So we all have two-factor authentication so we can prove who we are to our banks. If we are lucky it’s TOTP. If we are unlucky it’s SMS.
How about banks start using 2FA to prove it’s them when they call. “Hi, this is Steve from Your Bank. Please open your 2FA application. It should say 148-620 right now. Only Your Bank could know this.”
Edit: On further reflection, this won't stop a man-in-the-middle unless the bank can be sure that it's calling you directly, and in the light of SIM hijacking, I think it could still be vulnerable. Back to the tried and tested hang-up-and-phone-the-bank mechanism!




