I work in fraud prevention with vendors such as this. Let me be the devil's advocate here: trust and risk scores such as these are often very useful for identifying account takeovers and stolen identities in the financial and telecom worlds. We often see folks on HN complaining about how banks don't protect them from fraud losses - companies like this are how there is any hope left for some modicum of consumer protec…
Why not start by supporting webauthn (Yubikeys)? How come all online VISA transactions don't have to completed through a redirect to visa.com or master.com (or may bank website), but instead we're typing card numbers into sketchy websites? (I guess EU 2FA requirements are pushing the boundary, but very slowly and often in ways that still appear remarkably sketchy). Trust scores of IPs and phones numbers is a tool, bu…
TeleSign profiles half of the world’s mobile phone users
61–70 of 78 posts
Re: TeleSign profiles half of the world’s mobile phone users
#62I work in fraud prevention with vendors such as this. Let me be the devil's advocate here: trust and risk scores such as these are often very useful for identifying account takeovers and stolen identities in the financial and telecom worlds. We often see folks on HN complaining about how banks don't protect them from fraud losses - companies like this are how there is any hope left for some modicum of consumer protec…
Re: TeleSign profiles half of the world’s mobile phone users
#63Earlier quoted context omitted.
> They're already doing something (invisible as it may be). They can definitely do a better job. But without companies such as Telesign, fraud losses would far, far worse. Until banks accept that they got defrauded, not you, whatever they do will be too little.
No-one is actually breaking into a bank and stealing $$ from your account. Virtually most of the fraud is happening due to customer's own fault, not strictly bank's fault: 1. installed malware and got all saved CC data stolen 2. website you ordered your widgets got hacked and your CC stolen 3. clicked phish linked and lost your online bank credentials 4. got scammed and sent zelle to a scammer 5. used shady website t…
2. That is not the customers fault. Full stop. Yes, some sites are more shady than others, but there is nothing a consumer can do to determine if a service provider will get hacked.
3. Yes. Unfortunately, phishing is really easy. Despite the prevalence of this attack, training users to effectively detect and avoid being a victim is almost impossible.
4. See #3.
5. See #2.
6. How is a customer supposed to validate the security of an ATM against modern skimming technology, many of which are virtually indistinguishable from normal bank machines.
7. Yep, not great. Why don't banks require 2FA? Because it creates friction and increases costs. Better to just externalize the risk.
Your entire blame the user argument is bunk that has been packaged up and recirculated by the finance community for almost 20 years (and I have been using these arguments against them for nearly that long, granted it's close to ~12 years since I worked in infosec at a bank).
Re: TeleSign profiles half of the world’s mobile phone users
#64Earlier quoted context omitted.
these are the (not so) digital equivalent to what appeared in phone book anyway. Then, your phone number and emails are in any of your resumes, business card, subscription forms, contact details for any web service... They're not exactly private information anyway And I'm sure anyone can call your phone number and listen to the message of the voicemail, in which most ppl say their name out loud anyway. Lastly, isn't…
> isn't your email address firstname.lastname@gmail.com, as for most folks I'm going to guess that for 'most folks' there's probably someone else with the same name and therefore this way of guessing someone's email address is far from reliable. It's actually so unreliable that one email address I have receives mail for others who for some reason think it's their email. This includes plane tickets, accounts for phone…
Ask me about the Brazilian teenager with my name who keeps using my email to open facebook accounts that I keep recovering the password for and closing.
Re: TeleSign profiles half of the world’s mobile phone users
#65Earlier quoted context omitted.
Now go and explain to anyone's grandmother how this list of items is her fault. Hard disagree on victim blaming being the answer. Sure all of us can learn to be more careful with tech, but the way banks frame fraud against them as identity theft against you is slimy doublespeak.
Answer is simple: if you cant use technology safely - dont use it! Problem is nobody is teaching effective fraud defense for consumers at scale. Disable online banking, use checkbook and write checks everywhere or carry cash. I still see older people use checkbooks from time to time, even shopping groceries. Problem solved. We require drivers license to operate vehicle, it is time we should require infosec101 trainin…
Sure. Why not start with an outline for what infosec101 should look like. Include estimates for how long the training should take, what the cadence for testing should be, and which agency should be responsible for validating that training. Do be sure to accurately communicate the degree to which an end user with a chip enabled bank or credit card has the ability to distinguish and disambiguate what constitutes a 'safe' or 'legitimate' online business. Also, include some details about how individuals who have been certified as completing this class and/or licensing scheme should procure insurance to protect themselves in case of an accidental data breach (for example, they leak their card info), and outline the process by which that same licensee can file an insurance claim against the insured party downstream of the physical point of payment or online payment portal that allowed a breach to happen. After all - if we are going to require online safety training, and licensing, then we should create another insurance scheme to facilitate resolution of those claims and resolve the costs.
It is really easy to point the fingers at a customer and say "problem exists between chair and keyboard", but the reality is that in the modern economy, the end user has almost no control over the security of their transactions, and little ability to influence how their purchase is handled beyond the question of "cash or card".
The only incentive that retailers, online stores, payment processors, and financial institutions have to resolve this is the simple fact that they own the liability for this, and it's only through the myth of the idiot user that they have been able to shift that liability, to varying degrees, back to the consumer.
Re: TeleSign profiles half of the world’s mobile phone users
#66Earlier quoted context omitted.
Why not start by supporting webauthn (Yubikeys)? How come all online VISA transactions don't have to completed through a redirect to visa.com or master.com (or may bank website), but instead we're typing card numbers into sketchy websites? (I guess EU 2FA requirements are pushing the boundary, but very slowly and often in ways that still appear remarkably sketchy). Trust scores of IPs and phones numbers is a tool, bu…
It would be trivial for sketchy websites to have fake (but real looking) "official" Visa/MC forms, or even for multiple fake "official" sites to be set up. So redirecting everyone to the One True Payment System is no solution to fraudulent websites.
