Live data from Hacker News

My bank keeps on undermining anti-phishing education

moritz-mander.de

61–70 of 267 posts

Re: My bank keeps on undermining anti-phishing education

#61

Earlier quoted context omitted.

> cannot have more than 15 characters That's something! My bank insists on exactly 6 numbers. Not characters, numbers. They're also hostile to password managers and don't allow copy/paste. You have to click on the numbers with your mouse. "My security" is very important to them, so they've moved 2nd factor from a physical fob, to an app tied to my phone, and now they've improved it further by switching to sms! Now, t…

SG?

BNP. I used to have an account with Boursorama (which belongs to SG) and they also had the point-and-click number thing, but I think the code was a bit longer.

Re: My bank keeps on undermining anti-phishing education

#62
post #43

Earlier quoted context omitted.

> cannot have more than 15 characters That's something! My bank insists on exactly 6 numbers. Not characters, numbers. They're also hostile to password managers and don't allow copy/paste. You have to click on the numbers with your mouse. "My security" is very important to them, so they've moved 2nd factor from a physical fob, to an app tied to my phone, and now they've improved it further by switching to sms! Now, t…

I wonder if it's because they look at security more globally. Their actions probably keep lowering security for people who understand the risks and are willing to take the extra steps to protect themselves but on the other hand they probably drive up adoption of some extra security for most other folks. Or if you want to be less charitable: they were tired with dealing with support calls from a lot of tech illiterate…

I'm sensible to these considerations.

But I don't see how a JS applet where you need to click on a bunch of numbers in plain view of whoever is curious to look over your shoulder helps with this. People have to type in their customer number in a regular text field anyway, so why not use the same thing for the password?

Re: My bank keeps on undermining anti-phishing education

#63
post #41
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

The only time I ever triggered fraud detection system on my card I got a text message from bank that was "Your card is blocked due to suspicious usage, please call 'number'". And the number was also some random unlisted one. Only reason I didn't just ignore the thing is I did make a purchase on new website a half an hour before. Called my local bank and they confirmed this was legit, I almost went off on a full rant…

One of my former banks handled this pretty well. They called you and would say something like “there is an issue, but since you should never trust a direct phone call pretending to be your bank, please look up our number on our website and call us”.

It’s kinda nice because while doing this, they also educate their customers to never trust such a call and to rely on official information to contact them.

Re: My bank keeps on undermining anti-phishing education

#64
post #18

Earlier quoted context omitted.

My mom was recently phished. The scammer got into her bank accounts and charged a bunch of air india tickets to her credit card and used zelle to transfer money out. When we reported it to the bank they said it wasn't covered because their fraud protection doesn't cover scams. So the banks just don't care. (It was Capital One FYI)

> their fraud protection doesn't cover scams Eh?

When I talked to the bank I was like "So if she had just lied and said she didn't know how they got her information she would have been covered, but since she was honest and admitted to being scammed she is getting punished?"

Re: My bank keeps on undermining anti-phishing education

#65
post #24

I know this from sport events but often the lottery or prize draw are organised by external marketing companies. So likely this is one reason for not making it a subdomain. The other is that Germans seem very bad at this kind of stuff. Why the heck would the application for the German passport or Ausweis be published by some random GmbH and not Bundesregierung.gov?

But .gov are for American government sites, and Elon's friends (oh geez I loaded doge.gov, it looks so dodgy...), and I assume the assignment of the domain names under .gov is done by somebody in the federal government, if they haven't been DOGEed as well. If any country's government can get a .gov domain, I can imagine the hacking that could happen, similar to hackers managing to infiltrate Bangladesh's central bank and almost managing a heist, but for a typo: https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery

At least for Switzerland the federal government puts its sites under the domain admin.ch . And the Cantons have their own domains, e.g. zh.ch for Zurich.

Re: My bank keeps on undermining anti-phishing education

#68

Earlier quoted context omitted.

Heh. 20 years ago when I was buying my house, I was arranging the mortgage through HSBC bank. One day I got a random call, started by asking me to confirm my name and date of birth. I asked them who they were, and they refused to say anything before going through security. I told them I wasn't giving them any personal details without knowing who they were, and they hung up. A week later, I phoned up the bank asking w…

> that was their procedure so it was my fault for not complying This is the most fascinating (infascinating? like, infamous/famous distinction? whatever) things about bureaucracies, to me: they sincerely expect everyone to follow their internal rules and procedures, even the people who are completely outside their jurisdiction by any stretch of imagination. Like, "we require the application of your personal seal to t…

Oh, don't get me started on rubber stamps.

I taught at a German university for a few years. And they way grades were handled was, you had to print a standardized piece of paper for every student with their name, date of examination, and grade, and drop them off at the secretary's office.

The secretary would stamp every such Schein with a rubber stamp. Then the students would pick up their Scheine at the secretary's office and bring it to the examination department themselves (!) to get the grade registered. Only at the very of my time there, they changed the system and I could hand in the grades directly to the examination department.

At any rate, the system was so stupid. It was trivial for students to print a new Schein with a better grade and register that (there must have been a lot of fraud). But the counter argument was 'no, it's very safe because the students do not have a rubber stamp'. Of course, the rubber stamp was just the university logo with something like the faculty name next to it. Trivial to copy (or make a rubber stamp for more enterprising students).

Probably the procedure had been followed since 1573, well before home printers, scanners, phone cameras, or get-your-own-rubber-stamp-for-a-few-bucks internet shops.

Re: My bank keeps on undermining anti-phishing education

#69

I see Conway's Law at work here. The marketing department must have its own IT department separate from the IT that maintains the core website and business functions. It's impossible for them to get on the same web domain (much less build something in the phone apps). Instead, they built their own disparate site and experience.

It gets worse. These German "Sparkassen" are small to at most medium sized credit unions. They are organised in a larger umbrella organisation that takes care of some of the services like IT, but the individual banks can pick and choose what and how much they want to handle themselves.

Some of them are larger and pretty well organised, but there are also a lot of small ones that just don't have the people and expertise for things like proper IT security practices. But customers trust them, because they position themselves as these local neighbourhood banks, even though most of them are pretty incompetent and will rip you off with high fees on accounts and shitty, underperforming investment products.

Re: My bank keeps on undermining anti-phishing education

#70
post #59

> "The SSL certification is from Let’s Encrypt and not from one of the major root CAs" This is NOT a reason to distrust a website.

This absolutely IS a reason to distrust a website claiming to be owned by a bank (or any other institution working with such sensitive assets). To be precise, such a website absolutely needs to have a certificate granted not only on the basis of "yes, I control the machine this domain points to" (which is what Let's Encrypt does), but also based on other, more physical and reliable means.

[deleted]
Post reply on HN