Earlier quoted context omitted.
Oh, don't get me started on rubber stamps. I taught at a German university for a few years. And they way grades were handled was, you had to print a standardized piece of paper for every student with their name, date of examination, and grade, and drop them off at the secretary's office. The secretary would stamp every such Schein with a rubber stamp. Then the students would pick up their Scheine at the secretary's o…
> Probably the procedure had been followed since 1573, well before home printers, scanners, phone cameras, or get-your-own-rubber-stamp-for-a-few-bucks internet shops. This is almost always how these seemingly silly bureaucracy hoops become established. They were created in a prior time where a third party obtaining "magic item Y" with which to authenticate was significantly difficult to near impossible. Then, over t…
My bank keeps on undermining anti-phishing education
101–110 of 267 posts
Re: My bank keeps on undermining anti-phishing education
#102Earlier quoted context omitted.
The only time I ever triggered fraud detection system on my card I got a text message from bank that was "Your card is blocked due to suspicious usage, please call 'number'". And the number was also some random unlisted one. Only reason I didn't just ignore the thing is I did make a purchase on new website a half an hour before. Called my local bank and they confirmed this was legit, I almost went off on a full rant…
One of my former banks handled this pretty well. They called you and would say something like “there is an issue, but since you should never trust a direct phone call pretending to be your bank, please look up our number on our website and call us”. It’s kinda nice because while doing this, they also educate their customers to never trust such a call and to rely on official information to contact them.
Re: My bank keeps on undermining anti-phishing education
#103Re: My bank keeps on undermining anti-phishing education
#104It seems to me the better and simpler solution is to continue teaching your users that this pattern this bank engages in is in fact still the pattern of hostile actors and let the bank deal with the consequences. The system will surely rectify itself eventually when their spammy, manipulative, promotional banker campaigns do not produce results (is that a bad thing?) and they seek out firms that do produce results ba…
Re: My bank keeps on undermining anti-phishing education
#105My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…
Yeah, I think they don't have any people working on the full UX flow, my bank does similarly weird stuff. The example that comes into mind is making transfers to my wife, where every time I do it, they ask me to confirm a bunch of questions to make sure it's not a scam/fraud, which fine, good idea. Once I confirm, they display another notice telling me they won't ask for a confirmation/2FA code because I make transfe…
I saw some bank from Florida, that I'd never heard of, calling me on my cell. I assumed it was some sort of scam and ignored it. They're too stupid to get a phone number which has caller id set up to read the name of credit union with whom I did business.
Just amazing.
Re: My bank keeps on undermining anti-phishing education
#106Earlier quoted context omitted.
Oh, don't get me started on rubber stamps. I taught at a German university for a few years. And they way grades were handled was, you had to print a standardized piece of paper for every student with their name, date of examination, and grade, and drop them off at the secretary's office. The secretary would stamp every such Schein with a rubber stamp. Then the students would pick up their Scheine at the secretary's o…
> Probably the procedure had been followed since 1573, well before home printers, scanners, phone cameras, or get-your-own-rubber-stamp-for-a-few-bucks internet shops. This is almost always how these seemingly silly bureaucracy hoops become established. They were created in a prior time where a third party obtaining "magic item Y" with which to authenticate was significantly difficult to near impossible. Then, over t…
When they could just cut out the middle man and just make fraud itself illegal and not require the magic item at all.
Re: My bank keeps on undermining anti-phishing education
#107My bank used to call me with random marketing crap, and insisted on telling them my birthday and my mother's name before they can reveal their latest exclusive offer or some other crap. They were always dumbfounded when I retorted that it is them who need to prove that they're really calling from my bank first.
Re: My bank keeps on undermining anti-phishing education
#108Earlier quoted context omitted.
Heh. 20 years ago when I was buying my house, I was arranging the mortgage through HSBC bank. One day I got a random call, started by asking me to confirm my name and date of birth. I asked them who they were, and they refused to say anything before going through security. I told them I wasn't giving them any personal details without knowing who they were, and they hung up. A week later, I phoned up the bank asking w…
Had the same thing happen with a debt collector. They would identify themselves, but seeing as their name was meaningless to me as we had no prior relationship, and even if I knew what they were calling about I had no debt I was aware of... They were a _little_ more cooperative about it though. "Hi this is from . Can I start by confirming your name and date of birth?" "Who is this?" " from . Can I start by confirming…
Spectrum did this to me. They sent a single "hey, you owe us for this thing" email before sending it to collections.
Re: My bank keeps on undermining anti-phishing education
#109- HTML emails where links and remote images obfuscate the 'real' content of the email.
- URLs which are not clearly and easily human-readable.
- A workflow where my normal and expected daily behavior is to receive valid emails that I don't recognizes with URLs from vendors, and then I'm meant to click on those URLs, go to web pages, and enter my credentials.
The fact that _any_ normal products or business processes expect this means phishing will always eventually succeed. No, I don't have all the UIs and URLs for every vendor memorized. I'd have no way to know if they changed validly, and my job trains me on a daily basis to click on emails and enter my credentials. It's just that _every so often_ this same scenario is set up by a bad actor.
Re: My bank keeps on undermining anti-phishing education
#110My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…
They could have published the procedures/numbers online. IME companies decided that publishing notices/articles on the web, setting up subdomains and modifying apps are expensive projects. That leaves only noreply@bank.com for communication.