Called my local bank and they confirmed this was legit, I almost went off on a full rant about how bad their protocol is for this.
It’s kinda nice because while doing this, they also educate their customers to never trust such a call and to rely on official information to contact them.
The Dutch ING now has a new thing where you can verify in the banking app if it's them calling you:
https://www.ing.nl/de-ing/veilig-bankieren/wat-kan-je-zelf-d...
(I guess in some sense it's a step back because the bank is calling you again, but it's nice that you can verify it live in the app.)
Branch staff are all perfectly lovely, but they're at the mercy of very funky systems above them.
I am assuming card-present transactions? Because I order things from all over, not just locally.
I do appreciate the fraud protection but authorizing my ATM card for non-US withdrawals is overly specific and extremely annoying and time-consuming. Plans change? Expect to spend 15-20 minutes on the phone to say “yes, I will be in Portugal for one extra day”.
I always made a point of telling them that they had called me, that I had no proof of who they were, and that I was going to call back from the published number.
A few days later I found out the call really was from the bank, and the bank had blocked my account, in a way that took a long time to unblock (don't get me started...). As ever, I found out the hard way, when I needed to use the account for something in real-time and it wasn't available.
But the call was from a different department than general customer support, the department's number wasn't known to customer service, and the account status change wasn't visible to customer service either.
So the bank's own customer service thought it was a scam call!
The example that comes into mind is making transfers to my wife, where every time I do it, they ask me to confirm a bunch of questions to make sure it's not a scam/fraud, which fine, good idea. Once I confirm, they display another notice telling me they won't ask for a confirmation/2FA code because I make transfers to that account so frequently.
The only reason I can come up with why it is like that, is because there isn't a single person/group responsible for the full experience.
I saw some bank from Florida, that I'd never heard of, calling me on my cell. I assumed it was some sort of scam and ignored it. They're too stupid to get a phone number which has caller id set up to read the name of credit union with whom I did business.
Just amazing.
> I think they don't have any people working on the full UX flow
Probably right, but this is the importance of dogfooding. I really think this stuff happens because everyone is in such a rush and doesn't take a few minutes to think things though, which requires thinking about everything as a whole.A week later, I phoned up the bank asking why everything was progressing so slowly and they said I'd failed the security check, so the process had been paused. I explained what had happened, and how it was ridiculous that they expected personal details without even saying they were from the bank, which they seemed to agree with, but said that was their procedure so it was my fault for not complying.
This is the most fascinating (infascinating? like, infamous/famous distinction? whatever) things about bureaucracies, to me: they sincerely expect everyone to follow their internal rules and procedures, even the people who are completely outside their jurisdiction by any stretch of imagination.
Like, "we require the application of your personal seal to the papers" — "Personal seal?.. we use signatures in this part of the world, you know" — "No, we don't accept signatures, it has to be a seal imprint" so then you just stamp some absolutely random rubber stamp and they accept it because even if they can't actually read Cyrillic, it's a stamp and that's all that matters.
I taught at a German university for a few years. And they way grades were handled was, you had to print a standardized piece of paper for every student with their name, date of examination, and grade, and drop them off at the secretary's office.
The secretary would stamp every such Schein with a rubber stamp. Then the students would pick up their Scheine at the secretary's office and bring it to the examination department themselves (!) to get the grade registered. Only at the very of my time there, they changed the system and I could hand in the grades directly to the examination department.
At any rate, the system was so stupid. It was trivial for students to print a new Schein with a better grade and register that (there must have been a lot of fraud). But the counter argument was 'no, it's very safe because the students do not have a rubber stamp'. Of course, the rubber stamp was just the university logo with something like the faculty name next to it. Trivial to copy (or make a rubber stamp for more enterprising students).
Probably the procedure had been followed since 1573, well before home printers, scanners, phone cameras, or get-your-own-rubber-stamp-for-a-few-bucks internet shops.
This is almost always how these seemingly silly bureaucracy hoops become established. They were created in a prior time where a third party obtaining "magic item Y" with which to authenticate was significantly difficult to near impossible. Then, over time, the world, and technology improve, to the point where anyone, willing to spend $9.99, can have an exact duplicate of "magic authentication item Y" manufactured via any one of 78 different makers. But the bureaucracy continues using the now outdated process because "this is the way it has always been done".
It is largely a real world example of "The Monkeys, Bananas and Ladder Experiment": https://psychologyfor.com/the-monkeys-bananas-and-ladder-exp...
When they could just cut out the middle man and just make fraud itself illegal and not require the magic item at all.
Sometimes it becomes truly ridiculous: I once had to apply for some thing, and was told I need to grab and provide them some certificate from a different government service to prove that I'm actually eligible. Okay, I do that, and then they spend two weeks verifying the certificate by physically mailing and inquiring info about me from that other service and waiting for them to respond (also by physical mail).
My entire career is predicted on the things I did with a stack of university letterhead 40 years ago.
They wanted a government issued identification document with both photograph of the individual as well as their physical address on it.
No such document exists for South Africans, I offered to get attestations from lawyers, police, but nothing was good enough.
Then I had to threaten charging back the credit card to get a refund (as opposed to credit) on the not-insubstantial fee for a service that their verification policies made impossible to be fulfilled by South African entities.
