Live data from Hacker News

My bank keeps on undermining anti-phishing education

moritz-mander.de

11–20 of 267 posts

Re: My bank keeps on undermining anti-phishing education

#12
post #4

User facing tech and marketing practices at banks are the worst. Every Indian bank login form I've ever had to use is - hostile to password managers. - You cannot copy paste passwords. - Client side password hashing - Stupid requirements like the password cannot have more than 15 characters and even have a whitelist of character sets! (Looking at you HDFC) - And of course, run of the mill spam They are all stuck in t…

Indian banks and their websites are likely among the worst in the world. The fact that many situations require printing forms, dealing with SMS-based 2FA, multiple passwords, sometimes with different requirements… I’m not surprised that many Indians still prefer the hassle of visiting a branch.

Re: My bank keeps on undermining anti-phishing education

#13
post #4

User facing tech and marketing practices at banks are the worst. Every Indian bank login form I've ever had to use is - hostile to password managers. - You cannot copy paste passwords. - Client side password hashing - Stupid requirements like the password cannot have more than 15 characters and even have a whitelist of character sets! (Looking at you HDFC) - And of course, run of the mill spam They are all stuck in t…

> cannot have more than 15 characters

That's something! My bank insists on exactly 6 numbers. Not characters, numbers.

They're also hostile to password managers and don't allow copy/paste. You have to click on the numbers with your mouse.

"My security" is very important to them, so they've moved 2nd factor from a physical fob, to an app tied to my phone, and now they've improved it further by switching to sms!

Now, this isn't some neighborhood mom 'n'pop bank, but the biggest or second-biggest bank in France.

Re: My bank keeps on undermining anti-phishing education

#16
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

Ye they don't follow their own rules. Once my bank called me for a insurance change I requested a month or so earlier and asked me to verify myself via the security dongle. Like, and then they act surprised when people are scammed.

Re: My bank keeps on undermining anti-phishing education

#17
post #4

User facing tech and marketing practices at banks are the worst. Every Indian bank login form I've ever had to use is - hostile to password managers. - You cannot copy paste passwords. - Client side password hashing - Stupid requirements like the password cannot have more than 15 characters and even have a whitelist of character sets! (Looking at you HDFC) - And of course, run of the mill spam They are all stuck in t…

Indian banks and their websites are likely among the worst in the world. The fact that many situations require printing forms, dealing with SMS-based 2FA, multiple passwords, sometimes with different requirements… I’m not surprised that many Indians still prefer the hassle of visiting a branch.

I assure you, dealing with the staff at the bank is different ball game altogether.

I had to write 3 different "letters" (paper pen) to have a phone number typo (on their part) corrected.

Re: My bank keeps on undermining anti-phishing education

#18
post #10

Do these banks not have insurance companies looking at this liability and saying "no you goddamned idiots, we are not covering you."

My mom was recently phished. The scammer got into her bank accounts and charged a bunch of air india tickets to her credit card and used zelle to transfer money out. When we reported it to the bank they said it wasn't covered because their fraud protection doesn't cover scams. So the banks just don't care. (It was Capital One FYI)

Re: My bank keeps on undermining anti-phishing education

#19
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

The company we use for our yearly mandated training has a cybersecurity "class" which tells you not to click links in emails (which is good advice!).

Three guesses on how you log in to the service.

Re: My bank keeps on undermining anti-phishing education

#20
> “Here is your Sparkasse. A very important document is waiting for your signature. Please visit paperless.io/548fkjgd7f to continue.”

I mean this is just ... incredible. Are they living on the moon? Many real phishing messages are even more sophisticated than this.

Post reply on HN