Does your bank support two-factor authentication?


Does your bank support two-factor authentication?  

43 members have voted

  1. 1. Does your bank support two-factor authentication?

    • Yes
      33
    • No
      4
    • No But I wish they did.
      5


Recommended Posts

I recently wrote to my bank asking for two-factor authentication. I would be happy if my bank would text my cell phone with a pin that I would use in combination with my login name and password. Apparently it got sent to the IT guy. So my question is, does your bank support two-factor authentication?

The 3 different types of authentication goes as followed

1) Something you know (Like a password, or something you type off the screen)

2) Something you have (Like a cell phone or some sort of device which generates a pin, which someone would have to have in their physical possession to log into your account)

3) Something you are (This would be where you would use a finger print reader, or have your eyes scanned)

My bank has a lame two factor authentication. The second part asks for 3 words random letters from the secret key. Dont like the idea of authenticators. I would rather prefer them texting me a unique key each time I login.

I'm confused, are they asking for something you know or for something have? At the moment it sounds like just 1 factor, just something you know.

Probably password then the next step is asking for three letters from an answer you have already provided them

So password

Give letter 1, 3, 5 of your secret answer

Authorised.

That is prob for online banking though.

My bank uses two-factor authentication for setting up new payees and changes to account settings but not for general online banking (transfers between accounts, viewing statements, etc). It's a decent compromise between practicality and security.

I would prefer banks used mobile more. In particular I would like to be notified every time money is withdrawn from an ATM or purchases above a certain amount are made. I've got an Italian friend and her bank sends her texts when a certain amount is withdrawn, which I think all banks should be required to offer.

I know that is an option with some accounts but not all which I agree should be required "theyarecomingforyou"

And same, setting up payees etc they require a automated telephone call with a pin and all sorts for bank of scotland

My bank has a lame two factor authentication. The second part asks for 3 words random letters from the secret key. Dont like the idea of authenticators. I would rather prefer them texting me a unique key each time I login.

That's what my bank does when I do an online sign in as well.

My bank does give you the option of alerts via email. But only a select few alerts. It does not let you set a dollar amount to be notified about.

For instance, I would like to sent an alert when a check / credit or debit is made on my account for $200 or more.

but what it will alert people about is if their tax refund arrived in their account :angry:

Hmm well I did just see where I can get an alert if my account falls below X amount of dollars. So I just turned that on and set an amount. I guess that's handy.

A physical key card of 72 6-digit codes for login, changing settings and some third-party online services, first 3 digits for confirmation of payments.

Not enough entropy for my liking. Also - three "strikes" and one has to go to the bank in person to unlock online banking again - which I've also had to do once due to taking the wrong key card and then wondering why it didn't accept the thing.

I bank in the UK with NatWest, they use 2 factor authentication in a sensible way. Barclays require you to use a physical chip and pin device every time you login, whilst secure it rapidly becomes a pain in the neck when you're out and about and need access - like that emergency purchase when you're at the office. NatWest only require you to use it when paying someone for the first time or when transferring large sums of money. I can cope with that!

  • Like 1

One of my banks only allow 6-8 character passwords, and I don't believe they even allow special characters . . .

My bank has a limit of 17 characters. The fact they have a limit at all is scary!

Mine uses two forms of something I know. A UN/PW and then a PIN, also if it's an IP address I've never logged in with they as a Secret Question. Pretty good security without getting in my way very much.

One of my banks only allow 6-8 character passwords, and I don't believe they even allow special characters . . .

Capital One is this way...I really wish they would allow me to use a stronger password.

I'm confused, are they asking for something you know or for something have? At the moment it sounds like just 1 factor, just something you know.

CW-88 explained it best, quote below:

Probably password then the next step is asking for three letters from an answer you have already provided them

So password

Give letter 1, 3, 5 of your secret answer

Authorised.

That is prob for online banking though.

I think banks need to up their game. The likes of Steam and Blizzard are providing better login security but I guess no bank has had their online security breached as bad as both these outlets.

