Live data from Hacker News

Citibank India wants credit card, bank account numbers to stop marketing emails

online.citibank.co.in

51–60 of 89 posts

Re: Citibank India wants credit card, bank account numbers to stop marketing emails

#51
post #45

Earlier quoted context omitted.

Banks should send ZERO emails, period. It's not secure for that. I do sometimes get emails from them but they're "useless" (usually a simple notification) Several banks have their own message box inside of Internet Banking.

Email is the only universally-accepted federated notification system. Emails such as "your card has been used 1000km+ from its last use" or "you just made this >$1000 purchase" are very useful indeed, and should be encouraged to detect fraud.

For small notifications (let's say a $50 purchase) I get an SMS

If it's something that rings a bell the bank calls me

Re: Citibank India wants credit card, bank account numbers to stop marketing emails

#52
post #23

Earlier quoted context omitted.

I don't think that's a smart move. Let's give them some benefit of doubt and bring this to their attention. I have messaged them on their facebook. Hope this will help. P.S. I am not a Citibank fan or something. Just trying to deal with this sanely.

I'm just talking about reporting it validly as spam. This poisons the IP blocks they use to send SPAM from as the IP addresses get recognized as consistent sources of SPAM. Certain mass-email marketing firms like MailChimp tout their "respectable email server IP addresses" as a feature. Yep, IP-blocks have reps, good and bad.

[deleted]

Re: Citibank India wants credit card, bank account numbers to stop marketing emails

#55
Citibank is one of the worst banks I've dealt with.

Once, one of their affiliate's employees offered me a Credit Card for free and said "it had no strings attached" and I don't need to do anything to keep it alive. Thought it sounded too good to be true, I bit the bullet and signed up, right on the spot, their affiliate clothing store. Before I was about to submit my documents, it was then I happened to meet a friend by chance and he told me that I would need to purchase a minimum X amount each year mandatorily through the "free" card, failing which I would be levied drastic charges.

Shocked, I asked the affiliate's employee if it was true and he confirmed the same. I politely declined, got my papers from him, and scored the entire application paper off diagonally so that no sane company would accept it as a valid application.

However, the very next day, I get a call from one of Citibank's employees asking me to submit a photograph so that he could forward the application. I was shocked and I asked him how it was even possible to submit a scored out application. Even though I scored off the application, I hadn't scored off my other copies of proof (Driving license, etc). So the rep had cleverly filled out a fresh form just like I would have and even signed where I should have (!) and forwarded the application to the card processing department. I know this because the rep who called told me that the only thing he needed was a passport size photograph and everything else was pucca.

Shocked, I told him that I don't need the card and asked him to stop bugging me. I got routine calls from the same rep for about 3 days and also continuous text messages asking me to submit just the photograph. Heck he would have come to even my house (the address was on the proof I submitted) , he was THAT desperate.

It was then I decided that I would never ever deal with a shady company like Citibank, ever again.

So, I'm not surprised that they are actually so intrusive to even have you unsubscribe from their site. This bank is full of shit.

Re: Citibank India wants credit card, bank account numbers to stop marketing emails

#56
post #29
post #24

This is a phishing attack waiting to happen! I never worked at a bank but I'm assuming (maybe I shouldn't) that there are a few people working there that know a thing or two about security. I doubt that any person who claims to be a "security expert" would have let this go by, but I always seemed to be proven wrong. Take for example TDBank in Canada who has a 80's password policy: Passwords must: - be 5 to 8 characte…

Or the classic bank telephones you and asks to verify your identity by answering your secret questions and answers. facepalm

My bank (NatWest, terrible) told me to never give my information to anyone who calls me and asks for it. Every time they ring they then ask me for my details for 'security purposes'.

Then again, that seems mild now that I've found out they don't keep auditing logs of the changes their employees make to customers' accounts.

There are also lots of cases of online banking being compromised by really basic attacks (such as a CSRF attack that could be used to transfer money to an account of the attacker's choosing).

