Making it clear when we're on a call with you to protect you from fraud
monzo.com
monzo.com
It is clear the bank has had a severe exfiltration event. There are other reports that online. IMHO the law should make banks report breaches to the ICO and a record of the nature and size of the breach be public.
Through the process I learned that in the UK you can call 159 to directly contact your bank fraud dept (most banks) https://stopscamsuk.org.uk/159
I also learnt about the police’s Action Fraud hotline to report cybercrime. https://www.actionfraud.police.uk/what-is-action-fraud
The phisher was very determined. They called back in 15 minutes claiming to be from the bank fraud dept returning my call. Then 2 weeks later they called back claiming to be from Action Fraud.
However prepared you think you are for such an attack, my advice is to have utmost caution for every single call from anyone claiming to be anyone.
I also have a Monzo account. Even if they called me I wouldn’t use this. Hang up. Call them. Don’t let them call you.
This is the golden advice. Never, ever speak to anyone about anything important if they contacted you. Call, text, email, whatever. End it and you contact them.
It doesn’t matter if it’s the bank, power company or telco. Even if HR called me or the CEO. Hang up, call them back. It adds 5 seconds to ensure all is good
This bears repeating. It's so simple to check in using another known-good contact method, and btw phone calls are still cool.
Not to large corporations. Have you called one lately?
It's a minimum of five minutes of bartering, begging and pleading with the IVR to let you speak to a human, and even then a successful outcome is anything but guaranteed.
The confirmation bias is real!
Depends on the bank.
Some make it almost impossible to get past their IVR, which always claims to be able to help you with any issues you might have (as long as the issue is wanting to know your balance and last three transactions).
This has become increasingly difficult in my experience. Where calling the local branch I have the actual relationship is just dumped into the IVR. They make it very hard to speak to an actual human being bank employee.
If they are behind an annoying IVR they usually know how to get back to themselves.
Of course don't take their word on what number to call, make them point to a part of their website that shows the number.
[1]: or something like that, I forget the exact words
https://security.stackexchange.com/questions/100268/does-han...
So try to call the bank from a mobile.
Its not really weird if you look at it in context.
People who are not Gen-Z whipper-snappers will recall the era.
Before cell phones, before DECT home phones, before wireless cordless home phones you had fixed phones.
You had a master socket and then, optionally, one or more secondary sockets (depending where you lived, you were either permitted to install these secondary sockets yourself, or you had to call in the telco to do it).
Anyway, so what would happen is that your friend from school would call you up. Inevitably your parent would answer the phone because they were, for example, in the kitchen cooking your dinner.
There would then be a shout across the house "Bobby its Johnny ... AGAIN !".
The call-transfer process would involve your parent hanging up and you picking up the nearest secondary handset.
Hence the exchange needed to keep the A-end of the call live whilst you completed the B-end "transfer".
The same generation of people will also recall the ability to abuse the mechanism to quietly spy on someone else using the phone. :)
"Called Subscriber Held", a feature that was carried into early digital exchanges because people expected it to work in the manner you describe, even though afaik it was designed for the other purpose of keeping the line open whilst operators patched it through, trunk lines picked up the tone, etc.
My grandpa was a something like chief engineer for the West Coast of Scotland phone network. I have so many questions I wish I could ask him these days.
Remember it used to be a switched physical circuit. In the early days the switching was done by people, later it was automated. But you still had a circuit from phone to phone.
When one side hung up, the circuit is still live. Eventually it timed out and the switch disconnected it, but it took a while (don't remember how long). So you could hang up a phone, walk to a different room and pick up another phone and the same call circuit was still live (as long as the other side didn't also hang up meanwhile).
If the dial tone is heard at all, it is for a very brief period, and might be entirely missed. This would make the scam you're describing even more readily achieved.
... the autodial feature may well be waiting for dialtone in order to dial. I've not looked into this and you're probably best off testing this yourself on your own equipment.
Honestly, I’m not sure it matters. They’ve all had such incidents. I read somewhere that about 30% of your fees and mortgage interest go toward fraud mitigation,monitoring, and restitution.
