Live data from Hacker News

My bank keeps on undermining anti-phishing education

moritz-mander.de

141–150 of 267 posts

Re: My bank keeps on undermining anti-phishing education

#141
post #41
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

The only time I ever triggered fraud detection system on my card I got a text message from bank that was "Your card is blocked due to suspicious usage, please call 'number'". And the number was also some random unlisted one. Only reason I didn't just ignore the thing is I did make a purchase on new website a half an hour before. Called my local bank and they confirmed this was legit, I almost went off on a full rant…

I've had the version of that where I called my bank's listed number to confirm the incoming "call us on this number" voicemail was legit, and they said NO, the call is not a legit number of theirs, the account looks fine, I was right to check, and they agreed it seemed like a scam call.

A few days later I found out the call really was from the bank, and the bank had blocked my account, in a way that took a long time to unblock (don't get me started...). As ever, I found out the hard way, when I needed to use the account for something in real-time and it wasn't available.

But the call was from a different department than general customer support, the department's number wasn't known to customer service, and the account status change wasn't visible to customer service either.

So the bank's own customer service thought it was a scam call!

Re: My bank keeps on undermining anti-phishing education

#142

I left Chase because their anti-fraud detection was so suspicious that Chase's own customer service told me it was fraud and had me close my checking account in the middle of a vacation. Only later I put together it was legitimate fraud detectiontriggering on an unexpected transaction location.

I called the number on the back of my Chase credit card (which goes to a call center in what sounds like India), and the person told me he has to verify me by hanging up, and then not to call anyone because he will call back in a few minutes... (Probably while he's on a "bathroom break" running to the scam center on the next floor of the same building.)

All the other times, they just ask for my verbal password to verify me.

I reported it and they said they created a ticket, but a month later when I called for a follow-up on the ticket, they said they had no idea what I was talking about :-/

(If anyone from Chase reads this, I have the recordings of those calls if you want them.)

Re: My bank keeps on undermining anti-phishing education

#143

Earlier quoted context omitted.

> that was their procedure so it was my fault for not complying This is the most fascinating (infascinating? like, infamous/famous distinction? whatever) things about bureaucracies, to me: they sincerely expect everyone to follow their internal rules and procedures, even the people who are completely outside their jurisdiction by any stretch of imagination. Like, "we require the application of your personal seal to t…

Had something like this years ago when we were trying to get an EV code signing certificate from GoDaddy (for our Windows application). They wanted a government issued identification document with both photograph of the individual as well as their physical address on it. No such document exists for South Africans, I offered to get attestations from lawyers, police, but nothing was good enough. Then I had to threaten…

I have had nothing but trouble with GoDaddy and their ridiculous identification routines. We've spent hours with (allegedly) real humans who will tell us "ok I've released the domain for transfer. It will be clear in about 30 minutes" (or whatever it is at the time) and it never is, and then we have to start the entire process over with a new rep. There are other reasons to hate them too, but I won't go on a rant :-D

Re: My bank keeps on undermining anti-phishing education

#144

Earlier quoted context omitted.

I recently joined a very old company, with many lifers, I continuously run into this mentality. “I can’t explain it now, but I’m sure there was a good reason for it, so we’re gonna continue doing it this way”

Per Chesterton's Fence, isn't this the right course of action for any individual who is unsure of why the practice was started? https://www.lesswrong.com/w/chesterton-s-fence

I like that fence, but I consider the best course of action to be going and finding out why the thing is done the eay it is, even if it necessitates careful investigation.

Re: My bank keeps on undermining anti-phishing education

#145

Earlier quoted context omitted.

One of my former banks handled this pretty well. They called you and would say something like “there is an issue, but since you should never trust a direct phone call pretending to be your bank, please look up our number on our website and call us”. It’s kinda nice because while doing this, they also educate their customers to never trust such a call and to rely on official information to contact them.

That is a great demonstration of best practices. What bank was that?

It's also a great filter for the scammers. The people who are non-gullible or medium-gullible will follow. The truly gullible will say "What is the web address?" To which they respond "citibank-support.blogspot.com"

Re: My bank keeps on undermining anti-phishing education

#146

When buying or selling a house, this can get really bad. You have all sorts of entities which extensions of other entities. The bank has a mortgage sector which uses a different domain. I also had to deal with a medical device recall, which was terrible. I had to trust some skeezy domains. This isn't hard to fix, all you need to do is list on your website your "partner domains." My personal security protocol was to s…

> At one point, a customer service person said, "you know it's legitimate because if you go to LinkedIn, you can see the person you're dealing with has listed as their employer."

"Yeah? Give me two minutes, and mine will say the same. So, will you give me your personal info?"

Re: My bank keeps on undermining anti-phishing education

#147

The US city I live in 9 months/year has a yearly burglar/fire alarm licence fee. A few years ago, I got a postcard that said "renew your alarm licence on-line" and the domain wasn't the .ca.gov domain the city uses, but something like "alarm-renewal-online.info" I had to spend 30 minutes on the phone with my city to verify that this was a legitimate way to renew the alarm. They had contracted with an outside company…

At least when my local government outsource their alarm permitting, they linked to the .com from their .gov website.

Re: My bank keeps on undermining anti-phishing education

#148

The naive people in decision-making positions often don't realize the risks involved in their behavior until they or someone near to them gets hurt -- in this case scammed or sued. We used to have a lot of people like this running businesses in the US before roughly 2012, but white (and black) hat hacking began spreading quickly and made generally short work of the problem.

I also suspect that the social dynamics of these kinds of organizations make it difficult for the right people for making these kinds of decisions to rise to the right positions for making them. There's almost a catch-22: setting good, effective policies tends to involve a lot of telling people "no". And it's hideously difficult to do that without ruffling the feathers of people who control promotions.

"Let me explain why that would be a career-limiting mistake for you..."

Re: My bank keeps on undermining anti-phishing education

#149
post #121

Earlier quoted context omitted.

I interviewed for a software engineering position at USAA. After seeing the incompetence of the interviewers none of the nonsense they do surprises me.

I worked in IT ops there for a long time, and since then have seen the inner workings of companies in several different fields. They had by far the most competent cybersecurity group I've witnessed. Things have changed in a decade maybe. But, they still use proprietary TOTP from Symantec which is annoying.

Yeah I've never worked there, but been a customer since 2005. For many years there, USAA was really cutting edge of tech and highly competent. The system has slowly gotten a little less usable though, but at least it still works most of the time

Re: My bank keeps on undermining anti-phishing education

#150
post #131

My bank used to call me with random marketing crap, and insisted on telling them my birthday and my mother's name before they can reveal their latest exclusive offer or some other crap. They were always dumbfounded when I retorted that it is them who need to prove that they're really calling from my bank first.

My bank eventually understood this, which is why currently you can check in the app whether on their end they're seeing that you're talking with their sales rep and which one specifically.

Forcing you to use the app isn't the best solution. I bet they only have apps for just two mobile OSes, don't they?
Post reply on HN