We succeeded with DigiCert, was a bit involved including getting sign off by a certified security consultant that we had appropriate procedures in place to protect the private key, but eventually got through the process.
But generally happy to not be using them these days. I do our domain registrations through Namecheap and can't say I've ever had an issue with them, also had to interact with support on occasion and also no negative experiences there.
They were a _little_ more cooperative about it though.
"Hi this is <Person> from <ABC Inc.>. Can I start by confirming your name and date of birth?"
"Who is this?"
"<Person> from <ABC Inc.>. Can I start by confirming your name and date of birth?"
"No, you may not. What's this regarding?"
"I can't discuss that with you until you verify your identity."
"Okay, well I have no idea who you are so I'm not about to do that."
"Well, I can't tell you anything else until you confirm your identity for me."
"Okay."
"So can I get your name and date of birth please?"
"No."
"..."
"..."
"..."
"..."
"Can you tell me what _day_ in January of 1970 were you born?"
I'm sure it broke some rule somewhere, but at least giving me some verification that they already had some of the information they were asking for I was willing to play along.(Turns out the ISP did their usual ISP thing and failed to mark that I'd returned my modem when cancelling service a few months prior then told no one and sent it to collections. The debt collector was very adamant that I needed to set up a payment because this wasn't going away. I walked into one of the ISP's retail outlets, told them what happened, they sighed heavily because this comes up _constantly_ and called in to have it marked returned and I never heard from anyone ever again. The end.)
Spectrum did this to me. They sent a single "hey, you owe us for this thing" email before sending it to collections.
The best was that certain sections were circular, so it would start to ask the same questions again but displaying answers prefilled in - yet it would arbitrarily forget particular (different) details on each loop, defaulting to values other than what you'd entered before, so there were only certain points you should exit the loop at, to be sure it would submit the right information!
On the plus side, despite their system woes, they had very competitive rates, so it was definitely financially worth spending another 20 minutes and accepting their idiocy!
Also, now I remember that I also had to jump through some deceptive hoops. The deal was technically only available on the graduate account, which my account had stopped being earlier in the year because it changed to a regular account after 10 years from opening. The bank manager said she'd bend the rules and let me have the deal as an exception, but then presented me with a load of life insurance policies to sign (which of course I didn't want or need) and it was strongly intimated that if I didn't sign them, she'd no longer bother bending the rules to get me the mortgage deal. So, I signed them, and as soon as I had the mortgage confirmation letter through the post I phoned up to cancel before the end of the 14 day cooling off period. I dread to think how much commission she'd have made from me if I didn't cancel.
When my father calls his bank, they actually verify him by sending a 2FA code to his email that he reads back.
Three guesses on how you log in to the service.
Hardly. The company shouldn't have XSRF-vulnerable software, if your browser is vulnerable you have bigger problems and what you actually shouldn't do is enter your credentials or download stuff after clicking on that link.
But of course there's an internal "phising test" that penalizes you for clicking on links... links that have been obfuscated by some email-modifying link-tracking security software that makes it nearly impossible to figure out to which domain the link even goes.
Then why even click on it in the first place (and risk your email address getting flagged as active in some illicit database?)
Generally clicking on the link is not what gets you compromised (except for some spearphishing involving zero-days...). It's actions following that which might. So they're barking up the wrong tree and penalize people for that. That's just chicanery.
Do as I say, not as I do.
Then the goddamn CEO sends out an empty email, with a .docx attachment, and the subject saying "urgent, open immediately" The HR sends out suspicious looking shit all the time. The. You have Microsoft spamming you with fucking QR codes!!!
You know what needs to happen? Disable all hyperlinks in email. Make everybody copy and paste the goddamn thing. Then they have to look at the link and they have to manually paste it into the browser. Then there are no obfuscated links. Also disable HTML email, images, and most file attachments. Then there is no pixel tracking, no possibility for malicious images to be auto-loaded, and no excuse for clicking a bad link.
I cannot write a check at Walmart today. Not that I would; it’s antiquated even by US standards to do so. It’s that they fucked up and blame me, 30+ years later.
Even better when it's a bank you don't use and the number on their site goes to an automated system that won't let you access it without an account number, so you have to scrounge for alternative phone numbers to get to talk to someone.
In Gmail or Thunderbird they don't just show the PDF and since they display the sender differently it makes it obviously a scam.
Sometimes it feels like companies are just helping scammers and I don't know why.
There's a lot of similarities to scamming and marketing. In particular, they both have essentially the same desire for well-designed messages.
It's not a good system if it's hard to differentiate. We should be encouraging making money by providing meaningful value to the people buying the product. To get those things aligned. I think we engineers can play a role too. While not having the ultimate decision I think speaking up and just pushing here and there to prioritize product quality over profits goes a long way. In the long run, I think quality and profits are usually aligned, though I think rarely in the short term
Problem is, one of the most common check frauds is check washing. The PTO line is changed to a fraudulent name, and the amount stays the same. So, yes, the amount matches a legitimate payment, but who was paid? Ha!
Mine actually tries to ask for PII and I tell them to kindly fuck right off and go to my bank website and ask them what the fraud number is.