Live data from Hacker News

TeleSign profiles half of the world’s mobile phone users

noyb.eu

51–60 of 78 posts

Re: TeleSign profiles half of the world’s mobile phone users

#51
post #44

Earlier quoted context omitted.

No-one is actually breaking into a bank and stealing $$ from your account. Virtually most of the fraud is happening due to customer's own fault, not strictly bank's fault: 1. installed malware and got all saved CC data stolen 2. website you ordered your widgets got hacked and your CC stolen 3. clicked phish linked and lost your online bank credentials 4. got scammed and sent zelle to a scammer 5. used shady website t…

Now go and explain to anyone's grandmother how this list of items is her fault. Hard disagree on victim blaming being the answer. Sure all of us can learn to be more careful with tech, but the way banks frame fraud against them as identity theft against you is slimy doublespeak.

Answer is simple: if you cant use technology safely - dont use it! Problem is nobody is teaching effective fraud defense for consumers at scale.

Disable online banking, use checkbook and write checks everywhere or carry cash. I still see older people use checkbooks from time to time, even shopping groceries.

Problem solved.

We require drivers license to operate vehicle, it is time we should require infosec101 training before handing over credit cards and or online banking accounts.

So that you cannot blame the bank for your own fault.

Or migrate to something Apple Pay, but that also does not guarantee 100% fraud prevention

Re: TeleSign profiles half of the world’s mobile phone users

#52
post #30

I work in fraud prevention with vendors such as this. Let me be the devil's advocate here: trust and risk scores such as these are often very useful for identifying account takeovers and stolen identities in the financial and telecom worlds. We often see folks on HN complaining about how banks don't protect them from fraud losses - companies like this are how there is any hope left for some modicum of consumer protec…

Why not start by supporting webauthn (Yubikeys)?

How come all online VISA transactions don't have to completed through a redirect to visa.com or master.com (or may bank website), but instead we're typing card numbers into sketchy websites? (I guess EU 2FA requirements are pushing the boundary, but very slowly and often in ways that still appear remarkably sketchy).

Trust scores of IPs and phones numbers is a tool, but when physically hardened security tokens aren't widely supported, I'd argue the essential tools simply aren't available to users.

Re: TeleSign profiles half of the world’s mobile phone users

#53
post #51

Earlier quoted context omitted.

Now go and explain to anyone's grandmother how this list of items is her fault. Hard disagree on victim blaming being the answer. Sure all of us can learn to be more careful with tech, but the way banks frame fraud against them as identity theft against you is slimy doublespeak.

Answer is simple: if you cant use technology safely - dont use it! Problem is nobody is teaching effective fraud defense for consumers at scale. Disable online banking, use checkbook and write checks everywhere or carry cash. I still see older people use checkbooks from time to time, even shopping groceries. Problem solved. We require drivers license to operate vehicle, it is time we should require infosec101 trainin…

So you are advocating for the vast majority of the internet population to stop using online banking.

Let's flip the omelette: no one forces banks to do business online; if a bank can't build secure online banking, they can default to checkbooks and cash. They have the means and motive to build solutions that are actually secure and usable, so they should bear the burden of dealing with fraud when their solutions fail to be secure.

Re: TeleSign profiles half of the world’s mobile phone users

#54
post #51

Earlier quoted context omitted.

Now go and explain to anyone's grandmother how this list of items is her fault. Hard disagree on victim blaming being the answer. Sure all of us can learn to be more careful with tech, but the way banks frame fraud against them as identity theft against you is slimy doublespeak.

Answer is simple: if you cant use technology safely - dont use it! Problem is nobody is teaching effective fraud defense for consumers at scale. Disable online banking, use checkbook and write checks everywhere or carry cash. I still see older people use checkbooks from time to time, even shopping groceries. Problem solved. We require drivers license to operate vehicle, it is time we should require infosec101 trainin…

Oh if the world could just be so simple. Can't protect yourself from getting mugged, stop going outside. Problem solved.

The reality of any non-trivial issue is that we have to consider potential improvements from all angles. I want to improve tech for grandma and for the bank, doesn't that seem like a goal worth working towards? And let's please not pretend that banks are infallible in all of this, they also have opportunities to improve.

Re: TeleSign profiles half of the world’s mobile phone users

#55
post #53
post #51

Earlier quoted context omitted.

Answer is simple: if you cant use technology safely - dont use it! Problem is nobody is teaching effective fraud defense for consumers at scale. Disable online banking, use checkbook and write checks everywhere or carry cash. I still see older people use checkbooks from time to time, even shopping groceries. Problem solved. We require drivers license to operate vehicle, it is time we should require infosec101 trainin…

So you are advocating for the vast majority of the internet population to stop using online banking. Let's flip the omelette: no one forces banks to do business online; if a bank can't build secure online banking, they can default to checkbooks and cash. They have the means and motive to build solutions that are actually secure and usable, so they should bear the burden of dealing with fraud when their solutions fail…

Most of the online banks are pretty secure for non-oblivious person.

I always used online banking and never got scammed. It is pretty secure for me.

Combination of user & password with enough entropy, and basic brute-force defense that blocks after 3-4 attempts is the industry minimum standard.

User is the weakest link always, you cannot fix the "stupid" user that downloads malware, warez, adult content and gets infected and loses everything.

These people need life lesson to learn how to operate technology safely.

Although I agree that online banking could be made more secure, but the threat model will immediately evolve and adapt because scammers/fraudsters are still there and they want to eat.

Re: TeleSign profiles half of the world’s mobile phone users

#56
post #12
post #11

Earlier quoted context omitted.

Does the full name have to be your legal name? I use different names/email on every site, but phone numbers are always these 2~3 numbers. If I'm going to send a deletion request under GDPR alike laws, it would be under different names.

> Does the full name have to be your legal name? Pretty much. Only your person has rights, not the fake identities you created. They can actually request a copy of an ID or something comparable to confirm your identity. You might have a hard time removing your data, in some cases, when using fake names since then your identity can't be confirmed.

> Only your person has rights, not the fake identities you created.

But if they only know u/lucb1e to own +31612345678, then it's all good and well that you're requesting data as Luc Lastname but that's not going to match their records anyway; that doesn't prove you're the legitimate person to send this data to.

> They can actually request a copy of an ID or something comparable to confirm your identity.

When I called the Dutch DPA about this, specifically about MAC address tracking (I got an email "welcome to ikea!", sent to anothercompany@lucb1e.com, when I connected to ikea's free wifi), and they said that supplying the MAC address is the identifier to use because that's the only thing they can match anyway. This was in 2018-ish so I may misremember details, to be fair.

As far as I know, this is similar to copyright under a pseudonym. If you can't prove it's yours, sucks, but if you can, then your rights are yours to exercise.

Re: TeleSign profiles half of the world’s mobile phone users

#57
post #51

Earlier quoted context omitted.

Answer is simple: if you cant use technology safely - dont use it! Problem is nobody is teaching effective fraud defense for consumers at scale. Disable online banking, use checkbook and write checks everywhere or carry cash. I still see older people use checkbooks from time to time, even shopping groceries. Problem solved. We require drivers license to operate vehicle, it is time we should require infosec101 trainin…

Oh if the world could just be so simple. Can't protect yourself from getting mugged, stop going outside. Problem solved. The reality of any non-trivial issue is that we have to consider potential improvements from all angles. I want to improve tech for grandma and for the bank, doesn't that seem like a goal worth working towards? And let's please not pretend that banks are infallible in all of this, they also have op…

the actual protection from getting mugged is moving to a safe neighbourhood.

People must adapt, because it is unreasonable to expect the world to adapt to the most naiive user. You either will get mugged every day, or you learn your lesson and move out to safe neighborhood, or you buy a gun and solve mugging problem for everybody else one shot at a time.

same with fraud - user will continue getting defrauded and scammed until user learns the lesson and either abandons tech he.she is unable to use securely, or adapt and learn how to use it

Re: TeleSign profiles half of the world’s mobile phone users

#58
post #57

Earlier quoted context omitted.

Oh if the world could just be so simple. Can't protect yourself from getting mugged, stop going outside. Problem solved. The reality of any non-trivial issue is that we have to consider potential improvements from all angles. I want to improve tech for grandma and for the bank, doesn't that seem like a goal worth working towards? And let's please not pretend that banks are infallible in all of this, they also have op…

the actual protection from getting mugged is moving to a safe neighbourhood. People must adapt, because it is unreasonable to expect the world to adapt to the most naiive user. You either will get mugged every day, or you learn your lesson and move out to safe neighborhood, or you buy a gun and solve mugging problem for everybody else one shot at a time. same with fraud - user will continue getting defrauded and scam…

> the actual protection from getting mugged is moving to a safe neighbourhood. People must adapt, because it is unreasonable to expect the world to adapt to the most naiive user. You either will get mugged every day, or you learn your lesson and move out to safe neighborhood, or you buy a gun and solve mugging problem for everybody else one shot at a time.

It's almost cute how you think people living in places with high crime rates wouldn't jump at the chance to move to a nicer neighborhood with lower crime rates, and that the reason they don't is because they haven't "learned their lesson".

Everyone buying guns and then going around shooting criminals is not a solution to crime, but if you're convinced it's a good idea, why not try it for yourself and "learn your lesson"

Re: TeleSign profiles half of the world’s mobile phone users

#59
post #57

Earlier quoted context omitted.

the actual protection from getting mugged is moving to a safe neighbourhood. People must adapt, because it is unreasonable to expect the world to adapt to the most naiive user. You either will get mugged every day, or you learn your lesson and move out to safe neighborhood, or you buy a gun and solve mugging problem for everybody else one shot at a time. same with fraud - user will continue getting defrauded and scam…

> the actual protection from getting mugged is moving to a safe neighbourhood. People must adapt, because it is unreasonable to expect the world to adapt to the most naiive user. You either will get mugged every day, or you learn your lesson and move out to safe neighborhood, or you buy a gun and solve mugging problem for everybody else one shot at a time. It's almost cute how you think people living in places with h…

Everybody makes tradeoffs, if you cant move out - you cope.

I grew up in high crime third world country and all young with half a brain folks emigrated as soon as they could.

The rest had to adapt and cope, due to different life choices and trade offs.

Yes you can blame the government for being unable to fix high crime, and sit helplessly while waiting for the same government to fix the problem.

Or you can get matter in your own hands and solve it the way you can.

Fraud problem cannot be attributed to banks 100%, given that users are at fault

Re: TeleSign profiles half of the world’s mobile phone users

#60
post #30

I work in fraud prevention with vendors such as this. Let me be the devil's advocate here: trust and risk scores such as these are often very useful for identifying account takeovers and stolen identities in the financial and telecom worlds. We often see folks on HN complaining about how banks don't protect them from fraud losses - companies like this are how there is any hope left for some modicum of consumer protec…

>Let me be the devil's advocate here:

The question here isn't (primarily at least) whether this is a good or bad thing, the important question is if this arrangement is legal under EU law. It can be the most beneficial thing in the world and still be illegal.

Post reply on HN