Anyway they needed to verify my identity, so they ask me for some info from the back of the card and a phone number that they can send the OTP to. I give them a phone number, it's not even the one on the account, they send the text to it. The text message says that the bank will NEVER ask for the code over the phone. They ask for the code, I give it to them, identity verified.
This regularly blows my mind.
Presumably it’s some data broker or phone carrier integration, because for me, the answer is usually “sorry, we can’t verify that number, is this a postpaid contract in your name?”
No, it’s not. Oh, that’s a requirement for doing business with you? In that case, I won’t.
And if a company can’t be bothered to have a fallback verification flow in case I do lose access to my phone number somehow, that doesn’t increase confidence either. I’m a person, not a phone number.
E.g. Blizzard (assuming they still do this)
If they want to be aggressive about fraudulent activity, fine, but don't restrict perfectly valid phone numbers from being used in their required 2FA scheme.
"Hi, I'm XYZ from XYZ background checks, I'm conducting your pre-employment check, and I just want to confirm that your full name is V, your DOB is W, your place of birth is X, your address is Y and your full SSN is Z...
... and that this is the correct email address for you. Please confirm."
Holy hell. Thankfully I reached out to the employer about this (and the background check company's attempt to reach out to my partner on Facebook for ... something? This wasn't a security check, just a regular employment background) and they were as horrified as me, apologized, and fired their background check provider.
Out of interest I clicked on the link in one of their "phishing" emails and I was redirected to a link where they essentially told me "never click on links in emails, you never know where they lead to". One week later I get an email "please click on this link to complete the second part of your course". Obviously I never completed their course, they told me never to click on links.
What's even worse is that they don't even use their own domain for the courses, but some random looking domain.
I also did this at work, and yeah it was a fake phising mail sent by a security company, and I had to do a quick 20 min online course on email security best practices. Yay. Me and like 3 other dudes, who clearly all also understood it was phising and were just curious about the scam.
Just shows how bad they are at faking it.
Although, I haven’t had many instances of communications from my bank where I cared about them authenticating. Like, if they tell me there is a problem, I can go check it out through the app, website, or whatever the user-initiated channel is. When I feel like it.
I ask what the basic issue is, then call the general bank number (or a number to their department, which I validate online before calling it). That way I’m initiating the call to a trusted number, and they can go through their process to authenticate me. Every time I’ve done this the person calling has understood and seemed to appreciate the caution.
You could ask them to list your last 3 transactions, and their exact amounts. Easy to cross-reference by looking at your banking website / app.
It isn't. China is the best example that draconian identity verification / KYC processes don't stop scammers.
Since WeChat allows accounts created outside of China, it's these accounts that are used. And it's why there are times it's a pain to create a WeChat account outside of China.
The financial transactions all take place outside of WeChat.
I've never heard of this, I'm very curious.
They are not worried that someone is going to come in, and steal your appointment. They are worried that someone with the same name as you might show up on the same day and the doctor might treat the wrong patient with the wrong information.
This is an completely different risk profile than a form on the internet.
I have the same name as my father (first and last, , different middle). We live at the same address. It’s a small town so we share a lot of the same doctors. We use the same pharmacy.
For just a bit of extra spice are birthdays are only two days apart.
A person she hadn't seen or talked to in 20 years had moved to this town neither of them were from and named their kid the same name.
Because I have literally seen this go wrong: “Mr John Smith, you’re here for procedure X, yes?” “Yes” Some other provider overhears: “I thought that was Mr Jones for procedure Y” “Are you Mr smith or Mr Jones?” “Mr Jones” “Then why did you say yes when I asked if you were Mr Smith” “I assumed you knew best”…
People do weird things in healthcare settings
The weakness is in the processes and the lack of critical thinking skills of people executing processes.
They have metrics and bosses. They do what they’re instructed to do by the banks, full stop. Or likely more precise the company that the bank contracted for the service.
It’s dehumanizing to suggest these folks lack critical thinking skills, given the incentives of the whole thing from the top down incentives their behavior. They’re only responding to the incentives of the system
It asked better and more relevant follow-up questions than any other technical interview I've ever had with an actual human.
I swear, if I got one wish from a genie, I would banish the phone from existence. It's the worst for goddamned everything. Video calls, skype calls, discord, email, texts, messaging, literally everything is better than the shitty old phone.
Talk about training people to give away sensitive data.
That's what you're supposed to do. That's what security is. That's the sensitive data that ensures it's not a rando calling who stole your card.
I'm not sure what alternative you are looking for? You're the one calling them, so it's fine.
> You're the one calling them, so it's fine.
Again, normalizing handing over complete CC details on the phone makes it much easier for scammers calling to succeed in asking for those details.
Basic customer service lets you do things like transfer money too, so you need something just as secure as a PIN.
So why would you want two different security mechanisms? Either it's you or it's not.
The banking system is so backwards in the US it's actually insane, you've just got used to it
YOU calling THEM is not an issue. That's the secure connection. There's not (afaik) a way to hijack the receiving phone number.
The issue is when somebody calls YOU. Faking the originating number of a phone call is easy, happens all of the time. That's the scammer route.
SS7 call routing and rogue 2G base stations are some potential approaches.
In terms of banking security, a good (ideal) architecture would treat the user PIN as a credential which is not transmitted over insecure means. Unfortunately many banks don't do this right, and still support bank-side PIN verification (with the PIN sent over the wire to the bank), rather than using the bank card's smart card features to carry out on-chip PIN verification.
If you built a bank from scratch, for security first, you'd likely still use smart cards as bank cards, but you'd only do PIN verification on-card, so the user PIN is never exposed to even the bank - the card can securely vouch for the PIN in a manner that's far more costly for an attacker to defeat than using a $5 wrench against the user of the card to make them reveal the PIN (h/t to XKCD).
Sending the card number and PIN over the phone is just asking for trouble - mobile phone calls are decrypted at the base station and available in the clear, before being transmitted up into the wider telecoms network.
For 99% of people, 99% of the time, what they need to worry about is someone calling them suspiciously asking for key information.
The fact that targeted attacks like that exist does not make it a good idea to treat them as ubiquitous. People with the kind of money that would make executing such an attack worthwhile should be expected to take higher precautions than the rest of us with it.
Edit: changed Klarna to Sofort
Send people to the website to find your number, idiots.
Spirit of the law: [ ]
Upon calling the number, you get an automated system that immediately asks for your social security number and won't let you proceed until you do.
The phone number was nowhere to be found on the bank's website nor did it appear in a single Google result.
Sounds like an obvious scam, right? Nope. It was genuinely one of the bank's official phone numbers, and I had to nag them through three separate channels to get them to add it to their website, which they did a week later.
The actual truth is, though, that the security theatre that they put on is about all that can be done when two strangers meet to prove identity.
Hey you do you know a secret that we know about you? Here's a secret about us that you are supposed to know.
You should have looked up the ssa site and found the number that way.
Why has some startup not solved this problem already?
It is many problems with many solutions.
tl;dr - bank calling you can do auth digitally on phone, but don't do it and don't advertise it to clients.
PS: I'm in EU.