Live data from Hacker News

My bank keeps on undermining anti-phishing education

moritz-mander.de

101–110 of 267 posts

Re: My bank keeps on undermining anti-phishing education

#101
post #91

Earlier quoted context omitted.

Oh, don't get me started on rubber stamps. I taught at a German university for a few years. And they way grades were handled was, you had to print a standardized piece of paper for every student with their name, date of examination, and grade, and drop them off at the secretary's office. The secretary would stamp every such Schein with a rubber stamp. Then the students would pick up their Scheine at the secretary's o…

> Probably the procedure had been followed since 1573, well before home printers, scanners, phone cameras, or get-your-own-rubber-stamp-for-a-few-bucks internet shops. This is almost always how these seemingly silly bureaucracy hoops become established. They were created in a prior time where a third party obtaining "magic item Y" with which to authenticate was significantly difficult to near impossible. Then, over t…

I recently joined a very old company, with many lifers, I continuously run into this mentality. “I can’t explain it now, but I’m sure there was a good reason for it, so we’re gonna continue doing it this way”

Re: My bank keeps on undermining anti-phishing education

#102
post #41

Earlier quoted context omitted.

The only time I ever triggered fraud detection system on my card I got a text message from bank that was "Your card is blocked due to suspicious usage, please call 'number'". And the number was also some random unlisted one. Only reason I didn't just ignore the thing is I did make a purchase on new website a half an hour before. Called my local bank and they confirmed this was legit, I almost went off on a full rant…

One of my former banks handled this pretty well. They called you and would say something like “there is an issue, but since you should never trust a direct phone call pretending to be your bank, please look up our number on our website and call us”. It’s kinda nice because while doing this, they also educate their customers to never trust such a call and to rely on official information to contact them.

That is a great demonstration of best practices. What bank was that?

Re: My bank keeps on undermining anti-phishing education

#103
I left Chase because their anti-fraud detection was so suspicious that Chase's own customer service told me it was fraud and had me close my checking account in the middle of a vacation. Only later I put together it was legitimate fraud detectiontriggering on an unexpected transaction location.

Re: My bank keeps on undermining anti-phishing education

#104

It seems to me the better and simpler solution is to continue teaching your users that this pattern this bank engages in is in fact still the pattern of hostile actors and let the bank deal with the consequences. The system will surely rectify itself eventually when their spammy, manipulative, promotional banker campaigns do not produce results (is that a bad thing?) and they seek out firms that do produce results ba…

I don't think that everything needs to be a sales pitch all the time. But I am curious, what kind of service do you see promotable in the article?

Re: My bank keeps on undermining anti-phishing education

#105
post #100
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

Yeah, I think they don't have any people working on the full UX flow, my bank does similarly weird stuff. The example that comes into mind is making transfers to my wife, where every time I do it, they ask me to confirm a bunch of questions to make sure it's not a scam/fraud, which fine, good idea. Once I confirm, they display another notice telling me they won't ask for a confirmation/2FA code because I make transfe…

The idiots at my former credit union apparently subcontract out their credit cards to some east coast bank, whereas my bank and I live on the west coast.

I saw some bank from Florida, that I'd never heard of, calling me on my cell. I assumed it was some sort of scam and ignored it. They're too stupid to get a phone number which has caller id set up to read the name of credit union with whom I did business.

Just amazing.

Re: My bank keeps on undermining anti-phishing education

#106
post #91

Earlier quoted context omitted.

Oh, don't get me started on rubber stamps. I taught at a German university for a few years. And they way grades were handled was, you had to print a standardized piece of paper for every student with their name, date of examination, and grade, and drop them off at the secretary's office. The secretary would stamp every such Schein with a rubber stamp. Then the students would pick up their Scheine at the secretary's o…

> Probably the procedure had been followed since 1573, well before home printers, scanners, phone cameras, or get-your-own-rubber-stamp-for-a-few-bucks internet shops. This is almost always how these seemingly silly bureaucracy hoops become established. They were created in a prior time where a third party obtaining "magic item Y" with which to authenticate was significantly difficult to near impossible. Then, over t…

The extension to that is making it illegal to own/buy/use 'magic item Y', on the basis it enables fraud.

When they could just cut out the middle man and just make fraud itself illegal and not require the magic item at all.

Re: My bank keeps on undermining anti-phishing education

#107

My bank used to call me with random marketing crap, and insisted on telling them my birthday and my mother's name before they can reveal their latest exclusive offer or some other crap. They were always dumbfounded when I retorted that it is them who need to prove that they're really calling from my bank first.

When a random call asks me to confirm some information, I always reply that I'm not going to share any personal information because I have no idea who they are. Half the time, they just hang up, the other half of the time they launch into the sales pitch.

Re: My bank keeps on undermining anti-phishing education

#108

Earlier quoted context omitted.

Heh. 20 years ago when I was buying my house, I was arranging the mortgage through HSBC bank. One day I got a random call, started by asking me to confirm my name and date of birth. I asked them who they were, and they refused to say anything before going through security. I told them I wasn't giving them any personal details without knowing who they were, and they hung up. A week later, I phoned up the bank asking w…

Had the same thing happen with a debt collector. They would identify themselves, but seeing as their name was meaningless to me as we had no prior relationship, and even if I knew what they were calling about I had no debt I was aware of... They were a _little_ more cooperative about it though. "Hi this is from . Can I start by confirming your name and date of birth?" "Who is this?" " from . Can I start by confirming…

> Turns out the ISP did their usual ISP thing and failed to mark that I'd returned my modem when cancelling service a few months prior then told no one and sent it to collections.

Spectrum did this to me. They sent a single "hey, you owe us for this thing" email before sending it to collections.

Re: My bank keeps on undermining anti-phishing education

#109
Phising and phishing education are inherently misguided. If my normal workflow includes much the following, then phishing will always eventually succeed:

- HTML emails where links and remote images obfuscate the 'real' content of the email.

- URLs which are not clearly and easily human-readable.

- A workflow where my normal and expected daily behavior is to receive valid emails that I don't recognizes with URLs from vendors, and then I'm meant to click on those URLs, go to web pages, and enter my credentials.

The fact that _any_ normal products or business processes expect this means phishing will always eventually succeed. No, I don't have all the UIs and URLs for every vendor memorized. I'd have no way to know if they changed validly, and my job trains me on a daily basis to click on emails and enter my credentials. It's just that _every so often_ this same scenario is set up by a bad actor.

Re: My bank keeps on undermining anti-phishing education

#110
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

They could have published the procedures/numbers online. IME companies decided that publishing notices/articles on the web, setting up subdomains and modifying apps are expensive projects. That leaves only noreply@bank.com for communication.

It could also be misguided security guidelines – because of things like caller id spoofing where scammers would spoof one of their actual numbers to lull people into a false sense of security
Post reply on HN