My bank requires the following when logging in online.

Access ID: A number provided by the bank.

PIN: A password that the user makes up for themselves.

Authentication Key: A random 6 digit number generated by a key generator supplied by the bank. Number is good for about 30 seconds before a new number has to be generated.

Not sure what else they could do. :)

My bank (Locally owned), has sort of a two factor authentication they think will be best. You log in - and it cross checks against your IP, if it changes, then it sends you a 'pin' to authenticate yourself either to your cell or email on file. Once you enter the pin, you are good to go with just your regular password. Before that, they had a picture that you were supposed to recognize and if you did, answered the question about it and then your password.

Personally, would LOVE to see more support on sites for Yubikey authentication - super easy to do and quite secure.

Personally, would LOVE to see more support on sites for Yubikey authentication - super easy to do and quite secure.

Ya, I bought one when it first came out. I just don't know where it is...hmmm.

my UK bank asks for a 10 digit number and then it'll ask me for 3 random characters from my set password and then for a random 3 digits of my cards pin number.

Canadian credit union asks for member number then it'll ask me for the answer to a security question. If I answer right it'll take me to a password page but it also displays 2 images I chose during signup to verify that the page is "true". Only if the images match should I enter my password.

Overall both institutions seem pretty secure. Never had any issues with fraud with either (touch wood)

I also have an account with another canadian bank and they just ask for debit card number and a password. If it detects that i'm logging on from an odd location or IP it'll ask a security question too.

my UK bank asks for a 10 digit number and then it'll ask me for 3 random characters from my set password and then for a random 3 digits of my cards pin number.

Canadian credit union asks for member number then it'll ask me for the answer to a security question. If I answer right it'll take me to a password page but it also displays 2 images I chose during signup to verify that the page is "true". Only if the images match should I enter my password.

Those "images" were defunked a long time a lot. The phishing sites would actually grab the "images" from the legit site and show them to you on the fake one."

HSBC in the UK are ahead with this type of thing.

You have your log on ID and a password.

Then you have to input the six digits from their "Secure Key" device.

6a01053620481c970b015390bf1a2e970b-500wi

When turning on the device, it asks for a 4-digit pin number, then randomly generates a 6-digit number of which you have to input to get into the bank.

Hassle for when I am elsewhere, but I don't remember my log on ID so only log on at home where the secure key is.

Here's their link with a demo.

It's not strictly two-factor, but it's as secure as it gets.

You enter your card number on the site (not a credit card, number is never used to pay), then put your card in a portable reader thingy and use that to scan an optical code on your PC display. Select what you want to do (logon/sign/buy), enter your PIN and then you get a response to enter on the web page.

To sign transactions or to buy stuff you not only have to enter your PIN number on the reader but also the (total) amount. Pretty much secures you against malicious spoofing of your transactions. I consider this to be extremely safe and you don't have to remember any passwords.

  • 1 month later...

Mine uses a random generated 8 digit password which is send to the registered mobile to authenticate any online payment.

The bank also has 3 passwords.

1) Login

2) Transaction

3) Profile

Login password needs to be changed every 2 months.

So to complete any online payment, I have to know 3 passwords. Login, Transaction and the password sent to mobile which is valid for 1 hr.

