My bank keeps on undermining anti-phishing education
moritz-mander.de
My bank keeps on undermining anti-phishing education
1–10 of 267 posts
Re: My bank keeps on undermining anti-phishing education
#2Re: My bank keeps on undermining anti-phishing education
#3We used to have a lot of people like this running businesses in the US before roughly 2012, but white (and black) hat hacking began spreading quickly and made generally short work of the problem.
Re: My bank keeps on undermining anti-phishing education
#4- hostile to password managers.
- You cannot copy paste passwords.
- Client side password hashing
- Stupid requirements like the password cannot have more than 15 characters and even have a whitelist of character sets! (Looking at you HDFC)
- And of course, run of the mill spam
They are all stuck in the early 2000s.
Re: My bank keeps on undermining anti-phishing education
#5I didn't know about it before my grandmother handed me an article from the local newspaper and told me some of her friends were worried about it. We laughed and I took the newspaper clipping to work and posted it on the wall of failures. Everybody in IT could immediately tell that this was a pretty bad idea, but we weren't asked.
I'd link the article and provide more details, but I'd have to visit my local library, and maybe later.
Re: My bank keeps on undermining anti-phishing education
#6Re: My bank keeps on undermining anti-phishing education
#7And then now we've got OIDC.
Re: My bank keeps on undermining anti-phishing education
#8I don't really know why the situation is so terrible -- there are many good and competent security professionals working in corporates in Germany -- but perhaps as the post alludes to it is due to a lack of legal or regulatory pressure to date.
Re: My bank keeps on undermining anti-phishing education
#9They said that domain name was not theirs, and they only use usaa.com in their emails. They locked my account without telling me. I had to call them back to get them to unlock my account, and I think that person in their fraud department understood the issue and they said they created a ticket.
We shall see...