Live data from Hacker News

My bank keeps on undermining anti-phishing education

moritz-mander.de

261–267 of 267 posts

Re: My bank keeps on undermining anti-phishing education

#261
post #210

Earlier quoted context omitted.

It makes more sense when you realize it's an ass-covering exercise. Legitimate transaction blocked: "It's the user's fault for not calling the number, see, we called them and told them to call this number." Phishing: "It's the user's fault for calling the number, see, it says on our website you should never call any number." No matter what, it's always the user's fault for disobeying advice. A lot of things in our wo…

The whole concept of "identity theft" is this. Consider this: some dude D comes to bank B and says "I'm actually John Smith, given me $TONS of money". Bank gives the money and D disappears. Now B comes to actual John Smith and demands the money back. John is like "how it's my fricking fault that you gave your money to some random dude?!" And the bank pulls out the "identity theft" card out - you see, your "identity"…

I had a paper check stolen in the early 1990s. A Walmart accepted the check without its even being signed. So I reported it.

I cannot write a check at Walmart today. Not that I would; it’s antiquated even by US standards to do so. It’s that they fucked up and blame me, 30+ years later.

Re: My bank keeps on undermining anti-phishing education

#262

My bank used to call me with random marketing crap, and insisted on telling them my birthday and my mother's name before they can reveal their latest exclusive offer or some other crap. They were always dumbfounded when I retorted that it is them who need to prove that they're really calling from my bank first.

Between '06 and '19 I was a client of bank that proudly bear the title of "pioneer of online banking" here and tbh, they actually were. You won't met anybody in Poland who wouldn't have contact with that brand one way or another.

I opted-out for all marketing purposes once they allowed to do so but yet, I was getting random calls from bank and 3rd parties. One day I called them because I had login issues on Windows Phone. I did mention to consultant that I was getting these calls and in return lady hit me with quite a revelation: they had a single opt-out that was only available if you called them.

Re: My bank keeps on undermining anti-phishing education

#263

Earlier quoted context omitted.

> Sure, but I still think this is preferable to sending the password in clear text even over HTTPS. You're trusting the server doesn't do anything with the password My point is in both cases the server has access to the password. As I mentioned, without salt the server can get the original password (by checking the pre-computed rainbow table of hashes up to n length), so the trust issue is the same. If this is slight…

Well no, because rainbow tables are quite small. You don't have precomputed hashes for all passwords 24 characters and under that contain numbers and symbols. I mean, even with just letters, you're looking at 620448401733239439360000 hashes required. x 128 / 8 bytes, you're looking at ~ 9000 zettabytes. So, a few order of magnitude larger than the entire internet. If you have a strong password, it's not comparable. I…

Very interesting point. I did not think of that, thanks. I was looking at the speed of calculation in different scenarios (calculated on the fly)based on which characters are part of the password and it is still very difficult, if you have a strong password. I am curious which percentage one could match just checking for hashes of common passwords, or common patterns like exclamation marks at the end. In any case it is better than the unhashed version, I agree.

PS Sorry punctuation, mobile phone.

Re: My bank keeps on undermining anti-phishing education

#264
post #131

Earlier quoted context omitted.

My bank eventually understood this, which is why currently you can check in the app whether on their end they're seeing that you're talking with their sales rep and which one specifically.

Forcing you to use the app isn't the best solution. I bet they only have apps for just two mobile OSes, don't they?

Why yes. Also, rooting is out of the question. The way out appears to be carrying two phones, but that's not practical.

Re: My bank keeps on undermining anti-phishing education

#265
post #24

I know this from sport events but often the lottery or prize draw are organised by external marketing companies. So likely this is one reason for not making it a subdomain. The other is that Germans seem very bad at this kind of stuff. Why the heck would the application for the German passport or Ausweis be published by some random GmbH and not Bundesregierung.gov?

But .gov are for American government sites, and Elon's friends (oh geez I loaded doge.gov, it looks so dodgy...), and I assume the assignment of the domain names under .gov is done by somebody in the federal government, if they haven't been DOGEed as well. If any country's government can get a .gov domain, I can imagine the hacking that could happen, similar to hackers managing to infiltrate Bangladesh's central bank…

Majority of countries around the world uses .gov top domain along with country code to provide government services to their citizens.

Re: My bank keeps on undermining anti-phishing education

#266

I see Conway's Law at work here. The marketing department must have its own IT department separate from the IT that maintains the core website and business functions. It's impossible for them to get on the same web domain (much less build something in the phone apps). Instead, they built their own disparate site and experience.

It gets worse. These German "Sparkassen" are small to at most medium sized credit unions. They are organised in a larger umbrella organisation that takes care of some of the services like IT, but the individual banks can pick and choose what and how much they want to handle themselves. Some of them are larger and pretty well organised, but there are also a lot of small ones that just don't have the people and experti…

I had a similar thought, but I suspect that this campaign is run by the umbrella organization
Post reply on HN