I’ve been going through updating all of my accounts (passwords, 2FA, etc.), and I’ve noticed that there are a lot of sites that don’t offer any form of MFA.

I can understand smaller services that might not have the bandwidth, but surely larger organisations are able to get this setup?

  • tiramichu@lemm.ee
    link
    fedilink
    arrow-up
    0
    ·
    5 months ago

    As a developer who has worked on similar systems, I can see why it likely ended up that way. Not justifying it, only understanding it.

    In the case of banks, it’s likely that;

    • They needed to make 2FA mandatory for all customers, rather than opt-in. This means they needed an MFA method which a person of any technical competency can use. SMS is the “lowest common denominator” here, so they chose it.

    • The cost of sending SMS messages is high, but banks are (unsurprisingly) rich and can afford it

    It would be great if banks offered better MFA methods, but development time in old-school banks is often ridiculously long as it is a very risk-averse industry that is also slowed down a lot by bureaucracy. It’s likely they would choose something else on the roadmap, and stick with SMS as simply “good enough”