Earlier quoted context omitted.
> cannot have more than 15 characters That's something! My bank insists on exactly 6 numbers. Not characters, numbers. They're also hostile to password managers and don't allow copy/paste. You have to click on the numbers with your mouse. "My security" is very important to them, so they've moved 2nd factor from a physical fob, to an app tied to my phone, and now they've improved it further by switching to sms! Now, t…
> My bank insists on exactly 6 numbers. Not characters, numbers. When I see this kind of thing I suspect that it's a web app that's simply a proxy for some mainframe screens that were written in the 1990s (or earlier).
My bank keeps on undermining anti-phishing education
51–60 of 267 posts
Re: My bank keeps on undermining anti-phishing education
#52However every time I use it, instead of answering through the secure channel, they try to call me on the phone.
Now they've put out security warnings about scammers impersonating bank staff making calls to customers.
Re: My bank keeps on undermining anti-phishing education
#53Earlier quoted context omitted.
Just piggybacking on this, if your bank (or eBay or Amazon or whoever) ever calls you to inform you of a suspected hack on your account, and says they're sending you a 2 factor authentication code to confirm your identity, do NOT tell them the code. It sounds obvious when phrased like this, but if you're not familiar with the scam then yeah, it's a scam and they're trying to get your 2FA token in order to access your…
That's when you pull out the 69420 code and if they ask your name, it's Ben Chode.
Re: My bank keeps on undermining anti-phishing education
#54> "The SSL certification is from Let’s Encrypt and not from one of the major root CAs" This is NOT a reason to distrust a website.
Not outright, but it's more likely that a malicious actor utilizes the simpler or cheaper solution. $300/yr+ adds up, especially if you need to go through due diligence to acquire the EV.
Re: My bank keeps on undermining anti-phishing education
#55Do these banks not have insurance companies looking at this liability and saying "no you goddamned idiots, we are not covering you."
My mom was recently phished. The scammer got into her bank accounts and charged a bunch of air india tickets to her credit card and used zelle to transfer money out. When we reported it to the bank they said it wasn't covered because their fraud protection doesn't cover scams. So the banks just don't care. (It was Capital One FYI)
Eh?
Re: My bank keeps on undermining anti-phishing education
#56The naive people in decision-making positions often don't realize the risks involved in their behavior until they or someone near to them gets hurt -- in this case scammed or sued. We used to have a lot of people like this running businesses in the US before roughly 2012, but white (and black) hat hacking began spreading quickly and made generally short work of the problem.
Considering that on paper these businesses all have employees serving as CISO, EVP-, SVP-, and many, many Directors of Security, I find it highly unlikely that the accumulated experience of the people and their teams results in decisions like this. It's hard to distinguish incompetence from malice in many situations but calling them "naive" seems to be indirectly excusing customer-hostile behavior. It doesn't make an…
I don't know of anything that can convince a group of leaders making money and doing fine to change besides fear. Perhaps the US with its lawsuit-happy culture helped propel such changes more quickly than in Western Europe.
Re: My bank keeps on undermining anti-phishing education
#57> So the next idea is to register the domain as a subdomain I think the problem is, someone in the IT department understands the high risk associated with handing out subdomains, so they refuse to do it. So other parts of the company "work around" this by registering their own domain name. I wonder how companies like Google handle this. A subdomain of google.com is probably the most valuable hack target in the world,…
Nearly. It almost certainly never even touched IT. The issue is that marketing is organizationally separate from IT and doesn't want to interact with them. IT is probably behind a slow, outsourced ticket based process and will take weeks to do a simple thing. They may also have random opinions about stuff marketing doesn't want them to have opinions about. So building out promos like this is delegated to SaaS service…
Re: My bank keeps on undermining anti-phishing education
#58User facing tech and marketing practices at banks are the worst. Every Indian bank login form I've ever had to use is - hostile to password managers. - You cannot copy paste passwords. - Client side password hashing - Stupid requirements like the password cannot have more than 15 characters and even have a whitelist of character sets! (Looking at you HDFC) - And of course, run of the mill spam They are all stuck in t…
> cannot have more than 15 characters That's something! My bank insists on exactly 6 numbers. Not characters, numbers. They're also hostile to password managers and don't allow copy/paste. You have to click on the numbers with your mouse. "My security" is very important to them, so they've moved 2nd factor from a physical fob, to an app tied to my phone, and now they've improved it further by switching to sms! Now, t…
Re: My bank keeps on undermining anti-phishing education
#59> "The SSL certification is from Let’s Encrypt and not from one of the major root CAs" This is NOT a reason to distrust a website.
Re: My bank keeps on undermining anti-phishing education
#60Something they do when they initiate a call to me on the phone is they start by making sure they are talking to me (they don’t ask me to prove it) and making sure I have the app on the my phone or access to a web page.
Then they initiate a MFA check within the app. I have to get it and read back a number. Then they ask me for my phone PIN or password. Once that’s done, then we can start talking.