Live data from Hacker News

A bank security check that leaves you guessing your own name

theguardian.com

21–30 of 67 posts

Re: A bank security check that leaves you guessing your own name

#21

Japan's banks have a similar system, based on half-width katakana. Fortunately most banks can fetch the name from each other, but sometimes transfers fail due to issues similar to those found in this article.

It's almost a rite of passage for expats in Japan to be denied some service over name issues.

The length of names is a common cause. In Japan, a normal full name is usually 4 or 5 characters long, with some exceptional cases being slightly longer. Systems often have a character limit which can exclude many non-Japanese names, especially if you have a middle name.

Re: A bank security check that leaves you guessing your own name

#22
post #18
post #16

Earlier quoted context omitted.

> In most countries, bank account numbers are not sensitive information. That is an american oddity. They're not really secret in America either. I mean, the account details are on every check for instance.

Yeah, but I dare you give out your account number to a random person. The bank security system here is ridiculous. I always stick to cashier's check for this very reason (and for accounting purpose).

I have written quite a few checks to people I don't know. I don't think too many people think twice about it.

Re: A bank security check that leaves you guessing your own name

#23

Australian banks have a system called osko/pay id. You register with your bank a phone number or email I think. And when someone transfers money using your phone number you get a confirmation of their name.

And it's so good! Really love the work the NPP are putting into building the new payments infrastructure.

Re: A bank security check that leaves you guessing your own name

#24
post #18
post #16

Earlier quoted context omitted.

> In most countries, bank account numbers are not sensitive information. That is an american oddity. They're not really secret in America either. I mean, the account details are on every check for instance.

Yeah, but I dare you give out your account number to a random person. The bank security system here is ridiculous. I always stick to cashier's check for this very reason (and for accounting purpose).

But that's what people did, back in the day when they wrote checks to pay for things in store.

Re: A bank security check that leaves you guessing your own name

#25
post #18

Earlier quoted context omitted.

Yeah, but I dare you give out your account number to a random person. The bank security system here is ridiculous. I always stick to cashier's check for this very reason (and for accounting purpose).

I have written quite a few checks to people I don't know. I don't think too many people think twice about it.

My understand is that in the US system anyone can initiate transfer out of your account with your routing and account numbers (both are on the check itself so they're not really "secret"), but if they are doing it without your consent they'll get into legal trouble and you can get your money back (but it _might_ take some time to get your money back). As a result most people just shrug it off.

Re: A bank security check that leaves you guessing your own name

#26

At least this is explainable by designers not anticipating hard cases. I remember the shittiest app from HSBC (who, by the way, seem to be sleepwalking their way through retail banking, with no direction from anyone who cares), which asked: "What is the answer to your chosen secret question?"

It's dumbfounding how awful bank websites are at security. They started with the stupidest conceivable way to implement two-factor--a second clear-text password that is an answer to a very small number of secret questions. Then they limited the secret questions to things people could find out about you on Facebook, then on top of that added secret questions about esoteric crap like your father's mother's childhood neighbor's dog's name, secret questions that have answers that vary over time like your favorite song, secret questions that have ridiculous length or punctuation requirements, authentication by SMS, authentication by robocall, and on and on and on. The only thing they absolutely refuse to try is an actual friggin' two-factor app!

There's security theater, and then there's Punch and Judy security puppet shows.

Re: A bank security check that leaves you guessing your own name

#27
post #18

Earlier quoted context omitted.

Yeah, but I dare you give out your account number to a random person. The bank security system here is ridiculous. I always stick to cashier's check for this very reason (and for accounting purpose).

I have written quite a few checks to people I don't know. I don't think too many people think twice about it.

Donald Knuth used to write checks in hexadecimal amounts to people who reported errors in his books (I have $7.68) but had to stop because people post photos of the checks online and the numbers printed on them can be used for fraud.

Re: A bank security check that leaves you guessing your own name

#28

We have a very similar system in Canada called Interac, which works well enough. All you need is the registered email or phone number of the recipient and it will grab all the rest of the info, no matter who they bank with.

There are a lot of issues with fraud on Interac though, even if it is just customers doing foolish things. https://www.cbc.ca/news/business/rbc-customer-out-of-pocket-...

This is clearly a usability vs security decision. The advantage here seems to be that you can receive payments without registering your email, which seems like a nice feature to have. I wouldn't have to keep track of yet another money transfer service (there's already paypal, vemo, zelle), and it's one less account that could get hacked in the future. Also, considering that the recipient's email was probably hacked (how else were they able to get ahold of the email?), even having a mandatory email registration system wouldn't necessarily prevent the fraud from happening. The attacker could re-register your email address to his account, and since he controls your email, he could also approve any verification emails.

Re: A bank security check that leaves you guessing your own name

#29

Japan's banks have a similar system, based on half-width katakana. Fortunately most banks can fetch the name from each other, but sometimes transfers fail due to issues similar to those found in this article.

They're fun, too, in that the ultimate authority for setting the recipient name is on the sender but the ultimate authority for accepting a transfer is the bank of the recipient, which can result in that failure-to-sync causing someone to input a name which cannot be reconciled with the account's owner. (This is particularly common in consumer-to-business payments because even with great attention to detail if you're not doing this frequently the error rate will be a few percent.)

The pull system works in a different but similar fashion, and will (notably) fail if the information submitted with an incremental pull fails to match the name which was handwritten onto the document which sets up the pull (which is circulated at both financial institutions). A gym once received, and I was (in the literal sense) CCed, an icily polite letter from my local bank saying that the bank had no knowledge of a Mr. (close misspelling of McKenzie) and that if the gym had business with customer of the bank it should due him the common courtesy of getting his name right.

Re: A bank security check that leaves you guessing your own name

#30

At least this is explainable by designers not anticipating hard cases. I remember the shittiest app from HSBC (who, by the way, seem to be sleepwalking their way through retail banking, with no direction from anyone who cares), which asked: "What is the answer to your chosen secret question?"

They rightly thought that showing the question could give away the answer, and thus decided to make that secret.
Post reply on HN