When there is so clearly a problem with the poor consumer being at risk, why are these institutions not urgently taking more steps to protect their customers and why is the Federal government not stepping in to legislate more safeguards to be mandated?
It used to be that apps were designed to increase a user’s convenience in completing a task by allowing them to bypass security steps. In today’s reality, those shortcuts are now dangerous and should no longer be an option. I would gladly take a few extra seconds to validate my identity rather than making it easier for some hacker steal my money more quickly. I am sure most people would agree with that sentiment.
Here are some suggestions that may help:
1. Make 2-Factor Authentication mandatory for all online banking and trading accounts. Don’t leave it to the consumer to set this up and then blame them for not doing so. Less critical apps including Booking.com, Open Table, Amazon, etc. automatically instituted 2-Factor authentication without requiring their customers to add this to their accounts. Why are financial institutions not required to do the same?
2. Require 2-Factor authentication to take place on every login, not just occasionally
3. Require 2-Factor authentication every time a financial transaction is made including withdrawals or trades, or if an attempt is made to change personal detail, link bank accounts, etc.
4. Add passkeys to all financial applications since this has been touted as the most secure way to protect an account. Currently for major banking and trading apps, only WealthSimple supports passkeys This article explains why passkeys are safer than 2-Factor authentication - https://www.passkeys.com/passkey-vs-2fa
5. Flag and hold any suspicious trades or bank withdrawals that don’t follow a historic usage pattern until the validity of the action can be verified by the account owner
6. For Discount Brokers
a. Add a setting that allows a user to specify the need for a trading password to be entered for EVERY trade, not just the first trade of each login session. Rather than providing this, our discount broker keeps offering options to remove the trading password. This seems so out of touch to today’s reality.
b. Allow the user to restrict which stock exchanges he wants to be able to trade against and require 2-Factor authentication to change this setting. We only want to trade on the TSX and have no desire to trade on NYSE, Nasdaq, or other off-shore exchanges where stories of pump and dump schemes using foreign penny stocks are more common (as illustrated in the two TD hacks mentioned at the start of this article).
It is clear why banks and discount brokers are not jumping to add more security since it costs money to make these changes. Thus, our government needs to step in to mandate more protection. I lobby for additional security changes any time I am asked to fill out a survey or am given the opportunity to suggest feature improvements.
If you have more suggestions, please post in the comments. I will add these to the next survey that I fill out.
It would also be great if we could hear from financial institutions or our government to clarify what plans are being taken to better protect us (not holding my breath). I wrote to the Minister of Finance after our bank accounts were hacked, asking why more security measures were not being legislated. I received what amounted to a form letter assuring me that the government takes their responsibilities seriously and are looking into ways to better protect us. Several years later, I have not read of any planned changes while the threats to us continue to escalate.

No comments:
Post a Comment