Live data from Hacker News

My bank keeps on undermining anti-phishing education

moritz-mander.de

231–240 of 267 posts

Re: My bank keeps on undermining anti-phishing education

#231
Something similar happened in Belgium in 2021. The Flemish government launched a compensation scheme for solar panel owners via a site called tellercompensatie.be. I registered the obvious typo variant: teller-compensatie.be right after the tv and radio announcements, added a visitor counter and a link to the real site. It got ~20k hits in a few days, my second most popular project thus far.

I just went to check the “official” domain and it looks like the domain is now owned by an ad network. Classic.

A news article link ( https://www.vrt.be/vrtnws/nl/2021/01/22/compensatieregeling-...) still ises that domain name in it’s article, but now redirects to a proper gov site: vlaanderen.be/veka

Re: My bank keeps on undermining anti-phishing education

#232
post #41

Earlier quoted context omitted.

The only time I ever triggered fraud detection system on my card I got a text message from bank that was "Your card is blocked due to suspicious usage, please call 'number'". And the number was also some random unlisted one. Only reason I didn't just ignore the thing is I did make a purchase on new website a half an hour before. Called my local bank and they confirmed this was legit, I almost went off on a full rant…

One of my former banks handled this pretty well. They called you and would say something like “there is an issue, but since you should never trust a direct phone call pretending to be your bank, please look up our number on our website and call us”. It’s kinda nice because while doing this, they also educate their customers to never trust such a call and to rely on official information to contact them.

Mine did the opposite for a while. In the event of an issue, they'd call, tell you that they were putting you on hold for a teller, and the first thing the teller did was identify the bank and ask for personal information to verify the account.

I always made a point of telling them that they had called me, that I had no proof of who they were, and that I was going to call back from the published number.

Re: My bank keeps on undermining anti-phishing education

#233

Earlier quoted context omitted.

Had something like this years ago when we were trying to get an EV code signing certificate from GoDaddy (for our Windows application). They wanted a government issued identification document with both photograph of the individual as well as their physical address on it. No such document exists for South Africans, I offered to get attestations from lawyers, police, but nothing was good enough. Then I had to threaten…

I have had nothing but trouble with GoDaddy and their ridiculous identification routines. We've spent hours with (allegedly) real humans who will tell us "ok I've released the domain for transfer. It will be clear in about 30 minutes" (or whatever it is at the time) and it never is, and then we have to start the entire process over with a new rep. There are other reasons to hate them too, but I won't go on a rant :-D

My initial philosophy with GoDaddy was "as long as it works, it's good enough".

But generally happy to not be using them these days. I do our domain registrations through Namecheap and can't say I've ever had an issue with them, also had to interact with support on occasion and also no negative experiences there.

Re: My bank keeps on undermining anti-phishing education

#234
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

The company we use for our yearly mandated training has a cybersecurity "class" which tells you not to click links in emails (which is good advice!). Three guesses on how you log in to the service.

Holy fuck this drives me insane. My company makes us do the idiotic trainings, which tell you all the "red flags" to look for.

Then the goddamn CEO sends out an empty email, with a .docx attachment, and the subject saying "urgent, open immediately" The HR sends out suspicious looking shit all the time. The. You have Microsoft spamming you with fucking QR codes!!!

You know what needs to happen? Disable all hyperlinks in email. Make everybody copy and paste the goddamn thing. Then they have to look at the link and they have to manually paste it into the browser. Then there are no obfuscated links. Also disable HTML email, images, and most file attachments. Then there is no pixel tracking, no possibility for malicious images to be auto-loaded, and no excuse for clicking a bad link.

Re: My bank keeps on undermining anti-phishing education

#235
I had similar with my energy provider in the UK (Octopus). For one reason or another a regular payment bounced which automatically puts you on a "call daily until the debt is repaid" list.

These calls come in on an unrecognised number, from staff who say "I don't know" when you ask them to prove they are from Octopus, and generate no call notes so you can't find out why they rang if you use the main customer service number.

To top it off they ask you to key in your card info on the phone after asking for your personal information.

I complained and they offered to fob me off with £30 credit instead of talking to their CISO, but they did at least say they can add phone passwords to individual accounts.

Re: My bank keeps on undermining anti-phishing education

#237
post #198
post #32

Earlier quoted context omitted.

Just piggybacking on this, if your bank (or eBay or Amazon or whoever) ever calls you to inform you of a suspected hack on your account, and says they're sending you a 2 factor authentication code to confirm your identity, do NOT tell them the code. It sounds obvious when phrased like this, but if you're not familiar with the scam then yeah, it's a scam and they're trying to get your 2FA token in order to access your…

> do NOT tell them the code When my father calls his bank, they actually verify him by sending a 2FA code to his email that he reads back.

At least he's doing so having called an already trusted number. But receiving a call from someone claiming to be your bank is a much more dangerous situation, despite it feeling similar to lay people. Banks should really train people to hang and call to their actual customer service.

Re: My bank keeps on undermining anti-phishing education

#238
post #91

Earlier quoted context omitted.

Oh, don't get me started on rubber stamps. I taught at a German university for a few years. And they way grades were handled was, you had to print a standardized piece of paper for every student with their name, date of examination, and grade, and drop them off at the secretary's office. The secretary would stamp every such Schein with a rubber stamp. Then the students would pick up their Scheine at the secretary's o…

> Probably the procedure had been followed since 1573, well before home printers, scanners, phone cameras, or get-your-own-rubber-stamp-for-a-few-bucks internet shops. This is almost always how these seemingly silly bureaucracy hoops become established. They were created in a prior time where a third party obtaining "magic item Y" with which to authenticate was significantly difficult to near impossible. Then, over t…

ARM had a huge headache when the CEO of their Chinese subsidiary stole the company seal and refused to give it back. That meant they effectively couldn't do business at all.

Re: My bank keeps on undermining anti-phishing education

#239
post #198

Earlier quoted context omitted.

> do NOT tell them the code When my father calls his bank, they actually verify him by sending a 2FA code to his email that he reads back.

At least he's doing so having called an already trusted number. But receiving a call from someone claiming to be your bank is a much more dangerous situation, despite it feeling similar to lay people. Banks should really train people to hang and call to their actual customer service.

A variation can be the scammer presents a fake number for you to call, via email, sms or worse through malicious ads that pop up when you google for the company phone number. Or, a phishing proxy like evilginx could overlay a “call [fake number] to unlock your account” as part of the login process.

Re: My bank keeps on undermining anti-phishing education

#240
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

More. I work with a bank that sends text messages asking if you issued a check for $x amount.

Problem is, one of the most common check frauds is check washing. The PTO line is changed to a fraudulent name, and the amount stays the same. So, yes, the amount matches a legitimate payment, but who was paid? Ha!

Post reply on HN