back

by joeblau·7y ago·view on hn ↗
I have USAA and they are pretty bad as well. Max password length is 20 characters. They only do MFA through cell phone numbers and email which allows someone to Sim-Swap if they are able to get your username and password. To top it off, they have a mobile app knock-off 2FA screen, but you _can not_ see it when you're trying to log in to your account via the mobile app because the modal doesn't let you leave the input screen.

I was going to write them an email, but they have no clear email to report security concerns so I figured they don't care.

1 comments
Extra stupidity: you literally can't use the USAA app on a rooted Android device; it'll detect that the phone's rooted and refuse to let you login. God forbid I assert control over my own goddamn device, right? It ain't USAA's job to lecture me about my own device security; its job is to shut up and show me information about my car insurance.