Live data from Hacker News

My bank keeps on undermining anti-phishing education

moritz-mander.de

171–180 of 267 posts

Re: My bank keeps on undermining anti-phishing education

#171

Earlier quoted context omitted.

There’s no other way to do it. Not all banks expose an API.

> There’s no other way to do it. Don't they allow you to manually enter the bank routing number and account number, then verify it by depositing and withdrawing a few cents?

That’s just account verification. ACH has some really antiquated practices on purpose that make the system more robust than a naive automated banking system and less robust than a comprehensive one.

I own a business that works directly in this space.

Re: My bank keeps on undermining anti-phishing education

#172

Earlier quoted context omitted.

SG?

BNP. I used to have an account with Boursorama (which belongs to SG) and they also had the point-and-click number thing, but I think the code was a bit longer.

SG is also exactly six, with a randomized on-screen keyboard.

It's a French thing.

Re: My bank keeps on undermining anti-phishing education

#173
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

Not a bank, but Apple Mail inline displays PDFs. I've been getting these PayPal Bitcoin scam emails lately and checking from Apple Mail they look legitimate. Problem is, I don't have a PayPal account...

In Gmail or Thunderbird they don't just show the PDF and since they display the sender differently it makes it obviously a scam.

Sometimes it feels like companies are just helping scammers and I don't know why.

Re: My bank keeps on undermining anti-phishing education

#174
post #100
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

Yeah, I think they don't have any people working on the full UX flow, my bank does similarly weird stuff. The example that comes into mind is making transfers to my wife, where every time I do it, they ask me to confirm a bunch of questions to make sure it's not a scam/fraud, which fine, good idea. Once I confirm, they display another notice telling me they won't ask for a confirmation/2FA code because I make transfe…

  > I think they don't have any people working on the full UX flow
Probably right, but this is the importance of dogfooding. I really think this stuff happens because everyone is in such a rush and doesn't take a few minutes to think things though, which requires thinking about everything as a whole.

Re: My bank keeps on undermining anti-phishing education

#175
post #169
post #105

Earlier quoted context omitted.

The idiots at my former credit union apparently subcontract out their credit cards to some east coast bank, whereas my bank and I live on the west coast. I saw some bank from Florida, that I'd never heard of, calling me on my cell. I assumed it was some sort of scam and ignored it. They're too stupid to get a phone number which has caller id set up to read the name of credit union with whom I did business. Just amazi…

Well, afaik caller id is actually unauthenticated and can be trivially impersonated.

You are missing the point. He (hopefully) won't trust the callerID to be the bank, but he will trust a "random" callerID to not be his bank/important.

Re: My bank keeps on undermining anti-phishing education

#176

Earlier quoted context omitted.

> that was their procedure so it was my fault for not complying This is the most fascinating (infascinating? like, infamous/famous distinction? whatever) things about bureaucracies, to me: they sincerely expect everyone to follow their internal rules and procedures, even the people who are completely outside their jurisdiction by any stretch of imagination. Like, "we require the application of your personal seal to t…

Oh, don't get me started on rubber stamps. I taught at a German university for a few years. And they way grades were handled was, you had to print a standardized piece of paper for every student with their name, date of examination, and grade, and drop them off at the secretary's office. The secretary would stamp every such Schein with a rubber stamp. Then the students would pick up their Scheine at the secretary's o…

Of course, the rubber stamp was just the university logo with something like the faculty name next to it. Trivial to copy (or make a rubber stamp for more enterprising students).

My entire career is predicted on the things I did with a stack of university letterhead 40 years ago.

Re: My bank keeps on undermining anti-phishing education

#177
post #60

I use USAA for banking. Something they do when they initiate a call to me on the phone is they start by making sure they are talking to me (they don’t ask me to prove it) and making sure I have the app on the my phone or access to a web page. Then they initiate a MFA check within the app. I have to get it and read back a number. Then they ask me for my phone PIN or password. Once that’s done, then we can start talkin…

That is a really bad idea. That's letting anyone who phones you prove to the bank that they are you. You should only reveal an MFA code to someone that you have called, knowing that it is the right person.

Walk me through the chain you’re thinking of. I want to understand it better.

If you’re thinking that - for example - someone is attempting to log into my account online and simultaneously call me pretending to be the bank. They are presented with an MFA check and tell me they initiated it. I give it to them unwittingly, and note they are in.

My understanding is that isn’t possible here, because this “MFA check” is different than the login one. The login one is the “Google Authenticator, 6 numbers”. This is a different code entirely. Obviously I didn’t specify that in the original post. My bad.

If that wasn’t what you were thinking and you can think of how this fails, I need to know and learn more!

Re: My bank keeps on undermining anti-phishing education

#178
My employer regularly sends out phishing honey pot emails. Which is great but they then will send out legitimate emails which are genuinely difficult to separate from actual phishing (using novel new email addresses and domain names in links). They also like to use some email filtering which has a habit of mutilating URLs.

Re: My bank keeps on undermining anti-phishing education

#179

My bank used to call me with random marketing crap, and insisted on telling them my birthday and my mother's name before they can reveal their latest exclusive offer or some other crap. They were always dumbfounded when I retorted that it is them who need to prove that they're really calling from my bank first.

I have this happen all the time in healthcare. I had someone from a specialist office call me and immediately ask me for my date of birth. Their surprise when I said no was incredible. But I agree with you, if THEY are the ones calling, they need to prove their identity.

Re: My bank keeps on undermining anti-phishing education

#180
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

It makes more sense when you realize it's an ass-covering exercise. Legitimate transaction blocked: "It's the user's fault for not calling the number, see, we called them and told them to call this number." Phishing: "It's the user's fault for calling the number, see, it says on our website you should never call any number." No matter what, it's always the user's fault for disobeying advice. A lot of things in our world are like this.
Post reply on HN