Live data from Hacker News

How Your Bank is Tracking Your Phone

wordloosed.com

1–10 of 13 posts

Re: How Your Bank is Tracking Your Phone

#3
I find this hard to believe, if this were so - every time I leave my phone on my desk and go to lunch across town I'd get a new card.

More likely is that a batch of details went missing from the issuer itself or a store that the owner had shopped at legitimately any time in the past reported a loss of data, and the timing was completely coincidental.

Re: How Your Bank is Tracking Your Phone

#6
I work at a bank and I can tell you that they will often allow one or two instances of actual fraudulent card use before issuing a new card. It is actually very expensive for them to issue a new card and very inconvenient for the client so most won't do it willy-nilly.

I would also be remiss if I didn't mention the completely clickbait headline of the article that in no way reflects the actual content of the article. A more accurate headline might be, "Weird Coincidence Elicits Paranoia About My Bank".

Re: How Your Bank is Tracking Your Phone

#7
I don't think that's what's going on.

I think it's more likely a standard multi-factor risk threshold that's been triggered. A vendor you've never used (or haven't used recently), a vendor category (auto parts) which you rarely purchase within, a higher risk payment processing method (perhaps they put through a CNP (cardholder not present) transaction) in a location (geo or vendor) where use of stolen cards is above average.

However, that said, many mobile banking applications require coarse (mobile network) and fine (GPS) location permissions (https://play.google.com/store/apps/details?id=com.grppl.andr... and https://play.google.com/store/apps/details?id=com.barclays.b... for example). I highly suspect that this data, along with other information gathered from your device such as IMEI, is used to assess login risk. If you look at the markup on a lot of internet banking login pages you'll often find Javascript and 1px images loaded from unusual subdomains at the bank (sometimes with "risk" or "security" in the name). A couple of the banks I use also embed hidden Flash objects, only on the login page, which I suspect are used for the same purpose.

My understanding is that they pull together data from a number of sources/signals to calculate a login risk score, in the same way virtually every bank calculates a transaction risk score when you use your card.

I doubt that this information is tied with physical card transactions, however.

Edit: I'll add that I'm the most surveillance/tracking conscious person I know (most just don't care) but this is a little paranoid even for me.

Re: How Your Bank is Tracking Your Phone

#9
post #5

just as easily they could compare the pace/rhythm at which you usually hammer you pin in or something alike

I don't think the EMV PED (PIN entry device) standard supports such a thing. You could certainly verify that by looking up the EMV standards.

Re: How Your Bank is Tracking Your Phone

#10
post #6

I work at a bank and I can tell you that they will often allow one or two instances of actual fraudulent card use before issuing a new card. It is actually very expensive for them to issue a new card and very inconvenient for the client so most won't do it willy-nilly. I would also be remiss if I didn't mention the completely clickbait headline of the article that in no way reflects the actual content of the article.…

I was just thinking this; banks take their time to issue a new card.

What're the odds that a new card was ready to go and posted (and that Royal Mail delivered it next day?) due to one questionable use?

Post reply on HN