Live data from Hacker News

My bank keeps on undermining anti-phishing education

moritz-mander.de

121–130 of 267 posts

Re: My bank keeps on undermining anti-phishing education

#121

My bank has implemented suggestions I've given them in the past (USAA), but recently they used a different domain for a legitimate-seeming email (the email was about something I just did, and it was to an address I only use with that bank ), and I called them up and spoke with someone in their fraud department to ask about it. I told them either they were hacked, or they were training their customers to fall for phis…

I interviewed for a software engineering position at USAA. After seeing the incompetence of the interviewers none of the nonsense they do surprises me.

Re: My bank keeps on undermining anti-phishing education

#122
post #91

Earlier quoted context omitted.

> Probably the procedure had been followed since 1573, well before home printers, scanners, phone cameras, or get-your-own-rubber-stamp-for-a-few-bucks internet shops. This is almost always how these seemingly silly bureaucracy hoops become established. They were created in a prior time where a third party obtaining "magic item Y" with which to authenticate was significantly difficult to near impossible. Then, over t…

I recently joined a very old company, with many lifers, I continuously run into this mentality. “I can’t explain it now, but I’m sure there was a good reason for it, so we’re gonna continue doing it this way”

Of course it is typically wise to consider Chesterton's fence.

Re: My bank keeps on undermining anti-phishing education

#123

Earlier quoted context omitted.

Ye they don't follow their own rules. Once my bank called me for a insurance change I requested a month or so earlier and asked me to verify myself via the security dongle. Like, and then they act surprised when people are scammed.

Heh. 20 years ago when I was buying my house, I was arranging the mortgage through HSBC bank. One day I got a random call, started by asking me to confirm my name and date of birth. I asked them who they were, and they refused to say anything before going through security. I told them I wasn't giving them any personal details without knowing who they were, and they hung up. A week later, I phoned up the bank asking w…

HSBC had famously terrible systems when I dealt with them for a mortgage years ago - they were so bad that the staff I spoke with pre-briefed me on the range of issues their website could suffer from.

The best was that certain sections were circular, so it would start to ask the same questions again but displaying answers prefilled in - yet it would arbitrarily forget particular (different) details on each loop, defaulting to values other than what you'd entered before, so there were only certain points you should exit the loop at, to be sure it would submit the right information!

On the plus side, despite their system woes, they had very competitive rates, so it was definitely financially worth spending another 20 minutes and accepting their idiocy!

Re: My bank keeps on undermining anti-phishing education

#124
post #10

Do these banks not have insurance companies looking at this liability and saying "no you goddamned idiots, we are not covering you."

The bank doesn't take the loss, the customer does.

Mitchell and Webb has a good commedy skit on this subject: https://www.youtube.com/watch?v=CS9ptA3Ya9E

Re: My bank keeps on undermining anti-phishing education

#125
post #91

Earlier quoted context omitted.

> Probably the procedure had been followed since 1573, well before home printers, scanners, phone cameras, or get-your-own-rubber-stamp-for-a-few-bucks internet shops. This is almost always how these seemingly silly bureaucracy hoops become established. They were created in a prior time where a third party obtaining "magic item Y" with which to authenticate was significantly difficult to near impossible. Then, over t…

I recently joined a very old company, with many lifers, I continuously run into this mentality. “I can’t explain it now, but I’m sure there was a good reason for it, so we’re gonna continue doing it this way”

The real issue is that most business just don't document anything to do with their processes. Chance are that there are a hand full of things that there are a good reason for doing and they do need to be done that way. Except the people that identified that original problem and came up with original solution have all left the company so now there is nobody around that has put in the effort (or been given the time to investigate) to figure out why things are done the way they are, and the last time one of the things that had been done forever was suddenly stopped it caused untold amount of chaos so now the directive is to just keep doing everything we've always done.

Re: My bank keeps on undermining anti-phishing education

#126
post #91

Earlier quoted context omitted.

> Probably the procedure had been followed since 1573, well before home printers, scanners, phone cameras, or get-your-own-rubber-stamp-for-a-few-bucks internet shops. This is almost always how these seemingly silly bureaucracy hoops become established. They were created in a prior time where a third party obtaining "magic item Y" with which to authenticate was significantly difficult to near impossible. Then, over t…

I recently joined a very old company, with many lifers, I continuously run into this mentality. “I can’t explain it now, but I’m sure there was a good reason for it, so we’re gonna continue doing it this way”

Per Chesterton's Fence, isn't this the right course of action for any individual who is unsure of why the practice was started?

https://www.lesswrong.com/w/chesterton-s-fence

Re: My bank keeps on undermining anti-phishing education

#127
post #60

I use USAA for banking. Something they do when they initiate a call to me on the phone is they start by making sure they are talking to me (they don’t ask me to prove it) and making sure I have the app on the my phone or access to a web page. Then they initiate a MFA check within the app. I have to get it and read back a number. Then they ask me for my phone PIN or password. Once that’s done, then we can start talkin…

That's really not safe...

Re: My bank keeps on undermining anti-phishing education

#128
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

It's fun when you phone the bank's regular number, waiting hours to get someone on the phone, and they say that number isn't legitimate when it actually is. Even better when it's a bank you don't use and the number on their site goes to an automated system that won't let you access it without an account number, so you have to scrounge for alternative phone numbers to get to talk to someone.

last digit +/- [1-9] usually isn't a bad place to start for larger institutions

Re: My bank keeps on undermining anti-phishing education

#129
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

The company we use for our yearly mandated training has a cybersecurity "class" which tells you not to click links in emails (which is good advice!). Three guesses on how you log in to the service.

My bank tells me via email to not click on links in emails and to directly visit their homepage instead. That's fine, but that email itself contains a link to their fraud prevention page (to learn more) and another link to log into their online banking service.

Do as I say, not as I do.

Post reply on HN