Comment Re:Until artificial limits are removed... (Score 5, Interesting) 538
Do you think that's all? Nope. With that you can only use IB in 'read only mode', not being able to perform any transaction that might make a debit to your account. Then you have to request a 'codes card', with is basically a very cheap version of a token, albeit a little less secure. Upon completion of each transaction you'd be required to type one of the codes in your card. Thing is, fraudters caught up to that pretty quicly, and started sending phising mail where they'd lead the baits to a website passing as the bank asking them to type all their codes for 'security purposes'.
So then they made it compulsory to register each computer you use IB with, therefore forcing you to use a whitelist to enable trusted computers. You actually have to go in person to an ATM machine and use your debit card + 3 letter PIN + 4 digit debit PIN to authorize each computer. Thing is, so many people have machines so full of malware that this wasn't enough to stop the fraudsters.
Next in line was their latest addition: now in order to be able to make transactions online, not only you must have the IB password, install a proprietary browser 'security plugin', the token card, authorize your machine previously on an ATM with your debit card + 3 letter PIN + 4 digit debit PIN, you also must have a mobile phone on your file with the bank. Then, after you use all your passwords and code card in a trusted machine, they then generate a 7-digit code that is send via SMS to your mobile phone (which can also be only updated in person or in an ATM with both pins).
What if you don't have a mobile phone? What if you don't have signal at the moment you want to perform the transaction? What if your phone battery is out of charge? Well, tough luck, you'll have to go to a Santander ATM machine, because all these security paranoia features are mandatory...
The thing is, this a perfect example of adverse selection in effect, so now every bank is demanding you to install proprietary plugins (which are usually modified rootkits themselves..) to ensure the safety of your machine before being able to use any IB. Some are already demaning the use of SMS on a per-transaction basis and the process of using IB is getting more inconvenient by the day...
When I compare that with the breeze that is using the IB for my HSBC account in the US... it makes me wonder how much inconvenience is enough to tolerate...