‘Stop using paper checks,’ says agency in charge of them
fusion.net
fusion.net
What a lot of people do is set up an 'incoming payments' account, an 'outgoing payments' account, and a 'storage' account. Have your bank block all external withdrawals from the incoming account, block all external deposits to the outgoing account, and automatically move money once-a-day from the incoming account to storage and from storage to outgoing(keep say $10,000 in there at all times). Never write checks against the storage account, or give the number out in any way.
On one hand, ACH is technically insecure. On the other hand, if a scammer can get away with the money a terrorist could get funded with the money, so money laundering and anti-terrorism laws have the side effect of making it hard for people to get away with it. And then you just throw the scammer in jail.
The article mentions handing a check to your landlord. Personally, as a landlord I set up an incoming rent checking account, hand out the checking account information to tenants, and let the tenant deposit the money electronically or by driving to the bank. I've asked my bank to reject withdrawals but accept deposits from that account, and use a debit card to pay for maintenance and utilities. I'm considering using SaaS software to collect this, mainly to ease accounting; I'm not worried about security here.
This is wrong, right? There is no such thing as a genuine check outside of conventions for repudiation(out of order check numbers, not on my check paper). Whether it came from the checkbook my bank sent, or out of my printer, it is just as good. Legally, writing it on a napkin would probably work, but draw lots of scrutiny becuase it looks suspicious and can't be processed automatically.
He apparently thought buy checks were a scam and he saw no reason to buy them when he could just use a sheet of paper.
How do you know who wrote the check? You should only see the recipient.
Once it became a regular thing, we made a note on his account.
I expect this works out better for people who get physical checks returned to them. Shredding the cow is a no-no.
But it depends. A lot on jurisdiction and local law.
Most banking systems I've worked with have a field 'cheque book issued' which is sometimes linked to a rule 'cheques outstanding'.
If the 'cheque book issued' field is false, no kind of cheque will be cleared. I'm not familiar with the US, but if an account was named a 'chequeing accound' would imply this is always set to true. Various red flags also exist, as a cheque book has cheques numbered, so the same number being used would result in payment denied. In the UK, payee blank cheques were disallowed in the 1990s, etc.
A long list of red flags, because banks hate cheques. The industry term is 'Manually Initiated Fund Transfer' which means, at some part of the transaction (any transaction - could be updating an interest rate, or an authorised signer), a manual step was involved. This creates huge risk of fraud, banks dislike fraud, and legal punishments are large, especially for the bank which has a procedure with holes to let it happen.
Cheques are manual, the responsibility is on the bank. An online initiated transfer, the responsibility is on the customer to ensure their password is safe (and the bank to also do automated checks - unusual IPs, 2nd factor confirmation, but much easier to automate). So a bank refusing to authorise payment from a cheque written on a napkin can be expected, as long as the process is documented as fraud control. Printing on company-headed document would probably work - the first small payment would raise many red flags, but if that cleared, future similar payments would be OK'd.
A single cheque to empty an account? Some kind of 2nd factor authentication would be employed by any sane bank, such as an old-fashioned call to the number the account is registered with.
It can say "sample" all over it or "not valid" and it's technically still a legal check.
Once in a while those "sample" checks issued by junk mailers actually work because the bank fails to check these things: http://www.sfgate.com/news/article/Playing-With-Money-How-a-...
Now this has got me wondering, how far off do you have to be from a standard bank-formatted check before one of those "deposit with your phone" banking apps will reject the check? I do bet that at the very least, someone with good penmanship could manage to "draw" a check that one of those apps would deposit. But could you go further?
For all their absurdity, paper checks are the only universally accepted almost-costless way to transfer money. ACH, wire transfer, card payments all come with an added cost of up to 3%, and every single proposed replacement system we've seen comes with new fees attached. For a payment of $10,000, payment by check costs perhaps $1. Payment by a 1% fee wire transfer system (most of them cost more) would be $100. Flat fee wire transfers range from $30 / transfer up.
Given how big and archaic ACH is now, and how expensive replacing it would be, I can't see a way out of this unless banks are required by regulation to provide an aggressively low-cost transfer mechanism.
*Specifically, I believe any country within SEPA.
I think they require SEPA transfers (roughly, transfers to other euro countries) to cost no more than domestic transfers.
Banks charge around 5-75 cents to business customers for electronic transfers, depending on the customer.
