Introducing Strong Customer Authentication: What you need to know

Do you mean making a payment to an existing payee or adding a new payee or something else? I only need password on new payee but perhaps I’m not doing what you are?

1 Like

be careful, i once had a post on here showing how to get round a paywall and i got a telling off

3 Likes

Like with most FCA ‘delays’, the rules come in and they won’t be inforced for the delay period. In fairness to banks, retailers are the reason for the delay!

People seem to opt out of laws all the time, though :thinking:

Probably not a smashing argument to make as a licensed bank though! :slight_smile:

1 Like

That’s only available if you’re super rich and donate to the party in power’s re-election campaign

1 Like

To start with, the current lack of any password or login when opening the app. I don’t think another banking app even exists that does this.

1 Like

Nooooooooooooooo :frowning:

My phone has strong customer authentication. I don’t need the ‘authorities’ to tell me what to do. Can we have an opt out?

Not really an authority that tells you what to do if you can opt out

It’s probably best to concentrate on the online payment authentication rather than the application access - you already need to dip into your app for the former a fair bit (3D Secure) and that is the main growth area

How long will it be before Monzo embraces the dark side!

15 Likes

My eyes!! :eyes: :scream:

4 Likes

It pisses me off how none of the buttons are aligned. Who designed this?

3 Likes

Never, Monzo cards don’t support those :wink: They’d have to reissue every card to support them :stuck_out_tongue:

I have seen our app with Strong Customer Authenticaton fully enabled and it’s obvious how much thought has gone into the experience. In my opinion, the changes are very unobtrusive and well designed. The team have done a wonderful job and I think they are genuinely looking forward to getting it into everybody’s hands :raised_hands:t2:

26 Likes

I’m a computer security advocate, anything like this is a plus. I’m a massive fan of 2FA/MFA and trust me, you need security on your services.

Having to auth to use a feature in an app/service is less of a hindrance than having to “mop up” the aftermath of a security incident.

Sure, banks are covered by the fscs, but if your account got compromised with your credential because you didn’t secure your account, then it’s your fault.

I deal with companies who have had breaches, we perform IT service security check-ups and implement security on services for companies who either a)want to pass Cyber Security Essentials, or b) have left their previous MSP due to their inability to secure their systems to begin with and have been compromised.

5 Likes

If I’m asked to authenticate myself to access the app, that isn’t unobtrusive. That’s pretty much blatant obtrusiveness by design.

1 Like

It doesn’t say that will be the case anywhere here :see_no_evil:

1 Like

To me, that means that if I don’t authenticate myself by (for example) sending a payment in a certain time frame, I’ll be forced to authenticate to access the app.

Depends how regularly regularly is

5 Likes

We have no idea if that’s the case though, so let’s not speculate and moan about something we don’t know to be true and let’s just wait and see eh!

8 Likes