PPRuNe Forums - View Single Post - Bank gadgets
Thread: Bank gadgets
View Single Post
Old 7th September 2013 | 02:31
  #18 (permalink)  
cattletruck
 
Joined: Apr 1998
Posts: 4
Likes: 1
From: Mesopotamos
For significant transactions my bank will SMS me a 6-digit code
Mac, I personally wouldn't trust SMS at all. The 3G air network has p!ss-weak encryption, and all that 4G hoo-haa about IPSec, if implemented (often it isnt), doesn't apply because SMS is often dispatched as GSM modem command string rather than an IP socket connection. SMS is unsecure and I've seen the telco toys that can easily intercept traffic in the air network.

Then there is the mystery of how your bank sends the SMS to you, even though it probably won't be via some free Nigerian internet to SMS service, it could suffer from similar vulnerabilities.

A more secure approach would be to use a banking app, but you need to invest in a smart phone. However even that is flawed, recently a colleague pointed out a dodgy certificate authority being used in the https internet connection to a big Australian bank's accounts. This occurred just after they had outsourced their internet banking systems to some third world country. He notified them of the serious risk - it took 3 months for them to fix it.
cattletruck is offline  
Reply