10 ms·
My bank keeps on undermining anti-phishing education
- wykmbh666 1y ago[dead]
- Rygian 1y agoFor me, the money shot is Chapter 4: the bank needs to be held legally accountable of gross negligence for sending phishing-resembling emails to customers.
- constantcrying 1y agoHow do you hold someone legally accountable for a non-crime with no identifiable victims? Especially for "gross negligence", when the negligence is very clearly minor.
- TimTheTinker 1y agoThe naive people in decision-making positions often don't realize the risks involved in their behavior until they or someone near to them gets hurt -- in this case scammed or sued. We used to have a lot of people like this running businesses in the US before roughly 2012, but white (and black) hat hacking began spreading quickly and made generally short work of the problem.
- bunderbunder 1y agoI also suspect that the social dynamics of these kinds of organizations make it difficult for the right people for making these kinds of decisions to rise to the right positions for making them. There's almost a catch-22: setting good, effective policies tends to involve a lot of telling people "no". And it's hideously difficult to do that without ruffling the feathers of people who control promotions.
- AnimalMuppet 1y ago"Let me explain why that would be a career-limiting mistake for you..."
- TimTheTinker 1y agoYeah, fear of consequences (due to something bad happening) seems to be the only way to both motivate and justify adopting more secure practices and policies.
- Mtinie 1y agoConsidering that on paper these businesses all have employees serving as CISO, EVP-, SVP-, and many, many Directors of Security, I find it highly unlikely that the accumulated experience of the people and their teams results in decisions like this. It's hard to distinguish incompetence from malice in many situations but calling them "naive" seems to be indirectly excusing customer-hostile behavior. It doesn't make any sense to me because it's expensive to make sure your company's services are secure, but it's also expensive to not be secure. Perhaps it's less expensive to not worry about it because the loss-of-customers impact on revenue are still under the cost of doing it right. If that's the case it's a sad state for all of us.
- TimTheTinker 1y agoThe example given in TA seems to be a straightforward case of institutional naivety (banks doing stupid stuff that confuses customers and makes them prone to potential identical-appearing phishing attacks) -- for which the only solution is for decision makers to be convinced that something needs to change. I don't know of anything that can convince a group of leaders making money and doing fine to change besides fear. Perhaps the US with its lawsuit-happy culture helped propel such changes more quickly than in Western Europe.
- stantaylor 1y agoI used to work for a financial services company that had a strong and well-managed security culture. The company got acquired, and afterwards, we kept getting emails from third parties for various things, all supposedly initiated by execs/groups at the parent company. We employees of the acquired company discussed the emails in Slack: we were sure that these emails were legitimate, but acting on them would have broken our security policies, so we all decided to all report them as phishing attempts. We understood that we were engaging in malicious compliance, but our actions were also a best practice, so we couldn't technically be criticized for it. After a while of this, execs at the parent company would send out sometimes exasperated-sounding emails ahead of time, alerting us to the email that we should expect to receive and how they wanted us to respond. Of course, that led to discussions of how we know that that pre-email emails were legitimate. After a while, we all lost interest in this malicious compliance and adopted the much laxer security culture of the acquiring company.
- x0x0 1y agoI had to fire the MSP I hired because they needed to install some software on everyone's computer, so they sent a company-wide email, with no clearance from anyone, directing approximately 40 people to open terminal and paste in a string sent in that email. Along with instructions on how to open terminal. The absolute last thing anyone competent does is train employees to receive communications like that in email and follow them. If they'd asked for 3 minutes at an all hands to prep employees, or announced in slack, or something similar then ok. Or some out-of-band announcement that this was legit.
- deleted 1y ago[deleted]
- 0x5FC3 1y agoUser facing tech and marketing practices at banks are the worst. Every Indian bank login form I've ever had to use is - hostile to password managers. - You cannot copy paste passwords. - Client side password hashing - Stupid requirements like the password cannot have more than 15 characters and even have a whitelist of character sets! (Looking at you HDFC) - And of course, run of the mill spam They are all stuck in the early 2000s.
- eldaisfish 1y agoIndian banks and their websites are likely among the worst in the world. The fact that many situations require printing forms, dealing with SMS-based 2FA, multiple passwords, sometimes with different requirements… I’m not surprised that many Indians still prefer the hassle of visiting a branch.
- 0x5FC3 1y agoI assure you, dealing with the staff at the bank is different ball game altogether. I had to write 3 different "letters" (paper pen) to have a phone number typo (on their part) corrected.
- sometimes_all 1y agoThe branches are worse. Staff rotates _constantly_. Most of the new ones don't know anything, including most straightforward things people go to branches for. Almost everyone from the tellers to the branch manager is mandated to upsell/cross-sell something or the other, and in the most non-transparent way possible (so that the right people get the commission). Need a bank locker? Jack up your savings account balance. Need a credit card? Get a unit-linked insurance plan, else don't waste our time. A couple of tellers will start calling random people to sell things (in direct violation of central bank rules).
- never_inline 1y agoIndian government's websites (eg: IRCTC train booking, exam registration portals) are worse IME.
- 1y ago
- tbrownaw 1y agoSpeaking of normalizing bad habits, does anyone else remember when you were supposed to only ever enter your password into a site if you'd entered the address yourself (or used a bookmark), because if some other site had redirected you there it might be a fake? And then now we've got OIDC.
- whatusername 1y agoThat is less of a problem in the consumer space where the OIDC Auth providers have giant long lived sessions (google/FB/etc). In the government/banking/etc space - there is at least FIDO/WebAuthn/Passkeys which also resolves it. But it's a fair criticism.
