Speaking of normalizing bad habits, does anyone else remember when you were supposed to only ever enter your password into a site if you'd entered the address yourself (or used a bookmark), because if some other site had redirected you there it might be a fake? And then now we've got OIDC.
My bank keeps on undermining anti-phishing education
81–90 of 267 posts
Re: My bank keeps on undermining anti-phishing education
#82User facing tech and marketing practices at banks are the worst. Every Indian bank login form I've ever had to use is - hostile to password managers. - You cannot copy paste passwords. - Client side password hashing - Stupid requirements like the password cannot have more than 15 characters and even have a whitelist of character sets! (Looking at you HDFC) - And of course, run of the mill spam They are all stuck in t…
> cannot have more than 15 characters That's something! My bank insists on exactly 6 numbers. Not characters, numbers. They're also hostile to password managers and don't allow copy/paste. You have to click on the numbers with your mouse. "My security" is very important to them, so they've moved 2nd factor from a physical fob, to an app tied to my phone, and now they've improved it further by switching to sms! Now, t…
Re: My bank keeps on undermining anti-phishing education
#83Re: My bank keeps on undermining anti-phishing education
#84Re: My bank keeps on undermining anti-phishing education
#85Earlier quoted context omitted.
> their fraud protection doesn't cover scams Eh?
When I talked to the bank I was like "So if she had just lied and said she didn't know how they got her information she would have been covered, but since she was honest and admitted to being scammed she is getting punished?"
Re: My bank keeps on undermining anti-phishing education
#86Earlier quoted context omitted.
> My bank insists on exactly 6 numbers. Not characters, numbers. When I see this kind of thing I suspect that it's a web app that's simply a proxy for some mainframe screens that were written in the 1990s (or earlier).
I remember at least one major US bank saying that the reason they only allowed short passwords was indeed that it was the limit for login passwords on their mainframe. I was sure this was complete bullshit because even if everything is handled on the mainframe a user using their online banking would not be logging on to the mainframe. The online banking password is a credential for the bank's application(s) that run…
Where I work, usernames are still limited to 8 characters because some old unix platforms didn't support more than that. I'm virtually certain that none of those are still in use today, but the requirement was baked into user provisioning in ways that would be expensive to change, so they keep with it.
Re: My bank keeps on undermining anti-phishing education
#87I also had to deal with a medical device recall, which was terrible. I had to trust some skeezy domains.
This isn't hard to fix, all you need to do is list on your website your "partner domains."
My personal security protocol was to search a .gov website for contact info of financial institutions, go to the domain listed, look for a customer service number, and call that to find out what domains to trust. Customer service people thought I was weird.
At one point, a customer service person said, "you know it's legitimate because if you go to LinkedIn, you can see the person you're dealing with has listed as their employer."
Re: My bank keeps on undermining anti-phishing education
#88To verify your account during online customer service calls, Comcast will text you a six digit 2FA looking auth code which you must provide to the Comcast customer support. Guys.
Re: My bank keeps on undermining anti-phishing education
#89My bank used to call me with random marketing crap, and insisted on telling them my birthday and my mother's name before they can reveal their latest exclusive offer or some other crap. They were always dumbfounded when I retorted that it is them who need to prove that they're really calling from my bank first.