Opening an E*TRADE account was a Security Disaster
The E*TRADE (part of Morgan Stanley) new account intake process was straightforward if a bit tedious, demanding not only personal information, including phone numbers, but also the uploading of a picture holding a government ID through DocuSign.
An intake process like this should normally complete within 24-48 hours, but it was 5 days before receiving a confirmation email that the account was open and accessible with the Account ID and Password. In the meantime, the webpage and chat always showed red alerts that they were having "technical issues" and to "try again later" (which was anything but reassuring).

But logging in did not bring satisfaction. After being asked for more information that should have been captured at account creation, an attempt to enable 2FA (two-factor authentication) for improved security resulted in a demand for a phone number, despite the fact it had been provided during account creation. Adding insult to injury, the system then rejected that phone number, locking the account, preventing access to any money.
Authentication and Security
E*TRADE (Morgan Stanley) was apparently adding mobile carrier verification despite having previously accepted both phone numbers and government ID. In addition to being a classic chicken-and-egg problem, mobile carrier verification is not a good way to verify security, because it is so easily hacked or spoofed. In effect they were downgrading password security by asking for a phone number after password login. Bad actors that have the password are already in.
What should have happened during new account intake, in addition to capturing all necessary information, is setting up secure 2FA using a TOTP authenticator app (by Google, Microsoft or others), completely solving authentication. Instead, this kind of 'security' nonsense is comparable to the security lapses in so-called Wired Equivalent Privacy, which turned out to be hackable in minutes.
Three Strikes
- Technical Problems. Persisting over several days.
- Account Lockout. Arbitrary denial of access to any money.
- Security Lapses. Redundant use of insecure mobile carrier verification.
You should never entrust money to an online system with such serious issues.













