Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think the best tips for non-savvy people are:

1 - use an iphone for all banking. It's the single hardest system for someone to install spyware on: they are more careful about which apps are in their store than android, and the apps are more isolated. Android apps often have spyware; android install prompts on websites are super sketchy (and cover 1/4 of the screen, perfect to trick older or unfamiliar users into installation), and the permissions are far less granular. Windows is a disaster for secure computing, from viruses to "install this to get 500 smiley faces" to flash with monthly zero-days to fake software installs advertised via google sem.

2 - use gmail, and use 2fa

3 - pay the $30 for the hardware login tokens for your brokerage (and ideally, banking) account

4 - don't use any wifi except home wifi; just use wireless

5 - NO, your friend/cousin/grandchild is not stranded in an airport in Europe



You have to pay for hardware login tokens? In most of Europe, they're not only free, but mandatory.

And, depending on how un-savvy you're talking about, I'd recommend just doing internet banking at your local bank. Just set all regular bills on auto, and configure your account to text you if something unusual happens (like your current account is running low). Then you should only really need internet banking a handful of times a year.


> Just set all regular bills on auto

I realize that opinions on this differ, but I think that automatic bill payment is a horrible security practice.

Just last week I was paying with credit card in which the merchant punched in $5504 by accident instead of $504. Had I not noticed it right away, at least I'd get another chance to correct the error when my credit card bill arrived. With auto-pay, my bank account would have been emptied.

What would you do if some sort of auto pay error emptied your bank account? These things take time to resolve. What if it's a weekend, or a holiday, or you're traveling overseas, or the entity that caused the problem is on strike, or they want a written dispute from you?


I like auto payments for regular payments such as a gym membership of $X/month and even for payments that vary somewhat but are from pretty reliable sources (monthly utilities--maybe) but NOT for credit cards. Credit cards are all sorts of different charges every month for all sorts of things in all sorts of circumstances. You really should look over the charges each month and figure out any that don't look right. Auto payment trains you to ignore something you should train yourself to keep an eye on.


Many banks allow you to set a max for an ebill. However, 99% of my auto payments are fixed amounts, so your scenario doesn't apply. Auto pay is the only thing that keeps my bills paid on time (I suck at paying bills manually).


I wouldn't (and I don't) have autopay on the credit card. Anyway, if suddenly my current account is emptied for some weird reason, I have backup funds that can be transferred to the current account in five minutes on my phone.

Also, I started from the assumption of a non-technical person with "simple finances", so no credit card.


I freely admit that hardware tokens may be more secure, but the more 2FA that uses the standard implemented by Google Authenticator the happier I am. Plus, in my mind it would be cheaper and easier to implement a software only process than to try and convince a CFO that buying, shipping and managing little pieces of hardware will have sufficient ROI.

I also am not holding my breath for even the software 2FA since quite a few of my financial institutions won't even let me use punctuation in my password. Yes, the irony of implementing 2FA lowering the risk of a simple password isn't lost in me.


the simpler one is don't do online banking at all




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: