Live data from Hacker News

My bank keeps on undermining anti-phishing education

moritz-mander.de

51–60 of 267 posts

Re: My bank keeps on undermining anti-phishing education

#51

Earlier quoted context omitted.

> cannot have more than 15 characters That's something! My bank insists on exactly 6 numbers. Not characters, numbers. They're also hostile to password managers and don't allow copy/paste. You have to click on the numbers with your mouse. "My security" is very important to them, so they've moved 2nd factor from a physical fob, to an app tied to my phone, and now they've improved it further by switching to sms! Now, t…

> My bank insists on exactly 6 numbers. Not characters, numbers. When I see this kind of thing I suspect that it's a web app that's simply a proxy for some mainframe screens that were written in the 1990s (or earlier).

I bet it's actually a set of solenoid actuators physically typing into a 90s terminal.

Re: My bank keeps on undermining anti-phishing education

#52
My bank has a secure messaging system inside their website and app.

However every time I use it, instead of answering through the secure channel, they try to call me on the phone.

Now they've put out security warnings about scammers impersonating bank staff making calls to customers.

Re: My bank keeps on undermining anti-phishing education

#53
post #32

Earlier quoted context omitted.

Just piggybacking on this, if your bank (or eBay or Amazon or whoever) ever calls you to inform you of a suspected hack on your account, and says they're sending you a 2 factor authentication code to confirm your identity, do NOT tell them the code. It sounds obvious when phrased like this, but if you're not familiar with the scam then yeah, it's a scam and they're trying to get your 2FA token in order to access your…

That's when you pull out the 69420 code and if they ask your name, it's Ben Chode.

Haha yeah, or 'Deez'.

Re: My bank keeps on undermining anti-phishing education

#54
post #46

> "The SSL certification is from Let’s Encrypt and not from one of the major root CAs" This is NOT a reason to distrust a website.

Not outright, but it's more likely that a malicious actor utilizes the simpler or cheaper solution. $300/yr+ adds up, especially if you need to go through due diligence to acquire the EV.

True - but if browsers don't show the EV cert until I click 3 buttons and my bank don't use one is there really a point?

Re: My bank keeps on undermining anti-phishing education

#55
post #18
post #10

Do these banks not have insurance companies looking at this liability and saying "no you goddamned idiots, we are not covering you."

My mom was recently phished. The scammer got into her bank accounts and charged a bunch of air india tickets to her credit card and used zelle to transfer money out. When we reported it to the bank they said it wasn't covered because their fraud protection doesn't cover scams. So the banks just don't care. (It was Capital One FYI)

> their fraud protection doesn't cover scams

Eh?

Re: My bank keeps on undermining anti-phishing education

#56
post #48

The naive people in decision-making positions often don't realize the risks involved in their behavior until they or someone near to them gets hurt -- in this case scammed or sued. We used to have a lot of people like this running businesses in the US before roughly 2012, but white (and black) hat hacking began spreading quickly and made generally short work of the problem.

Considering that on paper these businesses all have employees serving as CISO, EVP-, SVP-, and many, many Directors of Security, I find it highly unlikely that the accumulated experience of the people and their teams results in decisions like this. It's hard to distinguish incompetence from malice in many situations but calling them "naive" seems to be indirectly excusing customer-hostile behavior. It doesn't make an…

The example given in TA seems to be a straightforward case of institutional naivety (banks doing stupid stuff that confuses customers and makes them prone to potential identical-appearing phishing attacks) -- for which the only solution is for decision makers to be convinced that something needs to change.

I don't know of anything that can convince a group of leaders making money and doing fine to change besides fear. Perhaps the US with its lawsuit-happy culture helped propel such changes more quickly than in Western Europe.

Re: My bank keeps on undermining anti-phishing education

#57

> So the next idea is to register the domain as a subdomain I think the problem is, someone in the IT department understands the high risk associated with handing out subdomains, so they refuse to do it. So other parts of the company "work around" this by registering their own domain name. I wonder how companies like Google handle this. A subdomain of google.com is probably the most valuable hack target in the world,…

Nearly. It almost certainly never even touched IT. The issue is that marketing is organizationally separate from IT and doesn't want to interact with them. IT is probably behind a slow, outsourced ticket based process and will take weeks to do a simple thing. They may also have random opinions about stuff marketing doesn't want them to have opinions about. So building out promos like this is delegated to SaaS service…

Have you tried what you're recommending without an ad block extension recently?

Re: My bank keeps on undermining anti-phishing education

#58
post #4

User facing tech and marketing practices at banks are the worst. Every Indian bank login form I've ever had to use is - hostile to password managers. - You cannot copy paste passwords. - Client side password hashing - Stupid requirements like the password cannot have more than 15 characters and even have a whitelist of character sets! (Looking at you HDFC) - And of course, run of the mill spam They are all stuck in t…

> cannot have more than 15 characters That's something! My bank insists on exactly 6 numbers. Not characters, numbers. They're also hostile to password managers and don't allow copy/paste. You have to click on the numbers with your mouse. "My security" is very important to them, so they've moved 2nd factor from a physical fob, to an app tied to my phone, and now they've improved it further by switching to sms! Now, t…

SG?

Re: My bank keeps on undermining anti-phishing education

#59

> "The SSL certification is from Let’s Encrypt and not from one of the major root CAs" This is NOT a reason to distrust a website.

This absolutely IS a reason to distrust a website claiming to be owned by a bank (or any other institution working with such sensitive assets). To be precise, such a website absolutely needs to have a certificate granted not only on the basis of "yes, I control the machine this domain points to" (which is what Let's Encrypt does), but also based on other, more physical and reliable means.

Re: My bank keeps on undermining anti-phishing education

#60
I use USAA for banking.

Something they do when they initiate a call to me on the phone is they start by making sure they are talking to me (they don’t ask me to prove it) and making sure I have the app on the my phone or access to a web page.

Then they initiate a MFA check within the app. I have to get it and read back a number. Then they ask me for my phone PIN or password. Once that’s done, then we can start talking.

Post reply on HN