Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> A bank will likely never release their app as open source, nor will any of the big authentication vendors.

I suppose you're right and I think it's worrying that precisely these kinds of organizations still seem to rely on security through obscurity (to some extent, not solely).



I'll go further and say that a bank should be required by law to implement and enable access to open banking APIs.

As well as not require, under any circumstances, an account holder to install a proprietary application in order to use the bank.


Not just obscurity, but also requiring you to have a mobile phone, with software made by two spcific companies, (for us europeans) both foreign, and in some cases, not even allow you to have the phone rooted.

I miss the time of totp dongles.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: