Live data from Hacker News

My bank keeps on undermining anti-phishing education

moritz-mander.de

81–90 of 267 posts

Re: My bank keeps on undermining anti-phishing education

#81
post #7

Speaking of normalizing bad habits, does anyone else remember when you were supposed to only ever enter your password into a site if you'd entered the address yourself (or used a bookmark), because if some other site had redirected you there it might be a fake? And then now we've got OIDC.

Widespread TLS means you can now trust the domain name.

Re: My bank keeps on undermining anti-phishing education

#82
post #4

User facing tech and marketing practices at banks are the worst. Every Indian bank login form I've ever had to use is - hostile to password managers. - You cannot copy paste passwords. - Client side password hashing - Stupid requirements like the password cannot have more than 15 characters and even have a whitelist of character sets! (Looking at you HDFC) - And of course, run of the mill spam They are all stuck in t…

> cannot have more than 15 characters That's something! My bank insists on exactly 6 numbers. Not characters, numbers. They're also hostile to password managers and don't allow copy/paste. You have to click on the numbers with your mouse. "My security" is very important to them, so they've moved 2nd factor from a physical fob, to an app tied to my phone, and now they've improved it further by switching to sms! Now, t…

Worstpac?

Re: My bank keeps on undermining anti-phishing education

#85
post #64

Earlier quoted context omitted.

> their fraud protection doesn't cover scams Eh?

When I talked to the bank I was like "So if she had just lied and said she didn't know how they got her information she would have been covered, but since she was honest and admitted to being scammed she is getting punished?"

A retail bank with a massive advertising budget has to pinch pennies somewhere.

Re: My bank keeps on undermining anti-phishing education

#86
post #76

Earlier quoted context omitted.

> My bank insists on exactly 6 numbers. Not characters, numbers. When I see this kind of thing I suspect that it's a web app that's simply a proxy for some mainframe screens that were written in the 1990s (or earlier).

I remember at least one major US bank saying that the reason they only allowed short passwords was indeed that it was the limit for login passwords on their mainframe. I was sure this was complete bullshit because even if everything is handled on the mainframe a user using their online banking would not be logging on to the mainframe. The online banking password is a credential for the bank's application(s) that run…

The pathways and decisions made might be unintuitive and effects can linger even after the original reasons no longer apply.

Where I work, usernames are still limited to 8 characters because some old unix platforms didn't support more than that. I'm virtually certain that none of those are still in use today, but the requirement was baked into user provisioning in ways that would be expensive to change, so they keep with it.

Re: My bank keeps on undermining anti-phishing education

#87
When buying or selling a house, this can get really bad. You have all sorts of entities which extensions of other entities. The bank has a mortgage sector which uses a different domain.

I also had to deal with a medical device recall, which was terrible. I had to trust some skeezy domains.

This isn't hard to fix, all you need to do is list on your website your "partner domains."

My personal security protocol was to search a .gov website for contact info of financial institutions, go to the domain listed, look for a customer service number, and call that to find out what domains to trust. Customer service people thought I was weird.

At one point, a customer service person said, "you know it's legitimate because if you go to LinkedIn, you can see the person you're dealing with has listed as their employer."

Re: My bank keeps on undermining anti-phishing education

#89

My bank used to call me with random marketing crap, and insisted on telling them my birthday and my mother's name before they can reveal their latest exclusive offer or some other crap. They were always dumbfounded when I retorted that it is them who need to prove that they're really calling from my bank first.

[deleted]

Re: My bank keeps on undermining anti-phishing education

#90
I've been getting lots of scam calls lately, especially AI voice generated once, and there was one particularly annoying. Very persistent call about being approved for some loan, no reference to any particulars, all very vague, and I kept ignoring. In my mind I had no doubt it was a scam. Well, long and boring story short, now I have a missed payment on my credit report for my new HVAC system..
Post reply on HN