I always live by these rules
- call them back, don’t talk to them
- ask why you need to do anything. It’s exceedingly rare a bank would call you to do something legit there and then. “I will do it later” will help. In fact that’s how I caught the phisher as I noted the aggravation in 1% of his voice.
- use credit cards, not debit cards, for purchases. They have far more protection.
- use all the 2FA and password complexity you can
- never use real info for challenge questions. Never use maiden name of mother etc. you can put “14 green fish” as the answer to the question if you like.
- make sure they are FSCS regulated, and try not to exceed that limit.
- understand FSCS does not cover you most phishing attempts, since the bank will claim they tried to warn you and were not negligent
- use private tabs for bank interactions
Through this experience I have learned not to trust “what we know about you” information they share. Do not underestimate HUMINT. A bank snitch could give up something as seemingly innocent (to them) as your “join date” and it be a lynchpin piece of info for a scammer.
This may all seem obvious to an HM reader. But it’s worth refreshing and reiterating.
The law already is that they should report breaches to the ICO, at a minimum you should report this to the ICO and if you can you should name the bank, possibly right here in this thread so that others have a chance to find out. It's a throwaway so why not use it?
Louder for the folks in the back. All bank cards should be required to print this on them.
1. "Did you make these purchases?"
2. "Yes" -> "Thanks, bye."
3. "No" -> "Thanks, we're disabling your card, and sending a new one to your address. If your address has changed, please pick it up at the branch."
Any deviation from this is a scammer posing as the fraud department. Any attempt to gather any information from you, besides 'Did you make these purchases?' is a scam.
They know who you are, if they didn't, they wouldn't be calling you.
I had an issue where a bank (chase) called me to verify a transaction it felt was illegitimate, first thing the bank employee (who claimed to be with the fraud department) did was send me a SMS 2FA code that clearly said "do not share with ANYONE" I told him that and he said "yes, but I need it to confirm you are who I'm trying to reach, if you don't give it to me I will lock your account" ... My account was locked and I had to go into a branch, present 2 forms of photo ID to create a new userID and password and be able to use my cards/access my (new) account again.
I had some very strong words for the branch manager and anyone who would listen about how terrible a security practice it is to give those sorts of conflicting instructions.
I don't even have two forms of photo ID. I think I would just leave to another bank immediately if it was an option
But for retail banking, supposing you actually have the option, yes, absolutely.
When we got the mortgage for our house, we went out of our way to arrange it with a bank with which we had (and have since had) no other dealings.
Result: Our "mortgage bank" has no insight into our day-to-day finances. Our "day-to-day bank" has no insight into our mortgage.
I had one once that had an authentication question in their phone banking script that asked how a certain system was set up, option A or option B. Given that I was calling to set up that exact system, neither answer made sense. The agent I was speaking to was seemingly unable to comprehend this, and I got sent to a branch having failed the ID check.
I went to my local branch with enough ID bearing photos and recent addresses to pass all the usual KYC/AML checks to open a new facility at any major financial institution in my country. Having explained the situation and showed that ID to a bemused but sympathetic member of staff, they called their magic phone number to speak to the relevant team, gave their staff credentials, and confirmed that I was present in person with them and they had personally verified my ID. They were then transferred to apparently the same phone system I’d called from home myself, which got stuck at exactly the same ID check.
Didn’t stay there long, though longer than the place whose “security team” called me and started the conversation with, “Good morning, I’m calling from the security team at (my bank). Before I can talk to you any further, I need to verify some personal details to confirm your identity. Can you please tell me (the top three things I’d need to know if I were an identity thief and wanted to impersonate you with other services)?” I particularly liked the anonymous phone number they were calling from. And in case anyone’s wondering, I did call the bank back at one of their public phone numbers, and they confirmed that the call I’d rejected was from them.
[1]: (I'm probably mixing up some of the crypto specifics here, but hopefully a crypto expert can chime in and straighten them out)
The core argument essentially boils down to the fact that they never use their social security number, therefore it’s not an id. Which is obviously incorrect for a number of reasons, but here we are.
The only real solution here is for the problem to get so bad that the angry majority overrules the loud but uninformed nut bars.
That said, maybe they’ve fixed this since it happened to you: as of 2023, Chase’s Sapphire credit card department seems to be able to verify my transactions as legitimate or fraudulent and complete my live identification to a customer service representative without replicating your experience. They allow me to validate transactions by replying to email or SMS notifications which mention the specific transaction, and they can involve their mobile app in attempts to live verify my identity.
So, that was all possible back then too, this was specifically for an attempted ACH transaction between my chase account and my discover account, it was a large amount of money and chase didn't think I was the one who initiated the tx even though I'd already verified the other account in chase. they were concerned my actual account was hacked... in that case, as others have said calling a phone number and then sending a text to that same number doesn't add any additional verification for them, if I can answer the phone call I can see the text. Obv, if they suspect my account was hacked there really isn't a way to verify using any of the existing account info.
It seems to also hint to their fraud system. I think the last one I got was when I was traveling, and it quit asking if the charges were authentic after the first couple.
P.S. I don't know how Chase login happens, not a Chase customer.
Entertainingly, they seem to sniff user-agents in some way. Firefox on Linux works fine, but I tried to log in with Firefox on OpenBSD recently, and it just kicked me out suggesting I try their mobile app[0]; I tried the ungoogled-chromium package, and it worked. Apparently, this presents a FreeBSD user-agent string.
I sort of want to switch to, well, any other institution, but my family is terrified "what if there's not an ATM nearby?" Strangely, I've never had easy access to a Chase machine on any holiday or business trip I went on.
[0] I love it when they know I'm on a desktop and still encourage you to install their zippy new app. PayPal, I'm sure that iOS app has a Void package.
I usually politely tell them that I am going to hang up and reach their fraud department through the phone number on their website. I never had my account locked.
No. What we really need is a mutual authentication, where both parties talking over a phone can confirm each other's identity simultaneously, as a part of a single process (assuming a previously established secret(s)). Ideally, with a piece of human-readable metadata attached to it that describes the purpose of authentication.
So banks no longer ask you to read back a SMS, and you no longer guess if that's legit and you both know what this authentication is for (spelled out in a natural language).
If you have Internet connectivity, it should use it to perform all the communications, leaving both sides with a simple interface (as simple as tapping "confirm" or "reject"), and if Internet isn't available it should provide an ability to still perform the protocol by reading some phrases and typing in what you hear back.
You can simply ask the crook to name the amounts and descriptions of the last several transactions in your primary checking account. Or the statement amount of your most recent credit card bill on a particular card.
Sometimes gets weird reactions from the caller but they usually comply.
This RUDE person said well my debit card will remain locked until I answer their questions. I said fine I'll call my bank.
My card remains locked to this day.
You also have the option of reporting them to your state banking regulator [1], the CFPB [2], the FDIC [3] and FTC [4].
A polite way to do this is to write a letter to your bank explaining what happened and Cc’ing the regulators. It will tend to get escalated to their legal department and has a chance of forcing policy change (and producing compensation).
[1] https://www.consumerfinance.gov/ask-cfpb/how-do-i-find-my-st...
[2] https://www.consumerfinance.gov/complaint/
The Apple rep told me Amex was the worst, so I figured I'd call Citi. The person on the phone said "I've just sent a code to your phone". I got the text, which reads (and I quote): "Citi ID Code: 671865. We'll NEVER call or text for this code". I told him "this text says you'll never call for this code, yet you're on the phone with me asking me to give it to you". He laughed and said "yeah, I know it says that, but you have to read it to me"
I reluctantly read it to him, he unblocked my card, I tried purchasing again and it got blocked again. I ended up having to run home to get my wallet and run back. The Apple rep was kind enough to let back into the store with like a minute left before it closed.
This was ~6 months ago. My Citi app says my card is blocked to this day and that "[they] need to speak urgently with me", yet I can still make purchases with it as if it weren't blocked. I'm letting it linger in this limbo state to debug what happens. I have also never used this card again unless the POS really won't take Amex.
In this case you called them and they asked you.
I refused on a couple phone calls. I forget whether in the end I gave it to them or not, the details are hazy. I do remember I left feedback.
To my knowledge, Amex actually stopped that practice since then. Because as you note with the citi experience, it is bad.
