New ask Hacker News story: Ask HN: Bank with Yubikey support?

Ask HN: Bank with Yubikey support?
3 by jez | 0 comments on Hacker News.
Yesterday I got an SMS 2FA text from my bank for a login attempt that I did not trigger. I changed my password, alerted my bank, and have been checking my account balance every few minutes it seems, but luckily everything seems fine. The experience got me thinking, because the SMS 2FA was seemingly the last defense saving my account from a breach. My bank doesn't offer a stronger form of 2FA—neither TOTP nor any form of U2F. Meanwhile, I really love Yubikeys; I have one plugged into every laptop I own (work and personal). I use Touch ID or Face ID on sites I access frequently from mobile. It seems that the one place where U2F would be really impactful is online banking, but I've struggled figuring out which banks support strong 2FA without first creating an account with the bank. Does your bank offer U2F, FIDO2, WebAuthn or any other form of hardware security token mechanism for logins? Have you had otherwise positive or negative experiences with the bank overall?

Comments