https://news.ycombinator.com/item?id=21729875
> “I lost my inheritance with one wrong digit on my sort code”
31–40 of 67 posts
https://news.ycombinator.com/item?id=21729875
> “I lost my inheritance with one wrong digit on my sort code”
An identity check system used for VA loans uses your credit history to come up with secret questions. It's multiple choice and they auto-generate convincing other answers and/or some questions are completely auto-generated "ringers" which you must answer none of the above.
(The questions are things like "Which of the following banks have you had a car loan through?" "Which of the following addresses have you had?")
Problem is, I have very little credit history, so the likelihood of getting a question I can answer is near zero. On the other hand, whatever source they're using also has some assumed-real but actually incorrect associations for me (again, because I have little real credit history, the credit check system seems to be "grasping at straws" to generate a report on me).
So I couldn't just answer "none of the above" for all of the questions, because at least 1 out of each batch of 4 was not an auto-generated made up question but a real question asking me to guess what mistaken answer to it they have on file. After several tries / refreshed batches of questions that were all unanswerable, it locked me out of the system.
There is definitely similar Japanese-specific issues with specifying readings (especially for foreign names), but this works far better than requiring someone to specify the name exactly on the account to see if it is a match or not. I'm not sure if that would work well in the UK given how much more larger the Faster Payments infrastructure is.
The Thai version of this doesn’t require you to enter the recipient name, you just enter a number and a bank ... and it tells you the recipient name for you to check. Pretty fool proof except that it leaks names for bank account details
Seems like a good way to get war-dialed account numbers.
It’s not ideal, but at least since banks have KYC to deal with you know the name is correct. I pay our landlady every month via Zelle and it’s a lot better than mailing checks, if nothing else.
Turo was using out-of-date info to validate my driver's license; I had to guess that it wanted the expiration date from before I renewed my license. An identity check system used for VA loans uses your credit history to come up with secret questions. It's multiple choice and they auto-generate convincing other answers and/or some questions are completely auto-generated "ringers" which you must answer none of the abov…
Now I had to look them up and have a lot of these written down for whenever I need to do a bank wire.
It's never wrong to review that famous and ever-relevant essay, Falsehoods Programmers Believe About Names , and for which there has been oodles of prior discussion on this forum: https://news.ycombinator.com/item?id=1438472 https://news.ycombinator.com/item?id=12450825 https://news.ycombinator.com/item?id=21492464 Original at https://www.kalzumeus.com/2010/06/17/falsehoods-programmers-...
Turo was using out-of-date info to validate my driver's license; I had to guess that it wanted the expiration date from before I renewed my license. An identity check system used for VA loans uses your credit history to come up with secret questions. It's multiple choice and they auto-generate convincing other answers and/or some questions are completely auto-generated "ringers" which you must answer none of the abov…
Time to add a Falsehood[] Programmers Believe About Names: that it's even remotely possible to "match" them. That's just not how names work, frankly.
As a sanity check it’s not a bad system. If you’re expecting you send money to a John Doe it makes sense to be able to tell the bank this so they can compare and come back with “uhh this account is owned by a Mary Sue, are you sure?” As far as catching mistakes I’m sure it’s fantastically good. The odds that a mistyped account number happened to land on someone with the same name is probably vanishingly low. And that…
If we're willing to deal with the 'wardialing account numbers' factor, I think the right flow is "enter account number, SHOW associated name, and make customer confirm it (i. e. by transcribing it off the screen if it's a huge transfer, or just click "Yes, I meant to send to Scamco Ltd.") That avoids the usability nightmare of "the name on file is wrong but not in a guessable way."
I have pretty close to the simplest case for Western-style names-- no middle name, no hyphenation, no suffix or odd prefix, short, common first name, dictionary word last name. The number of times it gets recorded wrong is unbelievable.
Earlier quoted context omitted.
As a sanity check it’s not a bad system. If you’re expecting you send money to a John Doe it makes sense to be able to tell the bank this so they can compare and come back with “uhh this account is owned by a Mary Sue, are you sure?” As far as catching mistakes I’m sure it’s fantastically good. The odds that a mistyped account number happened to land on someone with the same name is probably vanishingly low. And that…
As a sanity check it's awful flow, though. If we're willing to deal with the 'wardialing account numbers' factor, I think the right flow is "enter account number, SHOW associated name, and make customer confirm it (i. e. by transcribing it off the screen if it's a huge transfer, or just click "Yes, I meant to send to Scamco Ltd.") That avoids the usability nightmare of "the name on file is wrong but not in a guessabl…
Sorry, this form requires a middle name.
Barclays does it well: they check and warn but still allow a transaction if names don't match. Santander does it badly: they check and fail, with no way to get around the system if names don't match.
Barclays generally does great UX and Santander sucks, so the above comes as no surprise whatsoever...