If you have to authenticate a withdraw in any way, the bank will have a better chance to win a fraud case because they had enough reason to believe the transaction was authentic and it is your fault not for protecting your pin or password enough. The bank might voluntarily rebook the transaction but why even bother if they had to do that anyways (even without a pin). The consumer is not the victim here, the bank who has to get the money back is. So why would you want to fix a system that works in your favor.
PIN-based cards are authenticated, but the practical security around those PINs is laughable.
So would you rather have obviously insecure but resilient system, or unobviously insecure and fragile system?
...
Making checks secure is relatively "easy". Simply have a mechanism for the person to review and authorize every credit/withdrawal via SMS or email. The problem, however, becomes keeping that mechanism secure, especially in the age of easily stealable and hackable mobile phones.
It doesn't matter to me if it has a chip or not (the chip has nothing to do with the pin, there are also chip-and-signature cards and cards that support both. The chip makes it hard to physically clone the card).
If you are interested in the downsides of the new pin card, checkout this video: https://youtu.be/Ks0SOn8hjG8
So, if zero authentication means that I am not liable for financial damages, I'm happy with it but I wouldn't bother to use a pin if I had the same liability. Unfortunately, the pin adds laughable authentication which makes me liable for many types of fraud (see the video).
I'd much prefer to do everything electronically, but I'm not going to pay an extra $24 to do it...
Is ACH not an option?
I inquired at my bank about electronic funds transfer (think ACH, but in Canada) and it would have cost around $100/month to sign up for that.
We avoided the mortgage securitization nightmare literally because Canadian banks hadn't gotten around to it yet. If the market crash had taken a year longer before happening, Canadian banks would have been along for the ride.
As far as insanity, I mean more little things. I can't speak for most US banks, as I only have accounts at BMO Harris. But for one thing, the statements I get from them are nuts. They list deposits, and withdrawals - the amounts, but not the dates, and not the resulting balance. And then separately they list a record of the balance throughout the month - not the amounts of the changes, but the new balance after each change, along with the date.
So in order to determine wtf actually happened, you have to compare the (potentially long!) list of undated transactions with the changes in balance throughout the month (which you have to calculate yourself) to find out what happened when. I mean... it's seriously like it's intentionally as convoluted as possible.
My statements from BMO Canada on the other hand show a sane account listing with transactions, dates, amounts, and resulting balance.
On the other hand, BMO Harris will mail a physical check (not a cheque! :P ) to anyone in the US for me, for free. Coming from Canadian banking, I was shocked that such a service existed, let alone on regular accounts with no usage fee. It's hilarious that you can do that but you can't send electronic transfers, but it's still extremely convenient, especially when doing business remotely from Canada!
I agree that the printed statements are weird. I'm guessing this is an American thing? I don't have experience with any other US banks to compare against.
I'm actually really curious whether other American banks have equally terrible statements, or if it's just them. Anyone?
The problem is really that Canada's interac system -- which was very advanced for its time -- never reached outside of the country or online, and market share means that you really want your payments to go through the major international card networks. But that's a matter of getting unlucky in backing the wrong horse more than anything else.
http://www.fcac-acfc.gc.ca/Eng/forIndustry/publications/laws...
According to some of my colleagues, these regulations were explicitly made to protect Interac against Visa debit and Maestro which were characterized as domestic schemes from the Visa and MasterCard network.
Because there are no co-branded cards, it also means that Maestro is not really accepted at many POS devices in Canada.
- Only some banks have the ability to initiate an arbitrary ACH transfer online (transfer between accounts that you own at other banks is a little bit more common).
- Even fewer of those banks make this feature free.
- Sometimes it is very well hidden inside the "Online Bill-Pay" feature (which wants you to search for an institutional payee by name), and no indication is given that you might use it to pay someone who is not a large corporate biller.
- Credit card companies and utilities usually provide a feature to give them your account number so that they do ACH withdrawals from their side automatically. They like it because you can't forget to pay. You should be wary of it because money just disappears from your account with no action taken on your part, and that's scary. A push-based option is much rarer - they will never just give you an account/routing number to push money to.
- There is never under any circumstances any kind of fee to write or deposit a check (provided it doesn't bounce).
- Usually your first couple of checkbooks are free (or pennies per check). If your banking relationship is large enough, then depending on your bank subsequent checkbook orders may be free as well.
- Far and away the easiest, least risky, most comfortable way to pay someone you are sitting next to is for you to write a check, and for them to take a picture of it with their mobile banking app.
