Live data from Hacker News

My bank keeps on undermining anti-phishing education

moritz-mander.de

1–10 of 267 posts

Re: My bank keeps on undermining anti-phishing education

#3
The naive people in decision-making positions often don't realize the risks involved in their behavior until they or someone near to them gets hurt -- in this case scammed or sued.

We used to have a lot of people like this running businesses in the US before roughly 2012, but white (and black) hat hacking began spreading quickly and made generally short work of the problem.

Re: My bank keeps on undermining anti-phishing education

#4
User facing tech and marketing practices at banks are the worst. Every Indian bank login form I've ever had to use is

- hostile to password managers.

- You cannot copy paste passwords.

- Client side password hashing

- Stupid requirements like the password cannot have more than 15 characters and even have a whitelist of character sets! (Looking at you HDFC)

- And of course, run of the mill spam

They are all stuck in the early 2000s.

Re: My bank keeps on undermining anti-phishing education

#5
Heh, we did something similar at the bank where I work. Our marketing department, tasked with getting people to complete some "ongoing due diligence" (a bank term, part of KYC), sent out a bunch of SMS' with links to a page (on a non-core business domain) where we then asked customers to enter a bunch highly personal information. The SMS contained a lot of scary language about your account getting blocked and stuff.

I didn't know about it before my grandmother handed me an article from the local newspaper and told me some of her friends were worried about it. We laughed and I took the newspaper clipping to work and posted it on the wall of failures. Everybody in IT could immediately tell that this was a pretty bad idea, but we weren't asked.

I'd link the article and provide more details, but I'd have to visit my local library, and maybe later.

Re: My bank keeps on undermining anti-phishing education

#6
My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is solid, but it tells you to not respond to their own legitimate calls)!

Re: My bank keeps on undermining anti-phishing education

#7
Speaking of normalizing bad habits, does anyone else remember when you were supposed to only ever enter your password into a site if you'd entered the address yourself (or used a bookmark), because if some other site had redirected you there it might be a fake?

And then now we've got OIDC.

Re: My bank keeps on undermining anti-phishing education

#8
Consumer-facing financial services in Germany are really bad at this, and it is not just Sparkassen: a few years ago an email supposedly from our corporate credit card provider to all of the foreign nationals at our company asking for scans of their passport photo pages triggered a deluge of phishing reports to IT, who had to subsequently inform everyone that yes, the email did indeed look exactly like a phishing attempt, but no, it was real.

I don't really know why the situation is so terrible -- there are many good and competent security professionals working in corporates in Germany -- but perhaps as the post alludes to it is due to a lack of legal or regulatory pressure to date.

Re: My bank keeps on undermining anti-phishing education

#9
My bank has implemented suggestions I've given them in the past (USAA), but recently they used a different domain for a legitimate-seeming email (the email was about something I just did, and it was to an address I only use with that bank), and I called them up and spoke with someone in their fraud department to ask about it. I told them either they were hacked, or they were training their customers to fall for phishing, and asked them to create a ticket.

They said that domain name was not theirs, and they only use usaa.com in their emails. They locked my account without telling me. I had to call them back to get them to unlock my account, and I think that person in their fraud department understood the issue and they said they created a ticket.

We shall see...

Post reply on HN