Vanguard conditioning users for phone phishing atttempts
benplesser.com
benplesser.com
From a security perspective, this should never happen. The author is absolutely, positively, without a doubt correct in his stance on this. Being called in such a way and having very little and/or weak security protocols as described is not only a security breach waiting to happen but it really is, as the author points out, training people to get phished.
But there's a bigger picture here. And that's the picture of Vanguard as a company having years of experience in talking to, working with, dealing with, and learning about their customers. Just like the manager says in the post, they need to balance security with service (no they're not mutually exclusive but they're not one and the same either).
In the end I think this okay. It's not technically correct but it seems like its the right thing to do. Now the reason for this call is never described (which gives some credence to the theories here that this actually never happened along with a lack of other details) but assuming here for the sake of argument that the call was just to talk about something that isn't of super high significance (let's say it was a sales call to upsell something) then a couple of security questions should suffice. If it's to talk about a 10 million dollar bank transfer to some off-shore account then maybe we should be in an uproar here.
Another point to consider is who is responsible for security? Obviously the company that hold your data should be reponsible for the safety of that data and should have measures in place to prevent fraudulent access to it. But then there's also the responsibility of the customer who needs to take care of their account credentials and make sure that if someone accesses one of their private accounts somewhere that there isn't a domino effect. I don't think it's Vanguard's responsibility to make sure that all of their customers use different, long, and random passwords on their Gmail and Facebook and what have you so that one day someone can access one of those and get into their Vanguard account. I mean, that's certainly a nice-to-have but customers have a responsibility to secure their data just the same as companies do. We want to be educating regular folks about security all the time but the moment it comes time for them to apply what we're teaching them we turn around and act like they're off the hook for being ignorant of security best practices. It's a double standard if you ask me.
I know we all like some good old fashioned manufactured outrage but before we get the pitchforks out let's look at the big picture, and not just one aspect of the issue here.
No need to believe me about the "truthfulness of the claims". Just call Vanguard yourself and ask if they handle cases this way. They will confirm.
You ask about security responsibility. I absolutely agree with you that customers have to take on a lot of it (Vanguard is not responsible for creating a 20 char password on your behalf).
I do think, though, that you have to draw the line before training your users to accept phishing attempts. That is what is happening here.
My biggest reason for pitchforking Vanguard here is that, for many people, they hold more assets than commercial Banks. Their security protocols should have HIGHER standards.
Thanks for bringing more attention to this. Personally, I think it is a fairly big deal and a responsibility that Vanguard should shoulder more of. They aren't providing free checking, or free email, or anything of that nature. They are taking money (pretty good money) for a financial service. Their web presence has improved by leaps and bounds and I'm surprised that this hasn't changed.
bpatrianakos is also right. Security has to be balanced with service. I think Vanguard's call would be okay if the security questions they ask are compartmentalized. What I mean by that is that they have separate security questions that they ask in a low-security environment (like an outgoing phone call) that they will never trust for high-security actions, such as withdrawals or password resets. Those actions should require a further level of authentication and should never be done via outgoing correspondence.
We should at least confirm that the security questions aren't compartmentalized before we break out the pitchforks. However, given that Vanguard limits passwords to 10 characters with limited support for punctuation, I don't have much faith that they have any sort of compartmentalized security.
The only reason why there are limits now is that there is code running on their servers specifically stopping passwords that are longer - which is insane, if you think about it - they are actively preventing people from creating stronger passwords. I'd rather create a 20-30 character password with no specials (which is still massively harder to crack than a 10 char with all possible specials), because it is easier to type in on mobile, but with this system, I couldn't - which is dumb.
I thought they didn't accept all special characters either, but I just successfully changed my password with special characters that I don't remember them accepting last time I changed my password. I was successfully able to log in using a version of my new password with the case changed for some letters.
if i were a black hat, targeting a place like vanguard would make so much more sense than going after a bank.
"Hi, I'm calling about some suspicious transactions on
your account which I'm fairly sure aren't authorized, but
I need to confirm with you just to make sure."
"Can you tell me what those are?"
"Sorry, I can't reveal specifics unless I can confirm I'm
talking to the authorized account holder. [Ask security
questions.] Thank you. Did you make a transfer of $500 to
Pharma Laboratories in Albania?"
"No."
"That's what I thought, we'll go ahead and cancel the
transfer. Your account will remain unaffected. Thank you
for your time."
The only defense against this (other than initiating the call yourself) is to casually give obviously wrong answers, and see if the rep accepts them blindly. If your first pet's name was Buddy and you say Ninja, a real rep shouldn't accept that. That should work until a really sophisticated operation tries to do a live man-in-the-middle attack.I know my account manager's name, so it is less of a concern, but that's only because she's helped me out on some thorny issues. I could imagine this being more problematic if there isn't a pre-existing relationship.
The solution? I never answer the questions. I ask for their name and a number/extension that I can call back from. I then either confirm that it matches the ones I know, or call their mainline and request to be transferred.
Anyone using common security questions is already balancing a risky behavior with ease of use.
They might also know that risk is low - if they don't allow any difficult to reverse transactions like outbound fedwire there may not be a lot they can't easily undo.
Phishing for this kind of info is stupidly easy though, and while call-centres quite definitely do condition people to be phished, there's not much that can be done when people are so willing to be fast and loose with their personal information.
Go tweet/facebook the following, and prepare to be astounded by how naïve most are:
"Want to know your porn star name? Just take your first pet's name, your first school's name, and your mother's maiden name! Mine's Muffy Grove Schlitz!"
A side-benefit of this is that if someone calls me and asks me to answer a security question, I won't know it. I'll be forced to call them back after I've opened 1Password and pulled up the record with the security questions.
I follow this protocol with American Express and it's always effective. I'm also a high dollar monthly spend (corporate account) and so I get answered within a couple rings and they can pull up my account and notes immediately.
-David
I contacted Vanguard regarding this and forwarded them the email. The representative thought it was a phishing attempt as well. I was later contacted by Vanguard and they told me it was legitimate. I was even able to contact the person that wrote the email through a Vanguard number.
https://personal.vanguard.com/us/ContactUsSecureEmail?isCont...