19-09-2021, 03:13 PM
(19-09-2021, 02:31 PM)sgxin Wrote: I still prefer the small offline HARDWARE security token, but all banks are phasing them out.
For app-based token, I guess it is better to install it onto another (dedicated) phone that one doesn't use to surf web. This will minimise the chance of hackers also hijacking the installed banking app for the OTP.
my suggestions
maybe we add additional x nr of digits and or Y nr of alphabets in front n after the otp only known to the banks(prearranged w the banks) so hackers will not be able to steal