Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah, this blog post comes across as startup-y hero worship, like

> I think the root cultural cause is an aversion to self-serve flows.

which is plainly false given the biggest push in the past decade of banking has been self service flows that allow them to cut costs and downsize branches.

Stripe is built on a traditional bank partner. The workflows Stripe optimizes are not “make it easy to empty my new bank account with minimal authentication” workflows.



So why do they all insist on SMS-only for 2FA?


Because they optimise for 'easiest for most people, with an acceptable risk profile'. Note acceptable not lowest.


It doesn't detract from your argument, but there appear to be nine US banks listed at https://twofactorauth.org/#banking which offer hardware- or software-based 2FA.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: