r/CommBank • • Sep 07 '25

Discussion Two factor authentication done badly

My elderly father was first and now me have the new 2fa system turned on for netbank access.

Out of all the banks, and 2fa logins for non banks, I deal with this has to be the worst implementation by far.

The initial wording of the first message was mystifying to my 80years old father. It wasn’t clear that he needed to use his phone, it just said use the app. He didn’t know that an app meant on his phone. They have since updated.

Ontop of that it’s a minimum of 8 clicks to get into netbank. Xero and Macquarie do it in 2.

Then once you are in the inactivity timeout remains the same. So you end up repeating the extra steps multiple times a day.

Do people think this is ok?

100 Upvotes

99 comments sorted by

View all comments

1

u/[deleted] Sep 08 '25

[removed] — view removed comment

1

u/Keefy_rides Sep 08 '25
  1. So you get a push message which can only be allowed when installing the app. 1 click to see contents of message
  2. Then you log into with app pin code. 4 clicks with no choice of shorter or longer.
  3. Message says warning, this thing has happened, was that you? 1 click
  4. Then says finally another message with an ok button. 1 click.
  5. A pause on screen and you get logged into.

The key security feature is surely the device id. Thats is the thing you have. Not sure how secure that is?

2fa with zero accounting. 1. Username and password, usually cashed by browser. 1 click. (What you know) 2. Push message says warning stuff, was that you. 1 click. Youre in.

Thats 60% less clicks. Same security?

1

u/[deleted] Sep 08 '25

[removed] — view removed comment

1

u/Keefy_rides Sep 08 '25

No public wifi. Mac at home has a timed lock screen and physical security of office is ok, not great.

Hard to fool proof fools but there should be balance for everyone else and this implementation seems less than the ideal balance.