Last time can use SMS
Now always prompt for token
Its to safeguard against fraud since its very rampant in Asia.
SMS you need to go through a 3rd party carrier like singtel whereby token provide a direct ID method between bank and client, relatively harder for fraud to occur.
The easiest fraud to perpetuate is to defraud the human, not hack into telcos with professional cybersecurity. DBS ought to know this basic principle of security, since they themselves have security professionals of their own.
I remember a case few years a ago someone phone was hacked and the sms was forwarded so Hacker got the sms OTP and the person did not get the transaction alerts that money is transferred out.
So the token is still the safest option.
Yes, hubby keeps telling me token is safer than SMS. But I find SMS more convenient.
In cases where password or SMS hacked, do the banks return us the money under SDIC?