Banks aren't actually that secure. They merely spend a lot of time engaging in very expensive hand-wavey security theatre to convince us that they are secure - not to mention using expensive laywers and unfair libel law (I am in the UK) to shut up security researchers that find problems. The reason that they are so frequently observed acting contrary to best security practices is because they are not actually particularly good at security.

Re: Citibank India wants credit card, bank account numbers to stop marketing emails

#57
post #18

Getting increasingly harder to unsubscribe. - Some big vendors (Dell, HP?) don't seem to use unified opt-out lists or they use agencies that don't share unsubscribes - Unsub pages with complicated unsub process (double-negative questions, button size tricks e.g. 'submit' is small and 'continue' is large) - Unsub pages requiring input of your email address on a form without the email address pre-populated (so you have…

There are two modes of marketing mail I've seen increase massively over the last year or two (note: completely subjective 'study' based on my own inbox):

1) "Screw your choices" spam - despite figuring out the Mensa-challenge-esque puzzle of which checkboxes to check or uncheck, when signing up for a new account the company opts you in to marketing emails anyway.

2) "Blast from the past" - a I used to use years ago has decided to add every single email address they've ever seen to their mailing list, and I'm suddenly seeing emails from them. To me this looks a lot like the desperate throes of a dying company - I believe Yahoo pulled this at some point this year. Amusing variation: My sole contact with one company was a complaint email, which they did not reply to. Two years later they started sending me marketing emails. No, thank you.

When it comes to unsubscribing there's another trick I've seen on the rise, other than the ones you already listed: An unsubscribe process that takes weeks. The page says something like "You will be unsubscribed within 28 days" and you keep getting spam in the meantime. I believe at least some of Yahoo's services do this, too? There are two main variations for this one: companies that do actually remove you after 28 days, and companies that don't (I assume it's just a distraction tactic and they hope you'll forget).

Re: Citibank India wants credit card, bank account numbers to stop marketing emails

#59
post #18

Getting increasingly harder to unsubscribe. - Some big vendors (Dell, HP?) don't seem to use unified opt-out lists or they use agencies that don't share unsubscribes - Unsub pages with complicated unsub process (double-negative questions, button size tricks e.g. 'submit' is small and 'continue' is large) - Unsub pages requiring input of your email address on a form without the email address pre-populated (so you have…

I particularly like the unsubscribe pages that have broken email validation. Sign up for a service with me+service@gmail.com just fine, but the unsubscribe page won't accept the '+'.

Or the ones that require you to sign in update your spam preferences.

Ugh.

Re: Citibank India wants credit card, bank account numbers to stop marketing emails

#60
post #56
post #29

Earlier quoted context omitted.

Or the classic bank telephones you and asks to verify your identity by answering your secret questions and answers. facepalm

My bank (NatWest, terrible) told me to never give my information to anyone who calls me and asks for it. Every time they ring they then ask me for my details for 'security purposes'. Then again, that seems mild now that I've found out they don't keep auditing logs of the changes their employees make to customers' accounts. There are also lots of cases of online banking being compromised by really basic attacks (such…

Banks aren't actually that secure.

Financial services generally aren't in the business of security. They're in the business of risk management. Once you understand that distinction, much of what they do makes sense.

Unfortunately, some unhappy conclusions for the customers of these services do logically follow, starting with the fact that if you're not a huge customer, the financial services have little natural incentive to care about the safety of any assets/investments they handle for you. If something very bad happens, you might be an acceptable loss relative to the cost of mitigation, right up to the point of fighting you in court and then losing anyway. You personally might suffer greatly for any losses, and even if it's ultimately put right you might suffer months or years being dragged through the system, but no employee at any financial service is personally going to lose any sleep over your case.

This is why it is necessary to have regulators with teeth in financial industries. Any lapse that could cause significant harm to a customer should also potentially cause significant harm to the financial service. An ongoing pattern of such lapses should cause severe damage to the service's bottom line and eventually it should become an existential threat to the financial service itself, preferably with safeguards to ensure that the management and/or shareholders can't just escape using the technicalities of incorporation. Without this sort of counter-balance, the numbers will always be in favour of trampling on the little guy, and if there's one industry that runs on the numbers more than anything else, it's financial services.

Post reply on HN