Yes, it's idiotic.
Like Germany, Norway have/had giros in widespread use, though. The UK technically had a giro system, but actual giros are rarely used here. The big difference between a giro and a cheque is that with a giro it is the payer rather than the payee that instigates the transaction - either directly to the recipients bank account, or by effectively registering an approval with the bank and sending something similar to a cheque to the recipient (but with the difference that the sender has first directly confirmed the transaction to the bank).
So to me cheques have always seemed backwards from the logical flow.
But people mostly moved to direct debit for those kinds of bills.
It turned out that our customers used checks because it helped with their cash flow. They could tell us they "cut a check" on Friday, mail it on Monday, we'd receive it on Wednesday, and the money would be in our bank account Thursday. They basically were able to hold onto that cash for an extra 5 days, compared to a wire transfer.
Generally, for services provided, Accounts Payable aim for 60 days after service provided, and Accounts Receivable aim for 30 days since service provided.
I dislike it, and have a far nicer relationship with companies that pay on-the-spot. Indeed, I bend over backwards for such clients.
e.g. The NZ banks jointly own the company that processes EFTPOS payments. A system like that could never emerge in the US. Instead, people have debit cards, which are manageable because they go through the credit card companies and there are only a handful of those.
But yeah, it's all incredibly primitive and fraud-prone compared to NZ or Europe (I've lived in all three).
Scale might explain it for individual countries situation
But it still has introduced SEPA over its whole area. If anything, a country should have less of a problem than a still somewhat disjoint union of 28 countries.
So fintech startups here have a much harder time to explain, what is different about them.
BTW. The case what is describe in the article sounds for me like some kind of deposit entry fraud. Something I feared for a while in Germany, because deposit entries are very common for e.g. phone bills. But they seem to be one difference, in Germany you can simply cancel it and get your money back, usually 6 weeks but courts already ruled that this is just the minimum time.
Since you can't ACH outside of the US (I think) and any bank in the US has pretty strict "Know Your Customer" requirements, you will know for sure at least the first hop of where the money went.
I've heard of "work from home" schemes to include people acting as a middle-man for funds like this. They receive the ACH funds, and then they wire them overseas or send them via Western Union. These people, whether they were honestly duped or not, have committed a felony.
So when people worry about checks containing all the data you need for someone to empty your account, the first thing to consider is deterrence is very strong in this area because the penalty is massive, and tracking where the money was sent via ACH is easy.
That said, it would be nice if they could phase in a new standard which used one-time codes and provided real-time validation for this sort of thing. ACH transfer fees are extremely low compared to credit cards after all.
This is clever on your part, but holy cow there should be a better system than this.
Sort of. There are "International ACH Transfers", but they're not exactly like domestic ACH transfers; I believe they need extra AML information added, for one thing. Being able to make domestic ACH transfers does not imply being able to make international ACH transfers.
Edit: Judging from the replies, my personal memories are incorrect.
Previous mentions of Patrick Combs on Hacker News: https://news.ycombinator.com/item?id=4344720 https://news.ycombinator.com/item?id=2020631
[1] The best link I could find today: https://www.reddit.com/r/todayilearned/comments/37b74g/til_t...
EDIT: added additional Ycombinator links.
http://web.archive.org/web/19971210082324/http://www.dnai.co...
Well... Someone who has your Debit card number and expiration date can remove money directly from your checking account just as someone who has your routing number and account number can. I never use ANYTHING connected directly to my checking account to pay, unless it's the only option. There are a few things I need to pay with a check, but I see literally zero reason to use my debit card. My credit cards are accepted in all the same places and they provide me with more protection (in the sense that there's a buffer between them and my cash - even if I get reimbursed for fraudulent debit usage, the money is gone from my account for some period of time, allowing checks to bounce and other bad things to happen).
Speaking as a Scandinavian expat, in Norway, a bank account number is all that's required for an IB transaction - whether to a private individual or an institution for paying bills etc (which will also require a reference, typically). The account number incorporates all required processing information.
In Australia it's slightly more complex by the availability of options; the routing info is split out into a BSB (bank branch identifier) so you need that as well as account number - and account name - for a payment to an individual.
For bills you have BPay through your Internet Banking (very similar to a BSB+Account No payment yet a different method, and it doesn't require you to enter a name as the BPay number will resolve to a named organisation). There are typically no transaction fees.
Outside of Internet Banking there is also a similar Australia Post system, as well as credit card payment methods.
