Live data from Hacker News

My bank keeps on undermining anti-phishing education

moritz-mander.de

201–210 of 267 posts

Re: My bank keeps on undermining anti-phishing education

#201
post #130

My bank’s fraud department uses text shorthand like “Stop2end” and “call ph#” and their dates lack spaces “24Jun” in their texts to me. Is this some kind of meta-level play to sound less fake?

Text messages used to be limited in size to IIRC 140 characters. (And I still have that limit on my Garmin inReach--about an abysmal a texting device as you can get, but it works off Iridium, not the cell net. I can be on the back side of nowhere and still talk to emergency services.)

Re: My bank keeps on undermining anti-phishing education

#202

Earlier quoted context omitted.

> their fraud protection doesn't cover scams Eh?

One of Zelle's explicit design goals, couched in customer convenience, was as a mechanism to offload as much fraud liability onto the customer and away from the member banks.

It wasn't just the zelle they didn't cover. They are expecting her to pay back the $3k in airline tickets charged to her visa (not a debit card).

Re: My bank keeps on undermining anti-phishing education

#203
post #30

Some of the worst practices I've seen are from FedEx. When you order an international package, you get a text from some random FedEx employee's personal mobile number, containing a link to a website where you're meant to enter your credit card details to pay import duties. WTF? NO. I've called up about it and the support team were just like "ugh, yes, I know, yeah that's actually probably legit."

Hah what. I would never have thought those scam sms I get all the time to pay duty had no real world counterpart.

Like, companies are making it so easy for scammers to pretend to be them.

Re: My bank keeps on undermining anti-phishing education

#204
The one that kills me is when a financial institution or healthcare facility calls and says, "Hi, this is so-and-so from The Place. I was calling about your request/account/etc"

→ "Oh, ok"

→ "Before we get started, I need to verify your social security number/address/other personal information"

→ "Yeah, you called me and I have no way of knowing if you are who you say you are. I'm not going to give you that information. Can you give me your name, and I'll call the number on the website and ask for you?"

→ "Flabbergasted Well, our system doesn't work like that, so you'll have to submit another request"

→ Repeat ¯\_(ツ)_/¯

Re: My bank keeps on undermining anti-phishing education

#205

Earlier quoted context omitted.

Heh. 20 years ago when I was buying my house, I was arranging the mortgage through HSBC bank. One day I got a random call, started by asking me to confirm my name and date of birth. I asked them who they were, and they refused to say anything before going through security. I told them I wasn't giving them any personal details without knowing who they were, and they hung up. A week later, I phoned up the bank asking w…

> that was their procedure so it was my fault for not complying This is the most fascinating (infascinating? like, infamous/famous distinction? whatever) things about bureaucracies, to me: they sincerely expect everyone to follow their internal rules and procedures, even the people who are completely outside their jurisdiction by any stretch of imagination. Like, "we require the application of your personal seal to t…

If something goes wrong and you followed the procedure, the chances you're getting fired are very low. If something goes wrong and it is discovered you didn't follow the procedure, the chances of you being assigned the blame and fired are very high. It doesn't matter how stupid the procedure is or what's at stake - 99.999% of people you'd be dealing with do not care if the bank as a whole loses business or money, but care very much whether or not they are getting in trouble. Following the procedure is the easiest way of CYA.

Re: My bank keeps on undermining anti-phishing education

#206
post #24

I know this from sport events but often the lottery or prize draw are organised by external marketing companies. So likely this is one reason for not making it a subdomain. The other is that Germans seem very bad at this kind of stuff. Why the heck would the application for the German passport or Ausweis be published by some random GmbH and not Bundesregierung.gov?

But .gov are for American government sites, and Elon's friends (oh geez I loaded doge.gov, it looks so dodgy...), and I assume the assignment of the domain names under .gov is done by somebody in the federal government, if they haven't been DOGEed as well. If any country's government can get a .gov domain, I can imagine the hacking that could happen, similar to hackers managing to infiltrate Bangladesh's central bank…

From what I've seen, Austria also does this pretty well, with everything being on xyz.gov.at. The problem I see for germany is that the principle of subsidiarity is taken very seriously here. Everything is decided at the lowest sensible level of government. Consequently, there are many very tiny local authorities that have to manage things independently and lack IT admins.

Re: My bank keeps on undermining anti-phishing education

#207
post #195

When buying or selling a house, this can get really bad. You have all sorts of entities which extensions of other entities. The bank has a mortgage sector which uses a different domain. I also had to deal with a medical device recall, which was terrible. I had to trust some skeezy domains. This isn't hard to fix, all you need to do is list on your website your "partner domains." My personal security protocol was to s…

>When buying or selling a house, this can get really bad. You have all sorts of entities which extensions of other entities. The bank has a mortgage sector which uses a different domain Huh? I got my mortgage thru a mortgage broker and I only dealt with a single person.

I did the first time too, and he screwed us. We realized we could get a mortgage just fine without a broker.

Domain insanity aside, or course.

I have a strong anti-mortgage-broker bias. Mostly because of that one bad apple.

Re: My bank keeps on undermining anti-phishing education

#208

Earlier quoted context omitted.

Heh. 20 years ago when I was buying my house, I was arranging the mortgage through HSBC bank. One day I got a random call, started by asking me to confirm my name and date of birth. I asked them who they were, and they refused to say anything before going through security. I told them I wasn't giving them any personal details without knowing who they were, and they hung up. A week later, I phoned up the bank asking w…

Had the same thing happen with a debt collector. They would identify themselves, but seeing as their name was meaningless to me as we had no prior relationship, and even if I knew what they were calling about I had no debt I was aware of... They were a _little_ more cooperative about it though. "Hi this is from . Can I start by confirming your name and date of birth?" "Who is this?" " from . Can I start by confirming…

I assume collections pays (pennies on the dollar, but still >0) for each case, so being more thorough in verification of this literally costs them (the ISP) money. And, also, people who are being pissed off aren't clients anymore anyway. So of course they'd not do it.

Re: My bank keeps on undermining anti-phishing education

#210
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

It makes more sense when you realize it's an ass-covering exercise. Legitimate transaction blocked: "It's the user's fault for not calling the number, see, we called them and told them to call this number." Phishing: "It's the user's fault for calling the number, see, it says on our website you should never call any number." No matter what, it's always the user's fault for disobeying advice. A lot of things in our wo…

The whole concept of "identity theft" is this. Consider this: some dude D comes to bank B and says "I'm actually John Smith, given me $TONS of money". Bank gives the money and D disappears. Now B comes to actual John Smith and demands the money back. John is like "how it's my fricking fault that you gave your money to some random dude?!" And the bank pulls out the "identity theft" card out - you see, your "identity" got stolen, so now it's your fault for not guarding your "identity" properly, not ours! So now you should spend your time and money to fix it and we will treat you for years as a suspicious character, borderline criminal, for it. A very neat system.
Post reply on HN