I called the fraud line on the back of the card (which was different than the number in the text) and they confirmed it was authentic but man, everything about that is straight up phishing.
TD Bank is also one that's horrible. Their online banking portal is myonlineaccount.net which is straight up a domain you'd use for phishing.
Those are 2 very different things! Indeed they did not call, you called.
> yet you're on the phone with me
That wording is specifically ambiguous as to who placed the call.
I’ve had them block my card and refuse to talk to me until I read them back a code from a letter in the mail more than once. The code is single-use, so this adds about a week of latency.
On the other hand, they once called me about fraudulent transactions on my card and didn’t hesitate at all to ask me for very personal details on that inbound (to me) call. I hung up and wasn’t able to get back to whatever department made that call due to the reasons above.
Called me out of the blue after a failed transaction, I refused to give them the info they wanted and so they locked my account. Unlocking needed me to send them physical info that would have cost me.
Easy to sign up for an alternative. Lost a customer after 15 years. Well done Sainsbury’s Bank.
I have nothing but good things to say about ally itself.
My parents got scammed in the past so they are on the lookout, but I still don’t think they are careful enough. And due to their age they get attacked a lot! Last time I visited, their phone was ringing every hour or two--all scam/spam. It’s only a matter of time until the next one is clever enough to get through.
I think these “external caller” scams are going to be with us until that generation dies out. The “trust the phone” instinct is too strong. Of course for my generation, the scammers will find something we inherently trust and exploit that, I have no doubt.
I get regular emails from retailers and banks reminding me that they will never call and ask for money or personal info. Then they state exactly what you said; hang up and call the institution's official number if you're unsure who is calling.
(Note: a quick way to find the official number is by looking on your debit/credit card. It should be printed on there.)
(Note note: Don't sign your credit/debit card. Put "SEE ID" or something in the signature area.)
But I haven't had anyone check the card in ages.
Best case everybody will ignore it; worst case your card will be declined because somebody will still actually attempt to compare the signatures on the receipt and card, and “SEE ID” is not a signature.
This seems like the second most secure form of identity check (chip + PIN #1) if everyone could be made to follow it consistently.
Yes, but that's not happening since there is no incentive for the merchant to do it. Merchants are generally not liable for card-present lost/stolen card fraud, so the only thing this does for them is add friction.
It's a textbook principal-agent problem (in addition to requiring a human in the loop), and I highly doubt that the schemes would ever introduce anything like that, especially given that there are viable alternatives available (PIN entry on the terminal, on-device authentication for mobile wallets etc.)
When is the last time anybody has even looked at the back of your card?
Signature comparison (or even asking for a signature) is no longer required in most circumstances under the card schemes’ rules, whatever the signature panel says.
I'd bet that it's not because of their age, but because they have been scammed in the past, so their data now is on the lists of "verified victims" which get passed around as those are thought to be more likely to fall for the next scam than simply a random number.
Seems like the next step would be to send an app push notification before the call and to have a banner that's visible as soon as you log in to the app. Some sort of visual indicator that appears everywhere in the app that you should not be on a call may also reduce an attackers chance of succeeding.
I don't think you can get details about the call that easily (like phone number and such) but with the right permissions it may also be feasible to maintain a scam number list based on user reports that sends out a notification when a known scammer is trying to call you.
There are plenty of scams based on impersonating some official (FBI, IRS, etc). It's not hard to imagine a scammer spoofing your bank's phone number [0, 1, 2, 3].
[0] https://www.snbonline.com/about/news/scammers-can-spoof-an-o...
[1] https://www.westernbank.com/fraud-prevention/what-you-should...
[2] https://www.wellsfargo.com/privacy-security/fraud/bank-scams...
I think this can be solved far more simply by only showing the notification/warning (or showing it more visibly) when the app detects you are in a call.
> with the right permissions it may also be feasible to maintain a scam number list based on user reports that sends out a notification when a known scammer is trying to call you.
So far, no apps that I know of have any such feature. If only one single app does it, it shouldn't cause a problem for anyone.
> If only one single app does it, it shouldn't cause a problem for anyone.
And that's how every app justifies doing it...
I can't say I share your experience. There are apps that spam you with notifications and intentionally don't use categories but I generally just uninstall those.
Everywhere would probably be to distracting, but placing it on important screens (such as "verify transaction") would probably be a good idea.
You mean that if a genuine bank representative calls you then they prompt you to verify it. A fraudster will not do that and if the customer doesn't challenge them then the scam can continue.
One of my fears around getting older is not having the wits to protect myself from bank fraud like this. I don't have a solution.
Most UK financial companies will have a third-party authority process. Its the sort of thing used to give professional advisors access to the account, but there is absolutely no reason it cannot be used to give other sorts of third-parties access.
The core difference is that a TPA is technically temporary (and thus will need to be renewed on a schedule, typically annually), whilst a POA is a more permanent affair and that's why a POA is a pain in the rectum to setup.
I have made it extremely clear to my older (not even elderly) relatives to never, ever agree to anything involving TeamViewer or any other kind of remote connection on a computer or phone. Take a number to call back if they want (do not agree to be called back later), then hang up and call me. And never, ever click anything in an SMS: not only can I not really explain how URL structures work, but companies keep using scammy-looking short URLs that even I can't tell apart, so complete interdiction on ever clicking a URL in a text is the safest way. And if I call saying I'm in jail, ask me for my car model and colour.
But I don't really know how to explain to them what is and isn't a scam on the 40 billion apps you're expected to use for banking, travel, parking, utilities, communications, everything with it's own security systems, quirks and bugs[1]. It's probably only a matter of time before a scam gets through (luckily the relatives are mostly not credulous enough or greedy enough to fall for most of them), but that doesn't mean I should execute an LPA and remove access to everything for their own good. Not least at that point they'll probably not be considered to be lacking capacity, a necessary condition for using the LPA, by the OPG just because they don't understand their mobile network's new login flow.
[1] which won't be fixed because most of these apps are consultancy effluence and they've been delivered and signed off on. So, the consultancy doesn't care any more and the recipient doesn't know how to maintain it even if they wanted to. Not only have they probably not got their own engineering these days, the app is an unmaintainable rush-job that is 90% technical debt and enough duct tape to get it over the acceptance wall before anyone notices. At best the issues will be fixed when the app is so completely untenable that another consultancy gets hired to rewrite from scratch. Then everyone gets a new app and a new set of "is this a scam" decisions to make.
It need to be done every time and it needs to happen frequently enough that people internalize an expectation that anything else is sketchy.
Now, how often does a bank representative call you? For me it's like once a year when their fraud department thinks that one of my monthly bills is sketchy, even though they've been unchanging for years.
Is that enough to build an expectation? I don't think it is, particularly for elderly clients.
Whenever I get a call from somebody claiming to be X organization I assume it's a fraud by default and don't provide them with any personal information. It has worked fine so far, as far as I can tell.
Though it might be helpful if the customer noticed the attacker didn't ask for the confirmation and became suspicious, but that's probably a small number of people and scammers are very good at allaying such worries with plausible excuses.
Background: Monzo froze _all_ of my bank accounts for nearly 5 days after triggering some fraud protection measures. Great in theory... until you are completely unable to speak to anyone.
I suspect phone calls only happen at the very edge of rare branches, with elderly or handicapped clients, complex transactions, when ID checks fail, etc. They might not do it at all, and had added that feature in the rares of cases they might — but making it visible as “this changes color if we call you” makes a more compelling story than they previous “we never call you” if you are on the phone with a high-pressure scammer.
> Don't depend on another channel for resetting any of the credentials.
What if a customer's house burns down with their phone and Yubikey in it?
> For person to person instant transfers, have velocity limits and legal framework to clawback and prosecute in case of fraud.
That's not up to a single bank.
> For large value transfers, require payees to be added to the account and have a 1-2 days cooling off period.
"Why are you telling me what I can and can't do with my own money!?"
Sometimes, large value transfers really do need to happen quite spontaneously to a previously-unknown recipient, e.g. for a used car purchase.
> Use a pre-registered and securely couriered FIDO2 token (Yubikey)
That would indeed be great, but not a single bank I've done business with supports FIDO. In fact, I haven't even heard of one that does (I might just open an account with them!)
Banks are awful enough with software, I don't want any hardware from them. Increasingly mobile apps are becoming first class citizen for online banking, web browsers second class. There doesn't exist reliable non-infuriating workflow with physical security key and a smartphone.
Does this work with a privacy-respecting ROM like GrapheneOS? If not, then it's nowhere near the best solution for me.
Sounds like a cool service.
And of course, their "scam-like" emails end up in the inbox, while real scammers emails would end up in the Spam folder.
Judging by their frequent and long lectures about how I'd be liable for any fraud, it sounds like they've absolved themselves of responsibility too well to need to improve fraud protection
They send email from an unfamiliar domain, not the one customers know from their website, nor a subdomain thereof
They call customers and ask for security information
They ask for one-time codes on some calls from customers, but they also separately say it's something that only fraudsters do
All of the above risk causing customers to lower their guard to fraud
They fail to recognise repeat payees to validate payment details when taking international transfer instructions by phone, which risks fraud (if an invoice seeming to be from a regular supplier is actually from a fraudster) or other loss (if the payment details are misheard)
They also fail to recognise repeat payees when using transaction history to flag unusual activity, which only increases false positives, so it isn't as bad, but it's still annoying
Prime example, Santander
From: Santander <santander@email2.yoursantander.co.uk>
Subject: Know more about Facebook Scams
Congratulations Santander, you've now trained your customers to trust emails from domains like "email2.your<business>.co.uk"
Perhaps you meant this the other way around?
Either way, I have received quite a steady stream of rather obvious phishing attempts directly to my inbox on Outlook.com. Once our twice a month I have a missed Amazon package, or some horrible debt, or an being investigated for tax fraud or other such.
But if a scammer sends me a fake email, it'll probably get caught in the spam filter of my email provider (hopefully).
I still forward all these "training" emails to abuse at corporate because if I'm doing extra work, they're doing extra work. Recently, they've automated this though because when I email abuse, I immediately get a reply saying congratulations, this was a test message. If this were a real bla bla... Anyway, I think it is safer to forward to abuse just in case.
Except they don't do it as a teaching experience, but as part of their normal operations, and if you refuse to do the extremely sketchy, red-flag, never-do-this thing, you will not be able to get your task done.
I've been required to provide part or all my online banking PIN on the phone and my credit card PIN on a random sketchy website (as part of 3DSecure). Different banks. Both legit and repeated.
Also wtf
I am on monzo.com
Better? Mix and broadcast authentication beacons over the audio channel. If it got there, by whatever transport the audio did, you're good to use them as a MAC against some key.
There are many, many ways (modems of a kind) of putting an (almost) inaudible signal into audio. Those could easily be short message authenticators, just a sequence of digits that derive from some frames of the audio, they might sound like little high frequency blips. Can you see how that might work?
[edit]
Forgot to say; those frames would get hashed along with some private part of a public key, or sym-key that only you (the user) has. A fake caller wouldn't be able to spoof them easily, and so they wouldn't decode at the client side correctly.
Of course you could build standards in at a point closer to the radio basebands. I mean, why is basic source authentication not built in as far back as SS7 given we had the technology even in the 1970s?
The only time you'd be using the app would be if receiving a call from an untrusted caller. And if you don't trust the app period, then the game is off anyway. In theory the same app could hold certs from a number of "trustworthy" sources you might like to check; much like a TLS certificate.
But in the end you'd wind up with too many, and hard to keep track of, and then buffoons like those from the EU commission would be wanting to "force trust" upon you to authenticate "approved government sources" - Which sadly is the problem with all source authentication schemes that work with PKI this way. You really need to keep the application layer relation 1-to-1.
I prefer simpler, elegant solutions - like your bank should never call you or push ANYTHING which is why I called it both a good and bad idea, and generally I distrust the whole ecosystem, of "apps" anyway.
Monzo could open some branches, where it's somebody else's problem to verify the identity of the staff in the building and you can be quite certain the person behind the desk is in fact an employee
(Edit: I know they're a 'challenger' bank)
I think that "app based" banking is a shitshow, and will only get worse, and ultimately more insecure. The entire economic strategy of dehumanisation is a catastrophe in the making.
And clearly there is no genuine market demand for it, people hate it with a passion, but it's being forced on the population, probably for other reasons more nefarious than "convenience" or "efficiency".
That said, if you're going to do telephone banking with another actual human over an audio or AV channel - which is an acceptable mode of interaction for me - then you may as well employ that information stream for more sophisticated authentication as we go into the age of AI deep-fake voices and video.
Because authentication doesn't need a terribly large bandwidth, indeed we can do it with tiny amount, side-channels within the audio stream see a good leverage point.
My experience with talking to banks on the phone has been that common security measures seem laughable to me - like "last four digits of your SSN" laughable.
Like all things it's more secure in the hands of people moderately educated in protocols and sufficiently sceptical.
A general security problem, perhaps a paradox, is that the more we try to hide it for "convenience", the more opaque and automatic, the more people come to blindly depend on the mechanism at some other layer and stop thinking.
I suppose what makes voice based interaction more secure is that it's slower. It gives more time for levels of security in depth and for people to figure out something is amiss.
But we'll have to see how that pans out with sophisticated voice-spoofing technology because I expect most people, even well educated and sceptical ones, are easily flipped into trust mode by the sound of a seemingly familiar voice and some clever replay attacks.
You can't rely on people being able to talk on the phone for accessibility reasons, so it should never be necessary to call people on the phone.
Instead, handle things by the app or wait for customers to call you.
> Remember, we will never call you without arranging it with you first through in-app chat.
i had someone call me recently claiming to be from coinbase and try to get me to enter a password reset code into a site hosted at “w-coinbase.com”. they claimed my account was compromised and “locked” (it wasn’t).
i humored the guy and asked for a help page from coinbase that listed “w-coinbase.com” as one of their official domains. they genius asked me to trust him, or i could talk to his manager who would share my ssn with me as “proof”.
i talked to the guy for like an hour asking him to put himself in my shoes, or explain why i couldn’t address the issue myself with a password reset or redoing my mfa setup. he got really angry, saying i was berating him for doing his job.
i suggested he give me a case number and i’d call back into coinbase’s support line. he gave me a six digit number and then hung up abruptly when i said i’d call him back.
it was glorious.
anyway, every one should have a feature like this.
Read about the stories here https://old.reddit.com/r/UKPersonalFinance/comments/17kvo4j/...
>TSB reimbursed 15 times more customers’ fraud losses than Monzo in 2022
https://www.theguardian.com/technology/2023/oct/31/tsb-reimb...
Company calls consumer via their private company-to-app system, app alerts user of an incoming communication request, and user accepts and has a voice conversation.
Then of course it becomes a question of the security quality of the app and communication design between it and the company, but presumably if that is broken then any app-based status or verification would also be broken.
You wouldn’t want it to ping these services on every call, so it would have to be an action you just train people to do.
Better than hiding it in an app though, this should be an OS concern somehow.
Hate them, they closed my account a few months after opening it without any reason or ability to appeal.
I did nothing wrong, just a normal user, was just testing it out the first couple of months so didn't use it for much, was about to move everything over to it and then they closed my account and i can never have an account with them again.
Awful company, who pretend to be friendly and cutting edge, but just gatekeep customers and cut them off without warning for whatever reason they wish.
Anyway, a frequent scam here is that someone calls you claiming to be the police or the government, and then generates a SSO request on your phone via trying to sign in to a government website using your EID number, and the request certainly adds a layer of seeming authenticity
I can barely handle adding a calendar event while on a call without accidentally hanging up or something, what a weird UI.
Why do they not just contact you via their installed app if they're going to assume you have it installed...
Banks should not call you anymore since it cannot be trusted.
https://niebezpiecznik.pl/post/istotne-zmiany-w-aplikacji-mo...
2. Bank confirms your identity with some inconsequential piece of information: a verbal passcode, the approximate dollar amount of two recent transactions, etc.
If the bank initiates the call, ask for their name and call the bank back.
Or, maybe I'm just a skeptical curmudgeon...