講起哩個就把幾火
本來add to wallet佢send sms嚟就認證完,宜家要自己走去搵銀行客服整,唔方便用家之餘跟本唔知邊到安全咗
雖然contact客服要login個app,咁佢app入面整個self service自己㩒制咪得,點解一定要搵真人客服搞,佢問啲問題跟本唔洗我本人都答到,淨係yes yes yes就搞掂,但係咁就搞咗4日,本來2分鐘搞掂嘅野

嬲到我去搵埋hkma份文件
Specifically, card-issuing AIs are required to conduct additional authentication (on top of the input of correct card data and the one-time password) to confirm that the
cardholders have indeed given the instructions to bind their cards with new payment services. Examples of such authentication measures include:
(a) Obtaining additional confirmation from cardholders before the binding takes effect through 2-way SMS, in-App confirmation, call back or other effective means;
(b) Requiring the cardholders to perform additional authentication (through measures similar to paragraph (a) above) before the first mobile payment transaction is conducted through the newly bound payment services; and
(c) Requiring the cardholders to activate the newly bound payment services after performing a two-factor authentication in the internet or mobile banking
applications of the banks
佢a b c都係例子,啫係淨係做一個都冇問題,咁你做c嘅話,銀行可以經mobile app send notification跟住要比password/指模,咁已經做到2fa(加埋本來就要嘅card number+SMS),成件事完全可以automate唔洗經人手
宜家係銀行design到個flow咁麻煩又冇特別安全到,唔屌銀行屌邊個
如果hkma自己寫完哩段之後又唔比銀行淨係用2fa就另計啦
