Authentication.

Jun 29, 2022 Last reply: 4 years ago 28 Replies

With thinks like confirmation of a web based purchase, where the card security check on the web site offers verification via the app, the app only needs the passcode (and will accept nothing else) - to verify the transaction. You may use the biometric just to get into the app however.

Having the option of a OTP via SMS as well, does weaken the whole system a little though. Not sure if that can be removed as an option.

In my case 'what is the name of your pet budgerigar?' 'I don't have a pet budgerigar'

Fooking typical. They just do it to annoy me. But thanks for confirming it.

When I paid online, I (assume) Barclay Card wanted further authentication. Gave me the choice of using the Barclays App, pin sentry (on line, I assume) or sending me a *one off* code via SMS. Not having needed this before I decided to try the Barclays' app. When I couldn't remember the log in code, it refused the transaction totally, on trying again.

So paid by debit card and got the authorisation via a text message.

Yup, that seems to be the way it is supposed to work. The Barclays app will let you login with just a fingerprint, but won't let you verify an online transaction that way...

While you can see why that option needs to be there, it does rather weaken the security advantage provided by the in app verification.

Still it illustrates that the best way to break most secure systems is not to tackle the security head on, but find a way round it altogether. :-)

IME all the banking apps that accept biometric identification capture their own sample, and don't use the set used by the OS for unlocking the device itself.

The barclays app must talk to the android biometric API ...

I have one finger from each hand registered with the phone, and they both work with the phone itself plus a couple of apps. I just added a third finger to the phone, wondering if the app would let me in with it.

As soon as I launched the app it said "your biometrics have changed, so have been disabled"

I went into the app, re-enabled biometric, it needed the banking PIN entering, but after that all three fingers work for the banking app, so a reasonably secure way to not let someone sneakily add their finger as a way into your bank, because if they know the PIN they're already into your bank.

ok this is interesting - I remember when I installed a number of banking apps they wanted me to submit a print "in app" as such. The implication being that it would not necessarily be the same as that used to access the phone.

However I just tried logging into a couple of them with with a finger that the phone knows, but I don't remember teaching the app, and it did work.

So I take back what I said, it looks like it does now work with the phone recorded biometrics.

(The detected change thing is a nice feature is a nice touch - as you say it stops someone adding a "backdoor" finger!)

Thinking more about this - the app scanning a print, may just be the app verifying that you have a print the phone already knows about before allowing access to the app - rather than it capturing its own data...

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required