Anyway I thought the Australian system was a bit hard or confusing at first, but the concept of creating digital images of cheques sounds outdated and painful.
Was that really called for? Checks have account numbers on them. And checks aren't the only way to pay for things.
The signature is a security measure. Not a very good one, but in terms of the process is the same as your password or whatever authentication you use. You do authenticate, right? You do need more than a single bank account number to complete your transaction, no?
By comparing the security procedure of US checks to the information needed without security elsewhere, you're exaggerating the difference. It is easier like you say, and checks should die as fast a death as possible, but the process you replied to takes 30 seconds to perform, not massively longer or more difficult than authenticating with your bank and doing it online.
In Norway: That single account number is all that's required to send someone money, with amount mandatory and an optional reference. From what I know, they've tightened security down a fair bit and require TFA devices etc, so it may not be as easy as in Australia.
In Australia: On my Android device I use biometric authentication (fingerprint) as a shortcut to the username password that is required on first time login; the username is different to my account number.
When transferring to a new recipient, an SMS confirmation code must be entered. I already explained what destination information was required, but omitted that for BPAY, we require our customer number reference.
Once entered it is saved, which means a manual bill payment is easy as: Log in, select payments, select recipient, dollar amount, submit then confirm => done. (Including login I can pay say my ISP bill in less than 30 seconds). Of course these can be made recurring.
I would say this electronic, biometric model sounds significantly easier, but then I've never lived in a place where banking is so paper based so that's just my world view.
(I received a bank cheque some time ago and honestly had no clue on how to cash it, so rare is this. I learned that our ATMs now feature scanners for depositing, but it took nearly a week to clear).
I also occasionally get bank cheques in the mail from companies. If you have a utility account, and you close it, and it is in credit, they'll mail you a bank cheque for the credit amount.
Actual personal cheques - my grandparents used to give me those for my birthday. That's probably the last time I can ever remember encountering one.
So, yes, I don't use paper checks as commonly as I used to, but they're still pretty common.
I've never owned a checkbook, and the only checks I've ever received were from my grandparents (on my birthday) or a Tax refund. And tax refunds switched to direct deposits around 10 years back.
This has changed over time. When I first started working as a freelance musician, clients such as bars and restaurants paid cash. That came to an abrupt halt around the same time as Sarbanes-Oxley, don't know if it's a coincidence or not. Today, the bandleader receives a check, and writes checks to the band members.
> The good news is that online ACH fraud is relatively uncommon, just because it’s rare to find an online vendor who will allow you to pay using ACH rails instead of your debit card. The case of paying off a credit-card bill is a unique one, because you can’t use a credit card to pay off a credit card.
In fact, the default payment method of bank bill pay is to mail a paper check. Sometimes they cut a check with your account information, sometimes they will go ahead and pull the money from your account, but send a check drawn from their corporate account. Sometimes they mail the check 2-3 days before your payment date, so that (in theory) it has time to get there, sometimes not. The only time they send electronic payments is of the payee has set up electronic payments with them, and even then they may decide to switch your payment to a check at any time for any reason.
What makes it even worse is that they try very hard to make sure customers have no way to tell how their payments will be processed, and there's never any kind of warning that something has gone wrong until you get a call about a late bill. For example, even your payment should be sent electronically, something as simple as a typo in the account number so it doesn't match the expected length or format might result in them sending a check to your payee (with the wrong account number), meaning that your payment sort of vanishes...
Personally I always set up payments through the payee's site, using a credit card whenever possible. If they screw up the payment then it's their problem to fix.
I've had really bad luck with using a credit card and automatic payments. In particular, it led to my insurance being cancelled. I seem to have my card number marked bad by the bank at least once per year, and either get a new number, new expiration date, or just have all transactions blocked.
Having a scan of a cancelled check in my online banking account has worked a lot better in proving those sort of payment disputes than anything else.
No one should use checks, and no one should accept them.
First, for a business to even use ACH, they need a bank account to receive payments. This involves an underwriting process and a cash reserve for any returns.
Second, businesses have daily limits they can process. This is usually well below their cash reserve.
Finally, any hint of fraud will cause the bank to drop them like a hot potato and seize their reserves for a period of time to ensure sufficient funds to process any returns. One example of fraud indication is a high return rate
That said, its truly annoying to deal with.
Is Bitcoin not a form fiat money itself? It has nothing physical backing its value...