No, that's contrary to the FCA regulations. In cases where you can't tell if there's been a third party committing fraud, the benefit of the doubt must be given to the consumer. If the bank cannot demonstrate that the consumer is committing fraud, they cannot refuse the consumer their money.
It's obviously complete nonsense to say "_whatever the rules are_, in scenario X the bank will be able to do thing Y"; in this case the rule is "in scenario X, the bank is not permitted to do thing Y".
Which is why I obviously was not talking about that.
> If the bank cannot demonstrate that the consumer is committing fraud, they cannot refuse the consumer their money.
OK. Now, the bank demonstrates that you committed fraud (that you didn't). Now what?
This thread is rapidly losing value to readers now, since you seem to be dishonestly representing what you’ve previously said, at best guess because you don’t like to be wrong. Quoting you:
“the somehow fraudulent order where the bank doesn't see any signs of fraud and you can't demonstrate it either.”
“That is the category or fraudulent transactions that are indistinguishable from legitimate transactions by anyone but you”
“There are cases where the bank will not be able to distinguish an actually fraudulent transaction from a legitimate one.”
Only now have you changed this to apparently mean the bank can falsely prove the customer committed fraud.
There’s nothing wrong with not being up to speed on recent banking regulation changes in the UK. There is something wrong with pretending you were saying something you weren’t, just for the sake of internet points.
If someone calls me pretending to be my bank and tricks me into giving them enough details (passnumbers etc) to move money out of my account, or persuaded me to authorise transactions they’re making (because I think they’re the bank saving the money from being stolen by someone else), then the transactions will look real to the bank. Previously, that was my problem. Now it is the bank’s - I may have divulged my details in good faith, but I didn’t give the criminal any money. The bank, unwittingly, gave the criminal money. The bank is no longer allowed to claim it was my money. Rather, the bank still owes me my deposit - nothing has happened to change that.
This has been a more commonly occurring crime in recent years, and the regulations are specifically there to:
Protect the consumer
Put the onus on the bank, to encourage them to do better protecting their money.
No, you are simply concentrating on the ultimately irrelevant details. I was not talking about any particular jurisdiction and their banking regulation, but about the fundamental problem that no banking regulation could possibly solve. Possibly I expressed that badly when I phrased things in terms of specific criteria that, of course, can lead to different assignment of liability depending on jurisdiction, but then, I would think that it should be clear from the context that that is not what I particularly care about here.
The fundamental problem is that you are trying to determine someone's intent. Ideally, you would want to be able to distinguish exactly when the bank customer intends to effect the execution of whatever order they formally have given you, and when they don't, either because they weren't actually involved in authorizing the order, or because they are somehow mistaken as to what the order they have given actually entails. If we could do that, the bank could refund all fraudulent charges without being at risk of being defrauded itself (or, ideally, prevent the fraudulent transaction in the first place).
It's just that we don't have access to someone's intent. All we have is someone who claims to have had a different intent than what the bank believes (or claims to believe), and who has a motivation to lie about that claim. But there is nothing that would be externally accessible that necessarily distinguishes someone who ordered some transaction fully understanding what that order entails and someone who gave the same order but was mistaken about what it entails. In some (maybe many) cases, you can have strong evidence that supports or contradicts the fraud claim, and those then generally can be resolved correctly. But there is absolutely no guarantee that you have any reliable evidence in either direction. And if you don't, there is no easy and reliable solution. You can not just say "if you can't know for sure, you have to refund", because you never can know for sure, so the bank would always have to refund, thus resulting in a massive fraud risk for the bank. Or you could say that, but it's just not gonna happen. The bank will always be able to avoid refunds without demonstrating beyond a doubt that the cutomer was trying to defraud them, or else they could not defend at all against people trying to defraud them. And as a result of that, there is always, unavoidably, the risk that you, as a customer, will be defrauded by a third party, and, no matter what the regulation, you will not get a refund because the bank can show sufficient evidence to convince a court that it was likely your fault according to whatever the specific rules are.
And all of that is relevant in this context because TFA suggested refunds as a supposed solution to the problem of weak passwords, and that is bullshit. While shifting much of the liability to the bank via regulation certainly helps in many cases, it can not, in principle, ever be a complete replacement for strong passwords. As far as guessing credentials is concerned, only strong, high-entropy, credentials actually solve the problem, solve it trivially (assuming the customer cooperates, of course), and solve it without exception.
Suppose you had one legitimate transaction, and one fraudulent transaction. Now, suppose the bank had certain evidence to show that the legitimate transaction is legitimate that is sufficient from a legal perspective to refuse your refund request. Then, suppose the bank had no such evidence to show for the fraudulent transaction.
And now pay attention: THE FACT THAT THEY DON'T HAVE EVIDENCE FOR ONE OF THOSE THAT THEY DO HAVE FOR THE OTHER MEANS THAT THE BANK CAN DISTINGUISH THEM. Got it?
I was talking about cases where the bank is NOT ABLE TO DISTINGUISH an actually fraudulent transaction from a legitimate one. Your response "but if they are able to distinguish them, they have to refund you!11" is just completely irrelevant to the point that I was making.
We are not making the point you think we are.
We're all clear that if the bank can distinguish, they must refund legitimate cases, but that's not what we're trying to explain either. Responding to your last paragraph alone:
"I was talking about cases where the bank is not able to distinguish an actually fraudulent transaction from a legitimate one. Your response "but if they are able to distinguish them, they have to refund you!11" is just completely irrelevant to the point that I was making."
My response is not "if they are able to distinguish them, they have to refund you". It is "if they are _not_ able to distinguish them, they have to refund you".