Live data from Hacker News

My bank keeps on undermining anti-phishing education

moritz-mander.de

21–30 of 267 posts

Re: My bank keeps on undermining anti-phishing education

#21
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

This is especially annoying when I have their app installed, if the app popped up warning me of fraud, I would trust it far more than a random phone call.

Re: My bank keeps on undermining anti-phishing education

#22
post #4

User facing tech and marketing practices at banks are the worst. Every Indian bank login form I've ever had to use is - hostile to password managers. - You cannot copy paste passwords. - Client side password hashing - Stupid requirements like the password cannot have more than 15 characters and even have a whitelist of character sets! (Looking at you HDFC) - And of course, run of the mill spam They are all stuck in t…

> cannot have more than 15 characters That's something! My bank insists on exactly 6 numbers. Not characters, numbers. They're also hostile to password managers and don't allow copy/paste. You have to click on the numbers with your mouse. "My security" is very important to them, so they've moved 2nd factor from a physical fob, to an app tied to my phone, and now they've improved it further by switching to sms! Now, t…

> My bank insists on exactly 6 numbers. Not characters, numbers.

When I see this kind of thing I suspect that it's a web app that's simply a proxy for some mainframe screens that were written in the 1990s (or earlier).

Re: My bank keeps on undermining anti-phishing education

#24
I know this from sport events but often the lottery or prize draw are organised by external marketing companies. So likely this is one reason for not making it a subdomain.

The other is that Germans seem very bad at this kind of stuff. Why the heck would the application for the German passport or Ausweis be published by some random GmbH and not Bundesregierung.gov?

Re: My bank keeps on undermining anti-phishing education

#25
I find there are a lot of people who just don't "get" written communication.

Once I got a vaccination, and in order to do it I had to fill out a form where I chose the arm. The form said to circle either "right or left."

The word "right" was on the left and "left" was on the right.

I pointed this out to the nurse and she laughed, and then realized her error, because she made the form.

Re: My bank keeps on undermining anti-phishing education

#26
> So the next idea is to register the domain as a subdomain

I think the problem is, someone in the IT department understands the high risk associated with handing out subdomains, so they refuse to do it. So other parts of the company "work around" this by registering their own domain name.

I wonder how companies like Google handle this. A subdomain of google.com is probably the most valuable hack target in the world, but google does use subdomains occasionally (...or maybe more than occasionally! https://gist.github.com/abuvanth/b9fcbaf7c77c2954f96c6e55613...)

Re: My bank keeps on undermining anti-phishing education

#27

The naive people in decision-making positions often don't realize the risks involved in their behavior until they or someone near to them gets hurt -- in this case scammed or sued. We used to have a lot of people like this running businesses in the US before roughly 2012, but white (and black) hat hacking began spreading quickly and made generally short work of the problem.

I also suspect that the social dynamics of these kinds of organizations make it difficult for the right people for making these kinds of decisions to rise to the right positions for making them.

There's almost a catch-22: setting good, effective policies tends to involve a lot of telling people "no". And it's hideously difficult to do that without ruffling the feathers of people who control promotions.

Re: My bank keeps on undermining anti-phishing education

#28
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

Ye they don't follow their own rules. Once my bank called me for a insurance change I requested a month or so earlier and asked me to verify myself via the security dongle. Like, and then they act surprised when people are scammed.

Heh. 20 years ago when I was buying my house, I was arranging the mortgage through HSBC bank. One day I got a random call, started by asking me to confirm my name and date of birth. I asked them who they were, and they refused to say anything before going through security. I told them I wasn't giving them any personal details without knowing who they were, and they hung up.

A week later, I phoned up the bank asking why everything was progressing so slowly and they said I'd failed the security check, so the process had been paused. I explained what had happened, and how it was ridiculous that they expected personal details without even saying they were from the bank, which they seemed to agree with, but said that was their procedure so it was my fault for not complying.

Re: My bank keeps on undermining anti-phishing education

#30
Some of the worst practices I've seen are from FedEx. When you order an international package, you get a text from some random FedEx employee's personal mobile number, containing a link to a website where you're meant to enter your credit card details to pay import duties. WTF? NO. I've called up about it and the support team were just like "ugh, yes, I know, yeah that's actually probably legit."
Post reply on HN