Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There isn't actually anything you can do with the login + password. Sure, you can look at the transactions, so I guess it's a privacy problem.

But any transaction or change usually requires generating a single use pin with your debit card and a small card reader. Some also use your mobile phone.



That really depends.

Some banks dont require a code at all for known contacts. Some banks dont require a code at all for small amounts (under 50). Some banks send you a plain SMS with a one-time-password. Some banks send you an SMS with some additional information (receiver, amount) and a one-time-password. Some banks ask for a one-time-password from a dongle. Some banks ask for a one-time-password by entering a challenge code into your dongle and then the dongle generates the new one-time-password. etc.

What I am trying to say is, there is no real standard. The best method I've come across so far is a device in which you insert your debit card, enter your pin, then scan a QR code on the computerscreen and the device will actually show you the receiving IBAN + amount. After pressing OK you get a challenge that you have to enter on the website.

Also in the Netherlands the banks have an API they can use called iDEAL which does the same as "SOFORT" but instead of having "SOFORT" log in to your account, your actual bank immediately transfers the funds and sends an OK to the vendor.

It makes me really angry that bank security isnt standardized and that good systems like iDEAL dont find international adoption. Luxembourg is trying to develope its own version of iDEAL e.g.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: