A bank security check that leaves you guessing your own name
theguardian.com
theguardian.com
https://news.ycombinator.com/item?id=1438472
https://news.ycombinator.com/item?id=12450825
https://news.ycombinator.com/item?id=21492464
Original at https://www.kalzumeus.com/2010/06/17/falsehoods-programmers-...
An identity check system used for VA loans uses your credit history to come up with secret questions. It's multiple choice and they auto-generate convincing other answers and/or some questions are completely auto-generated "ringers" which you must answer none of the above.
(The questions are things like "Which of the following banks have you had a car loan through?" "Which of the following addresses have you had?")
Problem is, I have very little credit history, so the likelihood of getting a question I can answer is near zero. On the other hand, whatever source they're using also has some assumed-real but actually incorrect associations for me (again, because I have little real credit history, the credit check system seems to be "grasping at straws" to generate a report on me).
So I couldn't just answer "none of the above" for all of the questions, because at least 1 out of each batch of 4 was not an auto-generated made up question but a real question asking me to guess what mistaken answer to it they have on file. After several tries / refreshed batches of questions that were all unanswerable, it locked me out of the system.
Now I had to look them up and have a lot of these written down for whenever I need to do a bank wire.
Then when you get a question and you aren't sure if it is one of the "ringers" or one of the ones that comes from errors on your credit report, you can check the reports to help decide.
I've got a similar problem, due to the post office trying to be helpful. Briefly, a neighbor with the same last name as me got married, changed her last name, and her husband moved into her house. Years later they moved and submitted a change of address form. The PO noticed the name on the form did not match the name in their records for that address, but did match the name on my address, assumed I was the one moving, and so it was my address that got changed, not my neighbors. We got it straightened out, but now my credit reports show me being at that other address for a few weeks.
Unless there is a lot of wrong information in your report, there is a good chance at least one of them won't use the wrong information in their set of questions.
Once you've got one downloaded and saved, you can try again with the others, checking any questions you are unsure about against the first download.
They're not really secret in America either. I mean, the account details are on every check for instance.
I always stick to cashier's check for this very reason (and for accounting purpose).
But, in order to fix it, they had to close my account. This alone was more than $40 in inconvenience for me, but there was literally nothing else that could be done. I had no idea how my account information got compromised (or, even if it was compromised), and I’m not sure what I would have done had my account information been leaked again via the same channel.
They may get into legal trouble. My mom had her checkbook stolen that was in her luggage and the person used the checking account to pay for an electricity bill. She reported it to the police, but they had more important things to spend time on. When you can use someones else's checking account number to pay for a utility at a fixed location, you probably aren't worried about legal trouble when you are doing it.
I work in the american bank industry. Just the status that 'bob jones has an account here' is considered personal information.
This might seem silly, but there are good reasons for it.
It’s not ideal, but at least since banks have KYC to deal with you know the name is correct. I pay our landlady every month via Zelle and it’s a lot better than mailing checks, if nothing else.
There is definitely similar Japanese-specific issues with specifying readings (especially for foreign names), but this works far better than requiring someone to specify the name exactly on the account to see if it is a match or not. I'm not sure if that would work well in the UK given how much more larger the Faster Payments infrastructure is.
You can use phone number or national ID number to register and that's all that is needed but you can set a display name freely if you don't want your name to leak via reverse lookup.
Generating QR also is available right in app and accepted pretty much universal via the same app you can check in for contact tracing or logging into government services or banks. Opening an account now is as simple as confirming a personal data sharing request sent to your app - no more paper forms
https://www.straitstimes.com/tech/singpass-to-be-upgraded-to...
The national ID has a checksum letter appended so simple typos are not very likely.
I remember the shittiest app from HSBC (who, by the way, seem to be sleepwalking their way through retail banking, with no direction from anyone who cares), which asked:
"What is the answer to your chosen secret question?"
There's security theater, and then there's Punch and Judy security puppet shows.
They also sent out a free RSA token for logins when they deprecated this system. It was first sent to "privilege banking" customers like me. And then they forgot that they sent them out, and tried to get me to pay for a new one. They were insistent that the token wasn't sent out at all. Ended up cancelling that credit card.
I remember that in a similar case I generated a random string with my password manager but I don't remember for which account. I hope it was one for I'll never have to spell that on a phone.
https://www.cbc.ca/news/business/rbc-customer-out-of-pocket-...
And that really seems to be all this is except that it uses the naivest process to do the check.
If we're willing to deal with the 'wardialing account numbers' factor, I think the right flow is "enter account number, SHOW associated name, and make customer confirm it (i. e. by transcribing it off the screen if it's a huge transfer, or just click "Yes, I meant to send to Scamco Ltd.") That avoids the usability nightmare of "the name on file is wrong but not in a guessable way."
I have pretty close to the simplest case for Western-style names-- no middle name, no hyphenation, no suffix or odd prefix, short, common first name, dictionary word last name. The number of times it gets recorded wrong is unbelievable.
Sorry, this form requires a middle name.
Barclays does it well: they check and warn but still allow a transaction if names don't match. Santander does it badly: they check and fail, with no way to get around the system if names don't match.
Barclays generally does great UX and Santander sucks, so the above comes as no surprise whatsoever...
I had no idea that it meant Joint Tenants With Right of Survivorship. If I did know that, I probably wouldn't have known what it meant.
Oh wait. I think it actually said JT TEN WROS. I still don't know the difference between that and JTWROS.
https://news.ycombinator.com/item?id=21729875
> “I lost my inheritance with one wrong digit on my sort code”
So the main user of that feature is the bank, not the bank customers.
The length of names is a common cause. In Japan, a normal full name is usually 4 or 5 characters long, with some exceptional cases being slightly longer. Systems often have a character limit which can exclude many non-Japanese names, especially if you have a middle name.
The pull system works in a different but similar fashion, and will (notably) fail if the information submitted with an incremental pull fails to match the name which was handwritten onto the document which sets up the pull (which is circulated at both financial institutions). A gym once received, and I was (in the literal sense) CCed, an icily polite letter from my local bank saying that the bank had no knowledge of a Mr. (close misspelling of McKenzie) and that if the gym had business with customer of the bank it should due him the common courtesy of getting his name right.
[1] https://www.rabobank.com/en/press/search/2018/20180523-ibann...
https://old.reddit.com/r/dredmorbius/comments/3mo7l6/that_go...
https://old.reddit.com/r/dredmorbius/comments/7qya12/informa...
https://old.reddit.com/r/dredmorbius/comments/2w618r/how_to_...
It sounds like a good idea, until I found out that the correct answers are considered to be incorrect by their system. I'm sorry, but I know where my mother lives, and she has lived there for decades. You got your data wrong, that's not my fault. When I answer the question correctly, it therefore locks me out of my account entirely, and I have to call Citibank to get my account unlocked. Helpfully, when you get locked out of your own Citibank account, anytime you try to log in the website delivers a plain-text "HTTP 403 Error" without any explanation. I had to deduce myself that it was because I "incorrectly" answered the question about me correctly.
I asked Citibank's customer service how to resolve this. I was eventually routed all the way to the top of their organization. Their best answer was that I should file a request with LexisNexis, the huge corporation that aggregates these data records on people using automated tools, to have the "official" answers changed.
That made me laugh. They want to place that burden on me?
So now I just do the whole dance every time I need to add a bill payee. Answer their questions correctly, get locked out because they think it's incorrect, then call customer service to get my account unlocked and to add the payee manually.
Does anyone know a good alternative bank?