5 ms·
In Sweden where I live you need to use the digital national ID whenever you make a credit card transaction via some app, for example when buying a bus ticket, s
by z3t4 1mo ago
In Sweden where I live you need to use the digital national ID whenever you make a credit card transaction via some app, for example when buying a bus ticket, so you need to have it with you at all times. But with the ID you can also take a quick loan and transfer all the money to a foreign bank basically ruining your life as the bank take no responsibility if the ID is used during the transaction.
- ianmurrays 1mo agoDoes the app not require authentication? At least MitID in Denmark requires a 6-digit PIN at the very minimum, or biometrics optionally.
- pitkali 1mo agoWhen I lived in Sweden I had an 8-digit pin and biometrics enabled, indeed.
- apelapan 1mo agoThe issue is that someone can look over your shoulder and memorize your code, if you use a pin in public. Some people will use the same pin for screen lock and BankID, and if someone gets their code and their phone they can cause a huge amount of trouble in a very short time.
- KomoD 1mo agoThat's just their fault at that point, in my opinion.
- z3t4 1mo agoGiving away your phone would be one thing, but they also force you to give away your passwords and unlock at gunpoint.
- apelapan 1mo agoTechnically yes, but it seems like people's intuition for safe behaviour is worse across the board with modern technology, than it is with old technology. Maybe it will improve by itself over time, but maybe not? There are a lot of things that humans generally suck at, and successful, human-friendly design must take that into account and work around it systematically. Maybe phones/it/banking/payments/identity/authorization needs to be radically changed, in order to serve society well.
- Symbiote 1mo agoMitID (at least as I have it on Android) requires either biometrics or a PIN. To help slightly I've set my username to a long string of random digits.
- ButlerianJihad 1mo agoThis may lead to unintended consequences. Passwords are "protected content" that may be hidden in a web form, but usernames are not. Your username won't be routinely hidden by any ordinary password manager. You may have difficulty when the need arises to share a long string of random digits with another human, or in writing. This may not ordinarily be a thing if more LLMs and chatbots are doing customer service, but if it's a government service, one day we find ourselves at a field office speaking with a civil servant at a window that is armored with Plexiglas, and nobody has a pen to write with, or scratch paper. One of my colleagues said he was so clever that all his "security question" answers were random hex strings. So I imitated him, and it was very easy with the KeePassXC password generator parameters to generate a hex string of 32 characters, and so "my first grade teacher" was 0xf7a83392b12b1029ac3be7e029acbe7e; my "favorite color" was 0xa83392ac3be7e029acbe7f7a83392b17, etc. This turned comical because security questions are particularly designed to be asked and answered in human conversations. Over the phone, the pharmacy CSR was not amused, and I lost a few accounts thanks to this ultra-paranoiac attitude and activity.
- raverbashing 1mo ago> and I lost a few accounts thanks to this ultra-paranoiac attitude and activity. Sorry, but it's obvious to most people that you shouldn't just add a bunch of numbers here If you want to trick the system, give a different (but believable) answer In a world where some companies still think mother's maiden name is something difficult to find, give a "wrong" or "tricked" answer (guess I just recalibrated my 'tism gauge)
- deleted 1mo ago[deleted]
- 1mo ago
- KomoD 1mo agoYes. Minimum 6-digit PIN (I don't know if there's a max) and you can enable biometrics.
- apelapan 1mo agoYes, you really shouldn't ever use a pin code for BankID (or your screen lock) in public. Only biometrics if anyone is watching.
- artisinal 1mo agoNeeding a government app to approve credit card transactions sounds very dystopian. Or did I misread that?
- KomoD 1mo agoIt's not a government app, and you don't need it. BankID (which is the one I assume he's talking about, and not Freja eID) is owned by several banks, but you aren't forced to use it. You can use a "bankdosa" (a separate physical device for auth)
- Symbiote 1mo agoThe app is owned by a consortium of Swedish banks, so you are using a bank app to approve the credit card / bank transaction. At least in my experience, I only needed to authenticate with the app the first time I bought a train ticket, but I don't buy bus/train tickets in Sweden very often. (But this authentication is annoying for trivial online purchases like this, so given the choice I prefer to use a physical card.)
- krn1p4n1c 1mo agoIt depends on which bank you use. Swedbank requires calling and speaking with a rep to transfer internationally in addition to a BankID check.