Re: TeleSign profiles half of the world’s mobile phone users
#67I work in fraud prevention with vendors such as this. Let me be the devil's advocate here: trust and risk scores such as these are often very useful for identifying account takeovers and stolen identities in the financial and telecom worlds. We often see folks on HN complaining about how banks don't protect them from fraud losses - companies like this are how there is any hope left for some modicum of consumer protec…
What I want to know is how "the regularity of completed calls, call duration, long-term inactivity, range activity, or successful incoming traffic" translates to a trust score. Do less trustworthy people tend to make longer or shorter phone calls than more trustworthy people? And what even is range activity, not to mention how does it relate to trustworthiness?
1. The former is likely using a throwaway phone number, the latter is using an established phone number. You can tell the difference with the number of completed calls over time, call duration etc. Burner phones will have bursts of high intensity activity to several different phone numbers whereas legitimate phones will have lots of successfully completed phone calls over a long period of time to repeating phone numbers.
2. The former will likely place calls all over the country or world as they attempt to raid several bank accounts digitally. The latter will probably have more local calls since they're calling their doctors, schools, etc. This is probably where range activity plays a role.
I'm not defending Telesign or how they collect data - I'm merely saying this data has value in account protection.
Re: TeleSign profiles half of the world’s mobile phone users
#68I work in fraud prevention with vendors such as this. Let me be the devil's advocate here: trust and risk scores such as these are often very useful for identifying account takeovers and stolen identities in the financial and telecom worlds. We often see folks on HN complaining about how banks don't protect them from fraud losses - companies like this are how there is any hope left for some modicum of consumer protec…
>Let me be the devil's advocate here: The question here isn't (primarily at least) whether this is a good or bad thing, the important question is if this arrangement is legal under EU law. It can be the most beneficial thing in the world and still be illegal.
Re: TeleSign profiles half of the world’s mobile phone users
#69I work in fraud prevention with vendors such as this. Let me be the devil's advocate here: trust and risk scores such as these are often very useful for identifying account takeovers and stolen identities in the financial and telecom worlds. We often see folks on HN complaining about how banks don't protect them from fraud losses - companies like this are how there is any hope left for some modicum of consumer protec…
Why not start by supporting webauthn (Yubikeys)? How come all online VISA transactions don't have to completed through a redirect to visa.com or master.com (or may bank website), but instead we're typing card numbers into sketchy websites? (I guess EU 2FA requirements are pushing the boundary, but very slowly and often in ways that still appear remarkably sketchy). Trust scores of IPs and phones numbers is a tool, bu…
I support your argument about Yubikeys - I myself use them for any financial site that allows it. A lot of companies do use them to check for fraudulent logins. But the friction of it is high enough that companies would much rather take the loss than force their customers to authenticate every time a transaction has to be made. Also, I think until it is normalized in the industry, there is a consumer perception of physical keys being too technically difficult to obtain, set up and manage. Not to mention, all the Yubikeys in the world still don't help if one goes and gets phished/socially engineered :)
Re: TeleSign profiles half of the world’s mobile phone users
#70Earlier quoted context omitted.
So you are advocating for the vast majority of the internet population to stop using online banking. Let's flip the omelette: no one forces banks to do business online; if a bank can't build secure online banking, they can default to checkbooks and cash. They have the means and motive to build solutions that are actually secure and usable, so they should bear the burden of dealing with fraud when their solutions fail…
Most of the online banks are pretty secure for non-oblivious person. I always used online banking and never got scammed. It is pretty secure for me. Combination of user & password with enough entropy, and basic brute-force defense that blocks after 3-4 attempts is the industry minimum standard. User is the weakest link always, you cannot fix the "stupid" user that downloads malware, warez, adult content and gets infe…
Ok, granted, I spent the last 23 years of my life working in IT security across consulting, government, finance, and tech companies, but this is just garbage. Banks only invest in security to the degree that: - they are legally required to - they have contractual obligations to - that the risk of loss for a specific class of incident exceeds their self-insurance threshold
That's not a hypothetical comment, that is something that was explained to me as an AppSec lead when running into walls trying to get some issues fixed at one of the largest banks in the world. For the record, the issues that I was trying to have remediated would have had to exceeded an annualized loss expectancy for the region I was operating in of 10 million dollars per year to be considered risky.
Your definition of a bank being pretty secure and mine are probably radically different.
> Combination of user & password with enough entropy, and basic brute-force defense that blocks after 3-4 attempts is the industry minimum standard.
Sure, users should choose strong passwords. Banks should also require multi-factor authentication (real 2fa, not the SMS based weaksauce that a bunch use). But, that increases support and transaction costs. So, instead, blame the user! Beyond password selection, there is also the issue of how passwords are hashed, salted, stored, and brokered into a more reliable back-end credential that can be used, absolutely none of which the user has input into or control over, but sure, blame the user.
> User is the weakest link always, you cannot fix the "stupid" user that downloads malware, warez, adult content and gets infected and loses everything.
sigh you really like banging that drum.
> These people need life lesson to learn how to operate technology safely. > Although I agree that online banking could be made more secure, but the threat model will immediately evolve and adapt because scammers/fraudsters are still there and they want to eat.
There is absolutely no way to train average users to operate modern internet technologies safely because the average user has no effective control over the software and hardware they use (yes, Linux is a thing, and so is open source hardware, but users of those OS and hardware are not average users)
The primary reason the incidence of fraud is so high in the finance sector is because business has chosen to optimize for high transaction volume, and has accepted the risks of doing so. Stop trying to blame end users.