Pretty decent.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • it would've been better to just have a screenshot with claude running instead of using a generic thumbnail that doesn't fit the narrative.
    • Helium Browser 0.13.2.1 by Razvan Serea Helium is a private, fast, and honest Chromium-based web browser — built for people, with love. It offers the best privacy by default, unbiased ad-blocking, and a clean experience free from bloat and noise. Proudly based on Ungoogled-Chromium, Helium removes Google’s clutter while keeping a fast, efficient development pipeline. With thoughtful touches like native !bangs and split view, Helium is a people-first, fully open-source browser that puts control back in your hands. Privacy, security, and control come first. Ads, trackers, and third-party cookies are blocked automatically, HTTPS is enforced everywhere, and all Chromium extensions work seamlessly — while Google can’t track your activity. Helium’s 13,000+ offline-ready !bangs let you jump straight to sites or AI tools like ChatGPT instantly. Open-source, people-first, and unbiased, Helium delivers a browsing experience that’s fast, secure, and free from noise, ads, and compromises. Helium Browser key features: Performance Fast, efficient, and lightweight — built on Chromium’s optimized engine. Energy-saving and consistent — stays fast over time without slowing down. No bloat — stripped of unnecessary components for maximum speed. Minimalist interface — compact, clean, and distraction-free. Customizable toolbar — hide elements you don’t need. Smooth and stable — no flicker, lag, or animation glitches. Comfort-focused experience — intuitive and unobtrusive. Privacy & Security Best privacy by default — blocks ads, trackers, phishing, and third-party cookies. Unbiased ad-blocking — powered by community filters and uBlock Origin. No telemetry or analytics — zero background web requests on first launch. Strict HTTPS enforcement — warns for insecure sites. Passkeys supported — modern authentication made simple. No built-in password manager or cloud sync — your data stays yours. Extension Compatibility Full Chromium extension support — including MV2 extensions. Anonymized Chrome Web Store requests — Google can’t track extension installs. Extended MV2 support — maintained for as long as possible. Smart Features Native !bangs — browse faster using 13,000+ offline-ready shortcuts. AI integration — use !chatgpt and others directly from the address bar. Offline functionality — bangs work without an Internet connection. Philosophy People-first design — open source, transparent, and community-driven. No ads, no noise, no bias — privacy and honesty over profit. Helium Browser 0.13.2.1 changelog: 6b6fbd0f revision: bump to 2 (#1907) cb3f77bd helium/ui/zen: fix cmd+s shortcut sidebar preference in zen mode (#1849) e3980159 deps: bump onboarding (#1905) c99531d5 helium/core: add an option to copy URLs from tab context menu (#1904) c1aba0ea helium/search: add kagi image search params (#1899) eb6711f4 helium/core/hibernate: add an option to hibernate other tabs (#1901) 425306f5 merge: update to chromium 149.0.7827.102 (#1897) ae94c3c8 helium/core/update-pref: improve auto updates strings (#1896) 06897c1d patches & domain_substitution: refresh for chromium 149.0.7827.102 d09826d0 merge: update ungoogled-chromium to 149.0.7827.102 9aeb58da helium/search-engine: reject default engine urls without %s (#1893) 4d7bb965 Update to Chromium 149.0.7827.102 fa67665c i18n: fix "add shortcut" string collision (#1891) 6894bd30 devutils/i18n: parse meaning into source.gen.json dc3fe739 helium/kb-shortcuts: disambiguate "Add shortcut" string cbf38eb4 i18n/apply: pass meaning to fingerprint generator 53ea9920 extra/disable-jit-flag: build drumbrake only if supported Download: Helium 64-bit | Portable 64-bit |~100.0 MB (Open Source) Download: Helium ARM64 | Portable ARM64 Links: Helium Home Page | macOS | Linux | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • ExplorerPatcher 26100.8457.70.2 by Razvan Serea ExplorerPatcher is a versatile and free tool that allows you to tweak and enhance the Windows Explorer. It comes with a range of useful features, including the ability to add new context menu items, change file name colors, and enable hidden features. Feature summary Choose between Windows 11 or Windows 10 taskbar (with labels support, small icons and lots of customization). Disable Windows 11 context menu and command bar in File Explorer and more. Open Start to All apps by default, choose number of frequent apps to show, display on active monitor and more. Choose between the Windows 11, Windows 10 and Windows NT Alt-Tab window switcher with customization. Lots of quality of life improvements for the shell, like: Skin tray menus to