Live data from Hacker News

An unprecedented wave of online bank fraud is hitting Britain

reuters.com

221–224 of 224 posts

Re: An unprecedented wave of online bank fraud is hitting Britain

#221

It utterly infuriates me that banks won't let you use their mobile apps -- which are inevitably their websites packaged in a bundle, with added tracking -- on a rooted (or jailbroken) phone, even though I am sure that the overwhelming majority of users on android who have a rooted device are likely to be the most technically sophisticated, with (in my case) the presence of mind to install updates to their four-year-o…

> expanding the contactless limit ... wallet sniping I am quite interested in the security details of NFC. Where is the best information you found? Unfortunately my searches found too little. BTW: apparently someone managed to use a fault in the protocol to steal well more than the limit. And by the way, if any product proposer mentions a "limit", in order not to be brainless they must also mention a "rate" (e.g. 10€…

Here are a few articles -- admittedly several are quite old, but I am sure I have seen more than this elsewhere. They either discuss attacks, or attack mitigations.

-- "Contactless payment data can be picked up at a distance" (2013) https://www.bbc.com/news/technology-24743920 -- "Mobile device prevention of contactless card attacks", US patent, 2014; https://patents.google.com/patent/US9379841B2/en -- "Proximity verification for contactless card control and authentication systems", Proc. Annual Computer Security Applications Conference, 2015; https://dl.acm.org/doi/abs/10.1145/2818000.2818004

-- Finally, a fairly good review article: "internet of Smart Cards: a pocket attacks scenario"; Intl. J. Critical Infrastructure Protection; 2019; https://www.sciencedirect.com/science/article/pii/S187454821...

Re: An unprecedented wave of online bank fraud is hitting Britain

#222

Earlier quoted context omitted.

"The solution's easy, I could solve it immediately if only people would listen to me" - Person With Absolutely Zero Experience In The Field.

What I get out of that post is "The solution is they have to want to fix the problem." Which is simple but is very different from calling it easy .

What is the evidence that they don't want to fix the problem? The evidence from TFA would suggest they are trying and struggling, mainly due to resources.

Re: An unprecedented wave of online bank fraud is hitting Britain

#223
post #197

Two days ago, I purchased a subscription online and my bank app thought it was a security incident, blocked the transaction and discarded the online virtual card I was using, informed me about the whole process and asked me to create another virtual card to replace all my other 6 subscriptions that were linked to the now defunct card. I'm discovering Revolut.

Are you saying this is a good feature of Revolut, or that you'll be switching to Revolut because of this incident? Personally I'd be happy with this level of fraud protection, as a previous victim of fraud.

This is a good feature. I'm enjoying it actually.

Re: An unprecedented wave of online bank fraud is hitting Britain

#224
post #180

Earlier quoted context omitted.

Haha I wonder if you've read my case. I was scammed out of 100k this year. The scammer had control of my solicitor's email and timed the attack perfectly so I was absolutely convinced I was sending money to the right place. Didn't realize until a few days later when the solicitor called me wondering where the money was. The two week thing might have helped us but the scammer would probably just time their attack diff…

Not sure if you managed to get your money back. But if you didn't, go research the contingent reimbursement model (CRM). Pretty much every major bank has signed up to it, and the CRM requires banks to reimburse victims, if the scam is sophisticated and the victim took reasonable steps to avoid the scam. A basic house deposit payment redirection scam should be covered, assuming you have evidence that the emails were s…

Yep I did. Thanks.
Post reply on HN