From Facebook account takeover to an empty bank account
badcyber.com
badcyber.com
At this point I ignore it and use my TOTP app anyway, but it bothers me to no end, as it leaves my account that much more vulnerable to a hacker intercepting the SMS in transit and using it to break into my Facebook account. Facebook does not allow you to disable 2FA SMS without disabling 2FA altogether.
Huh? Do banks actually do that?
While I haven't experienced that personally, a friend reported getting such a call from his bank after he ordered $400 of fireworks online.
Unfortunately it's all pretty opaque and bank dependent - as far as I know, there's no way a merchant can trigger such a call, for example.
The payment was declined until I called the bank and told them I was standing in line trying to actually pay for it.
The thing is, I don't think she was able to open it for just that transaction, but instead flagged my account so that ALL large payments like that were allowed.
Which to me just seems like an outlandish shortcoming.
It reminds me of the time that some random ACH got placed on my account. They claimed they couldn't even tell me the name of the person or company who did it, etc. And this despite me having specifically requested that any ACH's placed on my account are approved personally by me.
It's actually kind of scary just how inept these banks are sometimes with respect to these issues.
It's a security measure to protect both the bank and the customer.
EDIT:
BTW this shows that sites like Let's Encrypt, which automatically issue certificates to websites kind of defeat the whole purpose of certificates - they only check that the site exists and requestor has admin access to it, but do nothing to check whether it is legitimate business or scam.
A green padlock in the address bar should mean that the site is trustworthy. Now it only means that site admin knows how to setup https.
Is there a whitelist? Because then the press and the rest of the internet will cry censorship and stifling of innovation.
Is there an algorithm? Then the scammers simply learn how to game the algorithm and defeat it easily. (This applies to some easy checks like domain registration date too.)
Is it a team of humans? That's a lot of sites and a lot of humans to employ. What about user-reports? Now you have to deal with false reporting and abuse.
While it's possible for some combination of approaches to succeed here, it's not nearly trivial.
The problem with your scenario where https===trustworthy is that it doesn't leave any middle ground for a site to simply protect its and your information. It's either full bank-site security, or none at all. That's not acceptable.
The green padlock means that you have a secure connection to the site you have selected to visit. We should not attempt to ascribe any other meaning to it.
The purpose of certificates has never been a "not a scam" stamp, and no traditional certificate vendor was ever checking your business practices or legitimacy. Issuance of DV certs is just as automated at Verisign, etc.