The article doesn’t mention Monzo, but the table shows Monzo as last.
Just reading through the which result How safe is online banking? - Which?
It seems their main problems with Monzo were probably over passwords (it doesn’t have any and shouldn’t) and the fact it doesn’t log you out of the app every five minutes (please god no).
Just by not having a desktop interface that allows you to make transfers etc it’s already several times more secure than a bank that does, they don’t mention that I don’t think.
Ultimately the breaking the security of your Monzo account requires access to your device or your email, and your PIN number. If one or much more preferably both of those things are secure there’s nothing to worry about.
They mention things like pro security testing tools, but don’t actually say they found any weaknesses anywhere that would allow account access, almost certainly because they didn’t.
Interesting. Monzo have previously claimed - and I have no reason to doubt them - that their fraud losses are lower than many of their counterparts. Maybe the Which? survey is looking at the wrong things?
Again almost all remote fraud I’ve seen and heard of takes place via manipulating web browsers over desktops or installing malware with attacks that can’t really be replicated on mobile devices.
What leads to Starling ranking higher?
(I’ve never used Starling)
More than likely. I haven’t seen the linked one yet, but the last time I saw Which? do one of these surveys, they were giving extra marks for features that were, essentially, security theatre. IIRC not having 2FA was an automatic fail, for example.
ETA: looking at the table in the linked article, they give Monzo one star for ‘Navigation and logout’, from which I think it’s safe to assume that their biggest issue is that the app stays logged in (and they’re perhaps not taking into consideration the fact that (a) the user can turn on biometric locks, and (b) even logged in, you still need the PIN to do anything.
Reply rather than editing this time, as I found the Which report:
As I suspected, they had an issue with the ‘always on’ nature of the app:
Monzo was the lowest-scoring app we tested by some margin. It’s the only provider that doesn’t ask you to log in every time. It told us this is a ‘conscious design decision to strike a balance between risk and customer experience’.
They go on to say that while they recognise that a PIN is needed for further actions, they “don’t agree this is the right approach for a bank”. In other words, they’re pretty much saying “Security theatre nao, pls”.
We also marked Monzo down for asking users to enter their debit card Pins to authenticate sensitive changes. While it does block three consecutive incorrect Pin attempts, after which it requires a selfie video and photo ID to proceed, we prefer banks to ask for app-specific passcodes.
(Emphasis mine). This is perhaps a fair point, although I’m sure staff in the past have discussed why they decided against using different PINs - IIRC it was at least in part because a separate app PIN could lead to potential performance/security issues if the app was offline (PIN stored locally, not secure; PIN only held by Monzo, app won’t work if offline).
the TL;DR is, Which? have a picture of how banking security should work, and Monzo have a different picture. It doesn’t actually mean Monzo is any less secure (IMO), just that they’re not doing what Which? want.
(Strikes me as analogous to a maths teacher marking a student’s homework down even though they’ve got the right answer, because their working doesn’t demonstrate the method that was taught in class.)
It would be a lot easier if they just said they don’t understand the difference between privacy and security.
Indeed. I’ll note also that they rank First Direct as best for security, which may be true by their metrics, but it’s f****** annoying; they have so many different passwords and memorable words that I’ve had to reset everything at least three times, due to putting the wrong thing in the wrong place too much and locking myself out.
I’ve had to create an entry in my password app to hold all the First Direct codes for future reference, but you can bet that there will be many people out there who have solved the problem by… writing them down. Probably in a notebook or on a sheet of paper in a desk headed “First Direct passwords”. Something Which? clearly don’t take into account and absolutely makes First Direct, in reality, actually far less secure than they may appear to be.
I actually closed my FirstDirect account because I found the security so annoying, there has to be a balance between security and usability.
sorry to repeat myself but I think any bank with a desktop portal is less secure than any existing one that’s app only.
I don’t think you can call someone having their email hacked a ‘Monzo flaw’. 
Well, that’s sort of wrong imo. The most secure the bank for the average consumer is the one that protects against most of the things criminals commonly try and use and are able to exploit and therefore prevents the most fraud. Reality, not hypotheticals, are what’s important.
Most fraud seems to happen from abroad through a mixture of social engineering and browser manipulation & malware.
Monzo is not the only app to score strangely on navigation and logout either.
First Direct, which seems to work the same as HSBC, scores much lower than HSBC and appears way down the table as a result.
It seems like a fairly useless criteria to be judging to me, the other categories seem far more important but appear to be weighted equally in the scoring?
They’ve missed the point too, since you can always turn on authentication in Settings, so the app can behave exactly how they want it to.
I presume a password, and a new device login requires video verification which I belive is reviewed by one of their team (at least in my experience it’s tended to take a few hours to gain access after changing/resetting devices). Neither of which I agree with as being “more secure”.
But you can’t sanction anything without the customer’s PIN number ![]()
Without?
I don’t know what you mean 
