App PIN Security

What am I missing with Monzo security:

  1. I have face authentication & app lock pin switched on.
  2. Someone knows my iPhone pin
  3. They get my phone, open Monzo app and face isn’t recognised, so they use the iPhone pin to open Monzo.
  4. From here they can create a payment link using phone pin and empty my account.

Surely this can not be right. I changed my iPhone pin thinking it was a mistake, but it’s not.

Someone with access to your iPhone pin has full access to empty my account.

No they can’t.

They need your card pin to transfer money out of your account.

Also, there’s advanced security methods that Monzo added that you can enable, which will protect your account further, with limits you can choose above which these checks are invoked.

I’ve just tested it twice and I can log into the app using my iPhone pin. From here I can create a payment link by hiding my face, Monzo app fails to authenticate me and asks for a pin. Put in iPhone pin and link is created.

Please try this and tell me what I’m doing wrong

Are both your pins the same?

Your iPhone passcode is the same as your card pin by the sounds of it. They ought to be different (and your iPhone passcode should really be 6 digits or longer). Monzo asks for your card pin for making payments if FaceID fails. iPhone passcode is used as the fallback only for app access.

2 Likes