Live data from Hacker News

My bank keeps on undermining anti-phishing education

moritz-mander.de

221–230 of 267 posts

Re: My bank keeps on undermining anti-phishing education

#221
post #78

My bank replaced their phone authentication with something that asks you to speak a phrase (the same one every time) and tries to recognise your voice. Luckily that's completely bulletproof, there's no way it can be forged :-/

I read the FAQ on mine and it assures me it is totally safe and the voice cannot be forged. This mechanism was defeated in a hacker movie from the early 90s using a tape recorder but is actually being pushed as state of the art. I can't imagine how this method could ever be safe, even if it were possible to use some kind of advanced detection which would fail any time I had a cold my voice can be recorded and played…

>This mechanism was defeated in a hacker movie from the early 90s

Sneakers (1992)[0]

[0] https://en.wikipedia.org/wiki/Sneakers_(1992_film)

Re: My bank keeps on undermining anti-phishing education

#222

Earlier quoted context omitted.

Heh. 20 years ago when I was buying my house, I was arranging the mortgage through HSBC bank. One day I got a random call, started by asking me to confirm my name and date of birth. I asked them who they were, and they refused to say anything before going through security. I told them I wasn't giving them any personal details without knowing who they were, and they hung up. A week later, I phoned up the bank asking w…

HSBC had famously terrible systems when I dealt with them for a mortgage years ago - they were so bad that the staff I spoke with pre-briefed me on the range of issues their website could suffer from. The best was that certain sections were circular, so it would start to ask the same questions again but displaying answers prefilled in - yet it would arbitrarily forget particular (different) details on each loop, defa…

This wasn't so much a competitive rate, but I literally couldn't have afforded to buy this house if they didn't offer a 105% mortgage - so no deposit and some extra money so I could buy some furniture. To be fair, I had some deposit so didn't really need all the extra 5%, but I wasn't anywhere close to the 10% deposit that was standard at the time.

Also, now I remember that I also had to jump through some deceptive hoops. The deal was technically only available on the graduate account, which my account had stopped being earlier in the year because it changed to a regular account after 10 years from opening. The bank manager said she'd bend the rules and let me have the deal as an exception, but then presented me with a load of life insurance policies to sign (which of course I didn't want or need) and it was strongly intimated that if I didn't sign them, she'd no longer bother bending the rules to get me the mortgage deal. So, I signed them, and as soon as I had the mortgage confirmation letter through the post I phoned up to cancel before the end of the 14 day cooling off period. I dread to think how much commission she'd have made from me if I didn't cancel.

Re: My bank keeps on undermining anti-phishing education

#224

Earlier quoted context omitted.

Not a bank, but Apple Mail inline displays PDFs. I've been getting these PayPal Bitcoin scam emails lately and checking from Apple Mail they look legitimate. Problem is, I don't have a PayPal account... In Gmail or Thunderbird they don't just show the PDF and since they display the sender differently it makes it obviously a scam. Sometimes it feels like companies are just helping scammers and I don't know why.

> Sometimes it feels like companies are just helping scammers and I don't know why. There's a lot of similarities to scamming and marketing. In particular, they both have essentially the same desire for well-designed messages.

True, but I find that highly problematic.

It's not a good system if it's hard to differentiate. We should be encouraging making money by providing meaningful value to the people buying the product. To get those things aligned. I think we engineers can play a role too. While not having the ultimate decision I think speaking up and just pushing here and there to prioritize product quality over profits goes a long way. In the long run, I think quality and profits are usually aligned, though I think rarely in the short term

Re: My bank keeps on undermining anti-phishing education

#225

I left Chase because their anti-fraud detection was so suspicious that Chase's own customer service told me it was fraud and had me close my checking account in the middle of a vacation. Only later I put together it was legitimate fraud detectiontriggering on an unexpected transaction location.

I called the number on the back of my Chase credit card (which goes to a call center in what sounds like India), and the person told me he has to verify me by hanging up, and then not to call anyone because he will call back in a few minutes... (Probably while he's on a "bathroom break" running to the scam center on the next floor of the same building.) All the other times, they just ask for my verbal password to ver…

[dead]

Re: My bank keeps on undermining anti-phishing education

#227
post #76

Earlier quoted context omitted.

> My bank insists on exactly 6 numbers. Not characters, numbers. When I see this kind of thing I suspect that it's a web app that's simply a proxy for some mainframe screens that were written in the 1990s (or earlier).

I remember at least one major US bank saying that the reason they only allowed short passwords was indeed that it was the limit for login passwords on their mainframe. I was sure this was complete bullshit because even if everything is handled on the mainframe a user using their online banking would not be logging on to the mainframe. The online banking password is a credential for the bank's application(s) that run…

My hunch is that the idea that some banks have a mainframe user account per bank customer is a red herring, and that the real answer is that the customers are indeed in a separate database table. But that database is a mainframe database, and the field is a fixed width that maybe could be changed but the mainframe admins see no reason to.

Re: My bank keeps on undermining anti-phishing education

#228
post #41
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

The only time I ever triggered fraud detection system on my card I got a text message from bank that was "Your card is blocked due to suspicious usage, please call 'number'". And the number was also some random unlisted one. Only reason I didn't just ignore the thing is I did make a purchase on new website a half an hour before. Called my local bank and they confirmed this was legit, I almost went off on a full rant…

[deleted]

Re: My bank keeps on undermining anti-phishing education

#229

Here is american Express "secure email" documentation : https://www.americanexpress.com/us/customer-service/secure-e... I've mistakenly deleted from our mail quarantine multiple times as spam/phishing. Imho it's wilful négligence toynkeep such a system operating in 2025.

I love how even in their own screenshot, their app only has a 1 star rating on the App Store.

Re: My bank keeps on undermining anti-phishing education

#230
post #130

My bank’s fraud department uses text shorthand like “Stop2end” and “call ph#” and their dates lack spaces “24Jun” in their texts to me. Is this some kind of meta-level play to sound less fake?

Text messages used to be limited in size to IIRC 140 characters. (And I still have that limit on my Garmin inReach--about an abysmal a texting device as you can get, but it works off Iridium, not the cell net. I can be on the back side of nowhere and still talk to emergency services.)

SMS is limited to 140 characters, but there has been a standard to send multiple messages in a row and have the receiving phone concatenate them automatically since about the year 2000. For older devices that that don't support it, they will get multiple messages and just show it as "(1/2)" etc (I had a Panasonic phone that didn't support it during the transition so I remember it well)
Post reply on HN