Earlier quoted context omitted.
What else are you supposed to do? All bank require BYC and will ask you to control your identity. We shouldn’t blame customers for the fintech company mistakes
Some banks, I assume, allow showing the documents in person and without a selfie.
Revolut confirms customer data breach through fake government requests
121–130 of 139 posts
Re: Revolut confirms customer data breach through fake government requests
#122Storing identification data (like a scanned passport) is not necessary. The question is “did you check the customer identity?” And if the answer is Yes, then you can mark it as such. You don’t need to store these scans at all.
Good thing there's, at least EU wide, EUDI (EU Digital Identity Wallet) around the corner which legally allows using cryptographic proofs instead of just storing as much data as possible of the user.
This addresses exactly this issue of having to disclose this amount of information solely as proof.
Re: Revolut confirms customer data breach through fake government requests
#123Re: Revolut confirms customer data breach through fake government requests
#124Earlier quoted context omitted.
My card issuer just gives me a credit when I want to chargeback. They're like, oh you don't want to deal with a real chargeback, just have your money back for free. I would've pressed it since I kinda wanted the company to regret ripping me off, but I already got my money back so it wasn't worth the extra effort.
That's how chargebacks often work. Then they ask the merchant for evidence the charge was legitimate. If convinced, they will retract that initial quick refund.
Re: Revolut confirms customer data breach through fake government requests
#125Earlier quoted context omitted.
You do not need to compromise anything, you can put any address in the "from" field. Email has no universal verification for sender address.
I would sincerely hope .gov addresses use SPF/DKIM/DMARC. That makes spoofing impossible. In Revolut's case, the sender's email system had been compromised.
Re: Revolut confirms customer data breach through fake government requests
#126Earlier quoted context omitted.
The government did request the data. And since the announcement, it has requested highly sensitive data again, and to keep such data, backed by threats of violent repercussions, that businesses cease to operate or to even exist. That's a dangerous kind of threat to be making, and to act upon. for information that should remain private let alone owned by the bank itself.
> The government did request the data. What's your source? That is not what the news says. Also, you know you can easily impersonate any email? That's a flaw of the email protocol.
So when a company is requested to hand over sensitive data, they do. For sure when the origin of the request is the government itself (pawned email in this case)
Re: Revolut confirms customer data breach through fake government requests
#127How can this happen to a modern fintech... Esp. handling identity verification so poorly? > A Revolut spokesperson confirmed to TechCrunch that a “limited” number of customers were impacted and said the company had contacted those customers directly. Revolut, however, did not disclose the exact number of impacted individuals. It also did not answer whether the incident was limited to a specific market and declined to…
But yeah there is always a downside when moving fast, oops
Re: Revolut confirms customer data breach through fake government requests
#128Even if the trigger was spoofed, how come there is no secure channel that the govt provides to receive the data? Was this one also compromised?
That may not matter that much, as even if you run a relatively strict policy about where you send the reply, you can still easily get bitten by external mistakes there: Because of the huge number of individually administered departments that might each become authorized recipient of such data, a malicious party only needs to find one suitably dangling DNS delegation to score a "…@attacker-controlled-subdomain.legitim…
It should be made impossible for someone at Revolut (and every other org) to deliver this data into the wrong hands by accident.
Re: Revolut confirms customer data breach through fake government requests
#129Earlier quoted context omitted.
>The implication that the solution to this is to somehow convince your direct competitors to do inferior in-person KYC for you is the most ridiculous thing. People work with their competitors all the time (see Netfix vs Amazon). Whats ridiculuous is the claim that a scammer would prefer to show up physically at a bank and risk being exposed instead of operating remotely. >leaking a selfie is pretty low down on the li…
No, it’s most certainly patently ridiculous. > Whats ridiculuous is the claim that a scammer would prefer to show up physically at a bank and risk being exposed instead of operating remotely. Of course they wouldn’t prefer to show physically. What does that mean though? Are you saying no scammers showed up physically to banks, therefore banking fraud rates are less? Do you have a source for that? > don't some of them…
Is your argument supposed to be more convincing because you added the word "patently"?
>What does that mean though?
It means that when you find a way to bypass purely online identity verification checks executing fraud at scale is easier than the physical alternative. As you would say, this is patently obvious.
Re: Revolut confirms customer data breach through fake government requests
#130Earlier quoted context omitted.
Some banks, I assume, allow showing the documents in person and without a selfie.
You assume wrong if you’re taking about old-school banks. They’ll still scan your id and it ends up in the same system
Also I am surprised people do not see the different between isolated internal "old school" systems built on owned servers located at the bank property and modern vibe-coded microservices in kubernetes in a rented cloud with the widest attack surface possible.