match Windows style, make them behave like flyouts and center them relative to the icon. Choose action when left and/or right clicking the network icon. Revert to the Windows 7 search box in File Explorer, or disable Windows Search altogether. Disable immersive menus and use mitigations that help you run the real classic theme without glitches. Discover the program's full range of features by reading this wiki article. ExplorerPatcher 26100.8457.70.2 changelog: Tested on OS builds 22621.4317, 22631.7079, 26100.6899, 26100.8037, 26200.8246, 26200.8457, 26300.8493, and 28000.2113. TIP: Windows Defender no longer flags ExplorerPatcher. It is no longer needed to configure Defender exclusions. Enjoy! Important Fixed Windows 10 taskbar and Start menu crashes on builds 26220.8474 (Beta) and 26300.8493 (Experimental). Update ExplorerPatcher as soon as possible. Without this update, Explorer and the Windows 10 Start menu may stop working on future builds. Microsoft removed Windows 10 Start menu components from StartTileData.dll on these builds, so the Windows 10 Start menu option has been removed where it is no longer supported. Temporary workaround: replace C:\Windows\System32\StartTileData.dll with the version from build 26xxx.8457 (x64/ARM64). This may stop working in future builds. Work is ongoing to restore Windows 10 Start menu support. Highlights Fixed Windows 10 battery flyout crashes on build 25951+. Network flyout buttons reverted to pre-24H2 behavior as a side effect. Taskbar location changes now apply instantly. Windows 11 taskbar auto-hide is no longer modified when Explorer starts. "Open Start in All apps by default" is now hidden when using the new Windows 11 Start menu. Fixed Windows 10 Start menu crashes on builds 21996–22000.51. Fixed Regedit crashes when switching to thumbnail view in registry import/export dialogs. Improved compatibility with recent Windows builds, including 26H1 ARM64. Improved ARM64 performance. Added Greek translations. ep_taskbar Now supports all 43 Windows 11 languages. Fixed issues in the system tray and other components. Updated DLL naming scheme for mod developers. Improved TrayUI compatibility and vtable stability on builds with multiple ITrayUI revisions. Fixed a taskbar initialization deadlock. Windows 10 Start Menu Added a new tile layout engine to restore support removed in build 26xxx.8474. Restoration is currently partial: Tiles may overlap when pinned using "Pin to Start". Restarting StartMenuExperienceHost.exe or explorer.exe fixes the layout. Further improvements are planned. Other Changes Added an executable blacklist to prevent shell extensions from loading in selected applications. Updated Windows 10 Start menu animation support for ARM64 builds 28xxx.2149+. Please consult the README for more details. Download: ExplorerPatcher 26100.8457.70.2 | ARM64 | ~11.0 MB (Open Source) View: ExplorerPatcher Home Page | Features | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Microsoft: Windows 11 KB5094126, KB5093998 finally stops trusting a critical system threat by Sayan Sen This week Microsoft released the Patch Tuesday updates for June 2026 with KB5094126 on Windows 11 25H2, 24H2, and KB5093998 on Windows 11 23H2. On Windows 10 22H2 it's under KB5094127. Alongside the announced release notes for the new builds, Microsoft has revealed another change that is coming to Windows with these new releases. It has been confirmed that custom folders are getting a significant change with the June 2026 updates as such folders or folder names defined by desktop.ini will no longer appear after this update is successfully installed. While you may inititally think this is a bug with the new release, Microsoft has stated that this is in fact "expected behaviour" in its new support article regarding this which Neowin spotted today while browsing. Essentially it's a security hardening measure such that custom folder presentations are treated as potentially unsafe whenever Windows is not sure about their origin and whether that desktop.ini folder can be trusted or not. Here is list of such untrusted files and folders: Files downloaded from the internet that carry Mark-of-the-Web (MOTW). Files copied from certain remote locations, such as some WebDAV or HTTP-based locations. Files on network paths that are not classified as intranet or trusted by zone policy. For those who may not be familiar, Desktop.ini is a special configuration file used by Windows to customize the appearance and behavior of individual folders. Basically Windows can read specific instructions stored in Desktop.ini instead of displaying every folder with the same default settings. This can be used to apply custom icons, thumbnail images, localized folder names, and such informational tooltips (infotip). The file