Live data from Hacker News

My bank keeps on undermining anti-phishing education

moritz-mander.de

91–100 of 267 posts

Re: My bank keeps on undermining anti-phishing education

#91

Earlier quoted context omitted.

> that was their procedure so it was my fault for not complying This is the most fascinating (infascinating? like, infamous/famous distinction? whatever) things about bureaucracies, to me: they sincerely expect everyone to follow their internal rules and procedures, even the people who are completely outside their jurisdiction by any stretch of imagination. Like, "we require the application of your personal seal to t…

Oh, don't get me started on rubber stamps. I taught at a German university for a few years. And they way grades were handled was, you had to print a standardized piece of paper for every student with their name, date of examination, and grade, and drop them off at the secretary's office. The secretary would stamp every such Schein with a rubber stamp. Then the students would pick up their Scheine at the secretary's o…

> Probably the procedure had been followed since 1573, well before home printers, scanners, phone cameras, or get-your-own-rubber-stamp-for-a-few-bucks internet shops.

This is almost always how these seemingly silly bureaucracy hoops become established. They were created in a prior time where a third party obtaining "magic item Y" with which to authenticate was significantly difficult to near impossible. Then, over time, the world, and technology improve, to the point where anyone, willing to spend $9.99, can have an exact duplicate of "magic authentication item Y" manufactured via any one of 78 different makers. But the bureaucracy continues using the now outdated process because "this is the way it has always been done".

It is largely a real world example of "The Monkeys, Bananas and Ladder Experiment": https://psychologyfor.com/the-monkeys-bananas-and-ladder-exp...

Re: My bank keeps on undermining anti-phishing education

#92
post #30

Some of the worst practices I've seen are from FedEx. When you order an international package, you get a text from some random FedEx employee's personal mobile number, containing a link to a website where you're meant to enter your credit card details to pay import duties. WTF? NO. I've called up about it and the support team were just like "ugh, yes, I know, yeah that's actually probably legit."

And here we are: twenty five years into the 21st century, and it is STILL this bad... SMH

Re: My bank keeps on undermining anti-phishing education

#93
Here's an interesting scheme. Some credit/debit card merchant accounts can arrange to get updated card info if your card expires and/or gets replaced. So if the merchant is a bad actor and doesn't charge your card directly but just tracks your updated card info so it can be used fraudulently elsewhere, you, your bank, and the card company will never know they were the source. And the card is linked to your bank account, you can replace it ad infinitum and the bad actors will get the updated info for the new card every time. The only way to break out of this is to close your bank account and open a new one.

Re: My bank keeps on undermining anti-phishing education

#94

Earlier quoted context omitted.

Ye they don't follow their own rules. Once my bank called me for a insurance change I requested a month or so earlier and asked me to verify myself via the security dongle. Like, and then they act surprised when people are scammed.

Heh. 20 years ago when I was buying my house, I was arranging the mortgage through HSBC bank. One day I got a random call, started by asking me to confirm my name and date of birth. I asked them who they were, and they refused to say anything before going through security. I told them I wasn't giving them any personal details without knowing who they were, and they hung up. A week later, I phoned up the bank asking w…

Had the same thing happen with a debt collector. They would identify themselves, but seeing as their name was meaningless to me as we had no prior relationship, and even if I knew what they were calling about I had no debt I was aware of...

They were a _little_ more cooperative about it though.

    "Hi this is  from . Can I start by confirming your name and date of birth?"
    "Who is this?"
    " from . Can I start by confirming your name and date of birth?"
    "No, you may not. What's this regarding?"
    "I can't discuss that with you until you verify your identity."
    "Okay, well I have no idea who you are so I'm not about to do that."
    "Well, I can't tell you anything else until you confirm your identity for me."
    "Okay."
    "So can I get your name and date of birth please?"
    "No."
    "..."
    "..."
    "..."
    "..."
    "Can you tell me what _day_ in January of 1970 were you born?"
I'm sure it broke some rule somewhere, but at least giving me some verification that they already had some of the information they were asking for I was willing to play along.

(Turns out the ISP did their usual ISP thing and failed to mark that I'd returned my modem when cancelling service a few months prior then told no one and sent it to collections. The debt collector was very adamant that I needed to set up a payment because this wasn't going away. I walked into one of the ISP's retail outlets, told them what happened, they sighed heavily because this comes up _constantly_ and called in to have it marked returned and I never heard from anyone ever again. The end.)

Re: My bank keeps on undermining anti-phishing education

#96
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

The company we use for our yearly mandated training has a cybersecurity "class" which tells you not to click links in emails (which is good advice!). Three guesses on how you log in to the service.

> which tells you not to click links in emails (which is good advice!).

Hardly. The company shouldn't have XSRF-vulnerable software, if your browser is vulnerable you have bigger problems and what you actually shouldn't do is enter your credentials or download stuff after clicking on that link.

But of course there's an internal "phising test" that penalizes you for clicking on links... links that have been obfuscated by some email-modifying link-tracking security software that makes it nearly impossible to figure out to which domain the link even goes.

Re: My bank keeps on undermining anti-phishing education

#97
I had this happen worse from my car loan bank.

I got an email with a header that was obviously badly scanned from a paper document. It demanded that I provide proof of insurance or my car loan would be canceled. It had the name of the bank and my name and my email, but nothing else of import.

The only URL was to a domain unrelated to the bank.

I ignored the first couple, and finally looked into it the third time.

It was legit.

When I told them all the ways this looked like phishing, they couldn't understand my concerns.

I gave them the info they wanted in person at a local branch. I soon after paid off that loan and got away from them.

Re: My bank keeps on undermining anti-phishing education

#98
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

It's fun when you phone the bank's regular number, waiting hours to get someone on the phone, and they say that number isn't legitimate when it actually is.

Even better when it's a bank you don't use and the number on their site goes to an automated system that won't let you access it without an account number, so you have to scrounge for alternative phone numbers to get to talk to someone.

Re: My bank keeps on undermining anti-phishing education

#99

Earlier quoted context omitted.

> that was their procedure so it was my fault for not complying This is the most fascinating (infascinating? like, infamous/famous distinction? whatever) things about bureaucracies, to me: they sincerely expect everyone to follow their internal rules and procedures, even the people who are completely outside their jurisdiction by any stretch of imagination. Like, "we require the application of your personal seal to t…

Oh, don't get me started on rubber stamps. I taught at a German university for a few years. And they way grades were handled was, you had to print a standardized piece of paper for every student with their name, date of examination, and grade, and drop them off at the secretary's office. The secretary would stamp every such Schein with a rubber stamp. Then the students would pick up their Scheine at the secretary's o…

Ah, offloading the physical movement of papers between the offices onto the general populace... why don't they just mail each other directly, isn't the part of their job is to communicate with other offices? Lolnope.

Sometimes it becomes truly ridiculous: I once had to apply for some thing, and was told I need to grab and provide them some certificate from a different government service to prove that I'm actually eligible. Okay, I do that, and then they spend two weeks verifying the certificate by physically mailing and inquiring info about me from that other service and waiting for them to respond (also by physical mail).

Re: My bank keeps on undermining anti-phishing education

#100
post #6

My bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is sol…

Yeah, I think they don't have any people working on the full UX flow, my bank does similarly weird stuff.

The example that comes into mind is making transfers to my wife, where every time I do it, they ask me to confirm a bunch of questions to make sure it's not a scam/fraud, which fine, good idea. Once I confirm, they display another notice telling me they won't ask for a confirmation/2FA code because I make transfers to that account so frequently.

The only reason I can come up with why it is like that, is because there isn't a single person/group responsible for the full experience.

Post reply on HN