Live data from Hacker News

My bank keeps on undermining anti-phishing education

moritz-mander.de

111–120 of 267 posts

Re: My bank keeps on undermining anti-phishing education

#111

My bank: “Hello this is your bank can I please confirm your personal details?”

i've gotten unsolicited calls like this before from my insurance company and when i tell them i don't provide personal information to people who just call me out of the blue and ask for it, they act like i'm from mars.

then of course i have to call them back, sit on hold (and maybe get the same call center agent!) to verify their identity and conduct whatever business they originally called about. thanks, your bad practice just cost me an afternoon to deal with the inefficiencies of a private industry i think shouldn't even exist.

Re: My bank keeps on undermining anti-phishing education

#112
post #41

Earlier quoted context omitted.

The only time I ever triggered fraud detection system on my card I got a text message from bank that was "Your card is blocked due to suspicious usage, please call 'number'". And the number was also some random unlisted one. Only reason I didn't just ignore the thing is I did make a purchase on new website a half an hour before. Called my local bank and they confirmed this was legit, I almost went off on a full rant…

One of my former banks handled this pretty well. They called you and would say something like “there is an issue, but since you should never trust a direct phone call pretending to be your bank, please look up our number on our website and call us”. It’s kinda nice because while doing this, they also educate their customers to never trust such a call and to rely on official information to contact them.

My credit union does the same but with "call the number on the back of your card". I suppose they have a lot of practice getting it right, given that their idea of a suspicious transaction is any transaction out of state.

Re: My bank keeps on undermining anti-phishing education

#113
post #46

Earlier quoted context omitted.

Not outright, but it's more likely that a malicious actor utilizes the simpler or cheaper solution. $300/yr+ adds up, especially if you need to go through due diligence to acquire the EV.

True - but if browsers don't show the EV cert until I click 3 buttons and my bank don't use one is there really a point?

From a customer & technical perspective, not really.

From a compliance, regulatory & risk perspective, definitely.

The EV certificate often comes with additional liability protection to cover any end customer claims related to certificate issues (i.e., if the authority is compromised and the customer's PII becomes exposed).

Re: My bank keeps on undermining anti-phishing education

#114
post #10

Do these banks not have insurance companies looking at this liability and saying "no you goddamned idiots, we are not covering you."

insurance companies operate the same way! customer service departments aren't a hotbed of security awareness (coming from personal experience - no sleight to CS reps in general; it's systemic as much as it is personal).

Re: My bank keeps on undermining anti-phishing education

#115

The naive people in decision-making positions often don't realize the risks involved in their behavior until they or someone near to them gets hurt -- in this case scammed or sued. We used to have a lot of people like this running businesses in the US before roughly 2012, but white (and black) hat hacking began spreading quickly and made generally short work of the problem.

I used to work for a financial services company that had a strong and well-managed security culture. The company got acquired, and afterwards, we kept getting emails from third parties for various things, all supposedly initiated by execs/groups at the parent company. We employees of the acquired company discussed the emails in Slack: we were sure that these emails were legitimate, but acting on them would have broke…

I had to fire the MSP I hired because they needed to install some software on everyone's computer, so they sent a company-wide email, with no clearance from anyone, directing approximately 40 people to open terminal and paste in a string sent in that email. Along with instructions on how to open terminal.

The absolute last thing anyone competent does is train employees to receive communications like that in email and follow them. If they'd asked for 3 minutes at an all hands to prep employees, or announced in slack, or something similar then ok. Or some out-of-band announcement that this was legit.

Re: My bank keeps on undermining anti-phishing education

#116
The US city I live in 9 months/year has a yearly burglar/fire alarm licence fee.

A few years ago, I got a postcard that said "renew your alarm licence on-line" and the domain wasn't the .ca.gov domain the city uses, but something like "alarm-renewal-online.info"

I had to spend 30 minutes on the phone with my city to verify that this was a legitimate way to renew the alarm. They had contracted with an outside company to do the payment servicing. In the end, I just decided to mail them a check.

Re: My bank keeps on undermining anti-phishing education

#117
post #4

User facing tech and marketing practices at banks are the worst. Every Indian bank login form I've ever had to use is - hostile to password managers. - You cannot copy paste passwords. - Client side password hashing - Stupid requirements like the password cannot have more than 15 characters and even have a whitelist of character sets! (Looking at you HDFC) - And of course, run of the mill spam They are all stuck in t…

> Client side password hashing

Forgive my ignorance, but what's wrong with this one?

Re: My bank keeps on undermining anti-phishing education

#118

Earlier quoted context omitted.

Heh. 20 years ago when I was buying my house, I was arranging the mortgage through HSBC bank. One day I got a random call, started by asking me to confirm my name and date of birth. I asked them who they were, and they refused to say anything before going through security. I told them I wasn't giving them any personal details without knowing who they were, and they hung up. A week later, I phoned up the bank asking w…

> that was their procedure so it was my fault for not complying This is the most fascinating (infascinating? like, infamous/famous distinction? whatever) things about bureaucracies, to me: they sincerely expect everyone to follow their internal rules and procedures, even the people who are completely outside their jurisdiction by any stretch of imagination. Like, "we require the application of your personal seal to t…

Had something like this years ago when we were trying to get an EV code signing certificate from GoDaddy (for our Windows application).

They wanted a government issued identification document with both photograph of the individual as well as their physical address on it.

No such document exists for South Africans, I offered to get attestations from lawyers, police, but nothing was good enough.

Then I had to threaten charging back the credit card to get a refund (as opposed to credit) on the not-insubstantial fee for a service that their verification policies made impossible to be fulfilled by South African entities.

We succeeded with DigiCert, was a bit involved including getting sign off by a certified security consultant that we had appropriate procedures in place to protect the private key, but eventually got through the process.

Re: My bank keeps on undermining anti-phishing education

#119
A friend told me about a company where the CISO instigated security newsletters aimed at staff to build up their experience on such topics, yet the newsletters were emailed from an external email and contained links to a hosting site that wasn't related to any of the employers regular website domains and like this case would often come across as a phishing attempt, especially when they ran competitions (apparently they appeared too good to be true, as friend's employer was famously tight!)
Post reply on HN