can also influence certain folder-specific behaviors and properties. It is typically stored as a hidden system file within a folder that has been designated to support Desktop.ini customization. However, because Windows Shell automatically reads and applies these attributes whenever a customized folder is opened, they have historically (since the Windows XP days) presented an attack surface as a result of an unchecked buffer in the Shell component responsible for extracting custom attributes from Desktop.ini files. As such an attacker could create a specially crafted Desktop.ini containing a malicious or corrupted attributes and place it on a network share. So if a user were to browse that folder, Windows would automatically process the file, potentially triggering a buffer overflow. This could allow arbitrary code to run with the same permissions as the logged-in user. Hence a seemingly harmless folder could become a security risk when their contents are not properly validated. For admins and users alike looking to manage this behaviour, Microsoft has shared a few ways. One of them is to assign a trusted mark on the folder in case you are sure of its source. Secondly a policy can be used to revert back to the previous state. Finally, the MOTW can be removed too to indicate to Windows that this is a safe file. The company explains: Option 1: Add the source to Trusted Sites (Recommended) If the affected content is stored on a known internal or managed source, add that source to the Trusted Sites list. Once the source is treated as trusted, Windows processes desktop.ini from that source normally. This keeps the protection in place for other locations and is the lower-risk option. Option 2: Use policy to restore previous behavior Organizations that need broader compatibility can enable the policy Allow the use of remote paths in file shortcut icons.Enabling this policy restores the pre-June 2026 behavior for affected remote or untrusted scenarios. Option 3: Check for and remove the Mark of the Web (MotW) If the desktop.ini file has a Mark of the Web (MotW), Windows may treat it as coming from an untrusted source and block customization. Verify whether MotW is present and, if appropriate, remove it from the desktop.ini file. This can restore expected behavior, but should only be done for trusted content, as it removes the associated security protection. To remove the MotW tag, open PowerShell and run one of the following commands: For a single desktop.ini file: Unblock-File "C:\Your\Folder\Path\desktop.ini" For all desktop.ini files in a folder: Get-ChildItem "C:\Your\Folder\Path" -Recurse -Filter desktop.ini -Force | Unblock-File Microsoft has warned though against using a broad opt-out using the provided policy as it reduces protection against potentially malicious remote folder-customization content. As such the tech giant recommends trusting only controlled internal sources and keeping trust settings as strict as possible. You can check out the official support article here on Microsoft's website.
    • LAV Filters 0.82.0 by Razvan Serea LAVFSplitter is a multi-format media splitter that uses libavformat (the demuxing library from ffmpeg) to demux all sorts of media files. LAV Splitter is a Souce Filter/Splitter required to demux the files into their separate elementary streams. LAV Audio and Video Decoder are powerful decoders with a focus on quality and performance, without any compromises. Supported Formats: MKV/WebM, AVI, MP4/MOV, MPEG-TS/PS (including basic EVO support), FLV, OGG, and many more that are supported by ffmpeg! LAV Filters are based on ffmpeg and libbluray and is aimed to offer a all-around solution to perfect playback of file-based Media as well as Blu-rays. LAV Filters 0.82.0 changelog: LAV Splitter NEW: Support for demuxing Dolby Vision Enhancement Layer streams NEW: Support for Animated WebP images Changed: When demuxing Blu-ray discs, Dolby Vision metadata is available on the primary video stream LAV Video NEW: Support for Animated WebP images Changed: Hardware decoding support for DVDs has been removed Download: LAV Filters 0.82.0 | 15.5 MB (Open Source) View: LAV Filters Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • One Month Later
      Sopa flores earned a badge
      One Month Later
    • First Post
      StaticMatrix earned a badge
      First Post
    • Week One Done
      StaticMatrix earned a badge
      Week One Done
    • Rookie
      lamborghiniv10 went up a rank
      Rookie
    • One Month Later
      pinnclepd earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      506
    2. 2
      PsYcHoKiLLa
      207
    3. 3
      +Edouard
      156
    4. 4
      Steven P.
      88
    5. 5
      ATLien_0
      79
  • Tell a friend

    Love Neowin? Tell a friend!