set for the banking industry because one bank couldn't figure out how to do things properly.
I actually find the scam control for OCBC has become too strict now to be overly cautious. However their money lock feature is the best implementation amongst all the banks.But at least OCBC paid back all out of goodwill. If it had been DBS could be a different story, judging from reports on the way DBS handle scams nowadays.
And OCBC has learnt their lesson hard and probably spend more on IT. Recent IT changes they did much better and faster than the other 2 banks.
Depends on individual. Nowadays I don't complain about tight controls. I worry not tight enough.I actually find the scam control for OCBC has become too strict now to be overly cautious. However their money lock feature is the best implementation amongst all the banks.
Paying back out of goodwill is one thing, being the cause of an industry reset is the thing that negatively impact consumers in masses in order to reduce the liability of the banks due to scam. Facial recognition, IP address pinning, alternative MFA techniques have been used to reduce such risks but the banks do not actively adopt it due to cost.
I would encourage ability for customers to choose token of choice (digital, physical or even a security key). Each has pro and cons and the fraud risk differs.Depends on individual. Nowadays I don't complain about tight controls. I worry not tight enough.
I find DBS too lax. That's why most reports on scam a lot is DBS accounts. And worse is so lax that scammer can take up loan easily. That was an article where reporter tried out taking up loan of all 3 banks.
If only they bring back physical token.
any authentication methods that require password entry or OTPs are also easily phished so even with physical tokens, can still fall prey to phishing scams and enter your physical token OTPs in phishing sites.I would encourage ability for customers to choose token of choice (digital, physical or even a security key). Each has pro and cons and the fraud risk differs.
However for less savvy customers, physical token would probably be the safest.
Yup facial recognition + security key is probably the best practice. I'm highly against SMS or token OTP since it is the weakest of the link too. Sometimes not even sure what the OTP is used for since it's not clear, and requires an additional step to rekey in to a site.any authentication methods that require password entry or OTPs are also easily phished so even with physical tokens, can still fall prey to phishing scams and enter your physical token OTPs in phishing sites.
Still feel most ideal if facial biometric verification eg our singpass facial.
In thing now is passkey, which can use biometrics for authentication. For a start, setup ur Chrome browser passkey linked to ur iPhone or android phone.Yup facial recognition + security key is probably the best practice. I'm highly against SMS or token OTP since it is the weakest of the link too. Sometimes not even sure what the OTP is used for since it's not clear, and requires an additional step to rekey in to a site.
All these banking apps have the option of using thumb print to access leh. Isn't that the safest liao?Yup facial recognition + security key is probably the best practice. I'm highly against SMS or token OTP since it is the weakest of the link too. Sometimes not even sure what the OTP is used for since it's not clear, and requires an additional step to rekey in to a site.
the thumbprint is based on keys stored on your device itself (the OS key store), it's not exactly reading your thumb print per se, same for face ID performed by your OS.All these banking apps have the option of using thumb print to access leh. Isn't that the safest liao?
I go actively use a password manager, and where supported a hardware key.In thing now is passkey, which can use biometrics for authentication. For a start, setup ur Chrome browser passkey linked to ur iPhone or android phone.
So hacker can still access that?the thumbprint is based on keys stored on your device itself (the OS key store), it's not exactly reading your thumb print per se, same for face ID performed by your OS.
there could be zero day exploits that may be able to compromise it, but usually it should be safeSo hacker can still access that?
Im still sticking to my more primitive way of using banking apps for my main accounts on a spare phone that has no communication apps (whatsapp etc) or data plan / sim card. Meanwhile, the banking app on my day to day phone is just a throw away account with a max of $150.there could be zero day exploits that may be able to compromise it, but usually it should be safe