Good idea, only seen mbna as the other people that do this.
Seems way more secure then reposting a pin out anyway!
The blog suggests that iPhone 5 and onwards have Touch ID. Touch ID started with the 5S.
other banks like Monese also do this, but I think every bank should do so, so well done Monzo
Old news allready have itđ
Interesting to see in the screenshot that Leah has a profile image - is this something thatâs been released, or is this just a mockup screenshot?
Or are you using some other method to pull in the userâs image - such as Gravatar?
If you assign an image to a contact, in the default iOS Contacts app, then itâll be visible in the Monzo app too
While I appreciate the convenience, having the PIN in app is trading convenience for security by reducing the number of things you need to know, or have, to use the card by one. Youâve traded something you know, the PIN, for something you have, your fingerprint.
However your fingerprint was already securing the app, and the phone itself. So youâve reduced security down to a single point of failure, the biometric security of your fingerprint, and that was bypassed just days after the iPhone 5s was released, see http://makezine.com/2013/09/24/hacking-the-fingerprint-scanner-on-the-apple-iphone-5s/ for details of the hack. It is actually pretty trivial.
Iâm actually sort of torn here. In theory this is not a good thing. But in practice, I think this is probably better than SOP, because most people will now not resort to writing their PIN down.
Interesting. That doesnât seem to work for me.
The thing is
If that does happen, which seems unlikely (& as far as Iâm aware, there havenât been reports of this being a common issue), then theyâve acquired your PIN fraudulently which (subject to Monzoâs terms) which means that Monzo is liable for any resulting loss of funds.
What steps are you taking to assign a photo to the contact?
No. Iâm talking about my image. So in that screenshot itâs the userâs profile showing they have an image assigned. Iâm not referring to other userâs images on the transaction list.
My bad, I missed that
I donât have a profile picture in the Monzo app either, even though I do have an image assigned to my contact record in the Contacts app.
Indeed. Thatâs what Iâm asking â whether itâs an actual screenshot (if so, how is the image assigned), or if itâs a mockup.
I think my real fear about using the fingerprint in this fashion isnât this use per se, but how this single instance might expand. Thereâs a real danger with biometrics being seen to be secure enough to stand by themselves that they move from being used for authentication, to authorisation. There is a real difference between authentication and authorisation, and many people (even some security other professionals) confuse the twoâŚ
âŚso not this, exactly although Iâm still sort of torn by how one things I know and one thing I have has suddenly become just one thing I have, but how creeping incrementalism means that holes open in security.
Hopefully Richardâs comment goes some way to addressing your concern here -
I understand where youâre coming from but personally, I trust Apple & Monzo to understand the issues that youâre raising. If the situation that youâre anticipating does become a reality then Iâll definitely join you in raising it!
Itâs understandably not for the hyper security conscious as something you know if done right is harder to force than biometrics. Itâs just a matter of convenience and as @alexs says the common opportunistic thief wonât be going through the trouble of duplicating your fingerprint.
You can choose to not enable it if you wish. If do you choose to enable it then youâll need to enter your card pin and use your saved fingerprint before you can view the pin. In other words its better to enable it while you know it before you forget it, if you want to that is.
If you later decide you want to disable it, you can switch the toggle on your new settings page (link displayed in screen shot) under âTouch ID for paymentsâ.
Itâs a mockup Weâll fix it tomorrow to be accurate when a designer is around â good spot!
Hugoâs just shared a preview of an improvement to this feature which should make a few users (who have older iPhones or canât use Touch Id for whatever reason) pretty happyâŚ