TSB meltdown latest: Facepalming reaches critical mass as Brits get strangers' bank letters


SMS is not a secure method of delivery for 2 Factor authentication....most people in IT have known this for at least 3 years now - SIM swapping is just too easy.

How in holy hell a bank is allowed to continue to use this method is beyond me...

It's really not that hard to implement either Google authenticator or something like symantec VIP

