Live data from Hacker News

Citibank India wants credit card, bank account numbers to stop marketing emails

online.citibank.co.in

61–70 of 89 posts

Re: Citibank India wants credit card, bank account numbers to stop marketing emails

#61
post #22

Earlier quoted context omitted.

The link posted here redirects to a co.in domain. It's Citibank India. I have sent them a message on facebook, in an attempt to bring this to their attention.

OP here. I sent them a tweet, and they replied with a link to a complaint form that - guess what - required me to enter my account number :)

If this is a legitimate concern and it's not being addressed after some reasonable initial contact, maybe you can get a mountain of retweets going with some unfortunate hash tag about the bank and a link to some reputable source about this issue. For better or worse, Twitter campaigns do seem to be somewhat effective against the PR machines of big businesses, as sooner or later someone important at the business often hears about them and starts damage limitation.

Re: Citibank India wants credit card, bank account numbers to stop marketing emails

#62
post #23

Earlier quoted context omitted.

This. Poison their IP blocks in the SPAM RBL so they get the message.

I don't think that's a smart move. Let's give them some benefit of doubt and bring this to their attention. I have messaged them on their facebook. Hope this will help. P.S. I am not a Citibank fan or something. Just trying to deal with this sanely.

Their Facebook is most likely ran by an intern or "social media expert" who couldn't be any more disconnected from their actual website and programming. If their e-mails get banned however, it'll go to a sysadmin who can actually start a conversation to do something.

Re: Citibank India wants credit card, bank account numbers to stop marketing emails

#63
post #45

Earlier quoted context omitted.

Banks should send ZERO emails, period. It's not secure for that. I do sometimes get emails from them but they're "useless" (usually a simple notification) Several banks have their own message box inside of Internet Banking.

Email is the only universally-accepted federated notification system. Emails such as "your card has been used 1000km+ from its last use" or "you just made this >$1000 purchase" are very useful indeed, and should be encouraged to detect fraud.

The problem with that is banks sometimes ask what your last transaction was to prove you are the account holder. Anyone who has access to these email messages will know that information.

Re: Citibank India wants credit card, bank account numbers to stop marketing emails

#64
post #45

Earlier quoted context omitted.

Email is the only universally-accepted federated notification system. Emails such as "your card has been used 1000km+ from its last use" or "you just made this >$1000 purchase" are very useful indeed, and should be encouraged to detect fraud.

The problem with that is banks sometimes ask what your last transaction was to prove you are the account holder. Anyone who has access to these email messages will know that information.

I've never seen this with any of the banks with which I've done business. They will tell me what the transactions were and ask me to confirm that they were indeed by me in the case that they're suspicious of fraudulent activity.

Re: Citibank India wants credit card, bank account numbers to stop marketing emails

#65

Citibank is one of the worst banks I've dealt with. Once, one of their affiliate's employees offered me a Credit Card for free and said "it had no strings attached" and I don't need to do anything to keep it alive. Thought it sounded too good to be true, I bit the bullet and signed up, right on the spot, their affiliate clothing store. Before I was about to submit my documents, it was then I happened to meet a friend…

Forging your signature is illegal!

Re: Citibank India wants credit card, bank account numbers to stop marketing emails

#66

Citibank is one of the worst banks I've dealt with. Once, one of their affiliate's employees offered me a Credit Card for free and said "it had no strings attached" and I don't need to do anything to keep it alive. Thought it sounded too good to be true, I bit the bullet and signed up, right on the spot, their affiliate clothing store. Before I was about to submit my documents, it was then I happened to meet a friend…

Which country was this in? India?

Re: Citibank India wants credit card, bank account numbers to stop marketing emails

#67
post #24

This is a phishing attack waiting to happen! I never worked at a bank but I'm assuming (maybe I shouldn't) that there are a few people working there that know a thing or two about security. I doubt that any person who claims to be a "security expert" would have let this go by, but I always seemed to be proven wrong. Take for example TDBank in Canada who has a 80's password policy: Passwords must: - be 5 to 8 characte…

Poor password rules are a red flag. If their password code is this bad, how bad is the rest of their code?

Re: Citibank India wants credit card, bank account numbers to stop marketing emails

#68

Citibank is one of the worst banks I've dealt with. Once, one of their affiliate's employees offered me a Credit Card for free and said "it had no strings attached" and I don't need to do anything to keep it alive. Thought it sounded too good to be true, I bit the bullet and signed up, right on the spot, their affiliate clothing store. Before I was about to submit my documents, it was then I happened to meet a friend…

Forging your signature is illegal!

Its illegal but legal system is so bad that a person who openly swindled 25 billion-dollard in 5 years is going to become a ruler of a province...He will literally buy votes with the money.

Re: Citibank India wants credit card, bank account numbers to stop marketing emails

#69
post #24

This is a phishing attack waiting to happen! I never worked at a bank but I'm assuming (maybe I shouldn't) that there are a few people working there that know a thing or two about security. I doubt that any person who claims to be a "security expert" would have let this go by, but I always seemed to be proven wrong. Take for example TDBank in Canada who has a 80's password policy: Passwords must: - be 5 to 8 characte…

My bank requires a 4 character password with no letters or special characters! Oh wait, a PIN doesn't count?

Re: Citibank India wants credit card, bank account numbers to stop marketing emails

#70
post #28
post #24

This is a phishing attack waiting to happen! I never worked at a bank but I'm assuming (maybe I shouldn't) that there are a few people working there that know a thing or two about security. I doubt that any person who claims to be a "security expert" would have let this go by, but I always seemed to be proven wrong. Take for example TDBank in Canada who has a 80's password policy: Passwords must: - be 5 to 8 characte…

They might be running AS/400 as their backend systems, I recently saw a terminal to one of those in a bank and to my shocking surprise the passwords were not even encrypted on that system. I imagine that passwords are kept in the same database as transactions so I'm not sure the passwords would be the primary concern in the case of a break in.

The frontend part can still use a secure password mechanism which is then hashed to a password suitable for the underlying backend system.

There's no reason to keep the bad decisions from decades ago as a part of a modern system, even if it relies on the legacy system.

Post reply on HN