- SAI_Peregrinus 1y agoWidespread TLS means you can now trust the domain name.
- delusional 1y agoHeh, we did something similar at the bank where I work. Our marketing department, tasked with getting people to complete some "ongoing due diligence" (a bank term, part of KYC), sent out a bunch of SMS' with links to a page (on a non-core business domain) where we then asked customers to enter a bunch highly personal information. The SMS contained a lot of scary language about your account getting blocked and stuff. I didn't know about it before my grandmother handed me an article from the local newspaper and told me some of her friends were worried about it. We laughed and I took the newspaper clipping to work and posted it on the wall of failures. Everybody in IT could immediately tell that this was a pretty bad idea, but we weren't asked. I'd link the article and provide more details, but I'd have to visit my local library, and maybe later.
- TheFreim 1y agoMy bank uses a fraud detection system that calls you if suspicious activity is detected on your account. It then asks you to call back a number to verify the account activity. Every time they call, they provide a different callback number. Searching for the callback number online yields only one result, which is the fraud detection systems web page telling you to NOT trust phone calls of any kind (their advice is solid, but it tells you to not respond to their own legitimate calls)!
- rightbyte 1y agoYe they don't follow their own rules. Once my bank called me for a insurance change I requested a month or so earlier and asked me to verify myself via the security dongle. Like, and then they act surprised when people are scammed.
- ralferoo 1y agoHeh. 20 years ago when I was buying my house, I was arranging the mortgage through HSBC bank. One day I got a random call, started by asking me to confirm my name and date of birth. I asked them who they were, and they refused to say anything before going through security. I told them I wasn't giving them any personal details without knowing who they were, and they hung up. A week later, I phoned up the bank asking why everything was progressing so slowly and they said I'd failed the security check, so the process had been paused. I explained what had happened, and how it was ridiculous that they expected personal details without even saying they were from the bank, which they seemed to agree with, but said that was their procedure so it was my fault for not complying.
- Joker_vD 1y ago> that was their procedure so it was my fault for not complying This is the most fascinating (infascinating? like, infamous/famous distinction? whatever) things about bureaucracies, to me: they sincerely expect everyone to follow their internal rules and procedures, even the people who are completely outside their jurisdiction by any stretch of imagination. Like, "we require the application of your personal seal to the papers" — "Personal seal?.. we use signatures in this part of the world, you know" — "No, we don't accept signatures, it has to be a seal imprint" so then you just stamp some absolutely random rubber stamp and they accept it because even if they can't actually read Cyrillic, it's a stamp and that's all that matters.
- _petronius 1y agoConsumer-facing financial services in Germany are really bad at this, and it is not just Sparkassen: a few years ago an email supposedly from our corporate credit card provider to all of the foreign nationals at our company asking for scans of their passport photo pages triggered a deluge of phishing reports to IT, who had to subsequently inform everyone that yes, the email did indeed look exactly like a phishing attempt, but no, it was real. I don't really know why the situation is so terrible -- there are many good and competent security professionals working in corporates in Germany -- but perhaps as the post alludes to it is due to a lack of legal or regulatory pressure to date.
- RandomBacon 1y agoMy bank has implemented suggestions I've given them in the past (USAA), but recently they used a different domain for a legitimate-seeming email (the email was about something I just did, and it was to an address I only use with that bank), and I called them up and spoke with someone in their fraud department to ask about it. I told them either they were hacked, or they were training their customers to fall for phishing, and asked them to create a ticket. They said that domain name was not theirs, and they only use usaa.com in their emails. They locked my account without telling me. I had to call them back to get them to unlock my account, and I think that person in their fraud department understood the issue and they said they created a ticket. We shall see...
- kakuri 1y agoI interviewed for a software engineering position at USAA. After seeing the incompetence of the interviewers none of the nonsense they do surprises me.
- unethical_ban 1y agoI worked in IT ops there for a long time, and since then have seen the inner workings of companies in several different fields. They had by far the most competent cybersecurity group I've witnessed. Things have changed in a decade maybe. But, they still use proprietary TOTP from Symantec which is annoying.
- freedomben 1y agoYeah I've never worked there, but been a customer since 2005. For many years there, USAA was really cutting edge of tech and highly competent. The system has slowly gotten a little less usable though, but at least it still works most of the time
- RandomBacon 1y ago> But, they still use proprietary TOTP from Symantec which is annoying. They at least used to, but I'm not sure they still do. (And when they did, I was able to copy the key into a MFA app of my choice.) But now as an end-user, it's all built in to their own banking app. I don't use the code from the app though, because I just use my personal 4 digit pin (after entering in my unique password from my password manager).
- Pxtl 1y agoDo these banks not have insurance companies looking at this liability and saying "no you goddamned idiots, we are not covering you."
- imzadi 1y agoMy mom was recently phished. The scammer got into her bank accounts and charged a bunch of air india tickets to her credit card and used zelle to transfer money out. When we reported it to the bank they said it wasn't covered because their fraud protection doesn't cover scams. So the banks just don't care. (It was Capital One FYI)
- notpushkin 1y ago> their fraud protection doesn't cover scams Eh?
- imzadi 1y agoWhen I talked to the bank I was like "So if she had just lied and said she didn't know how they got her information she would have been covered, but since she was honest and admitted to being scammed she is getting punished?"
- kevin_thibedeau 1y agoA retail bank with a massive advertising budget has to pinch pennies somewhere.
- FireBeyond 1y agoOne of Zelle's explicit design goals, couched in customer convenience, was as a mechanism to offload as much fraud liability onto the customer and away from the member banks.
- imzadi 1y agoIt wasn't just the zelle they didn't cover. They are expecting her to pay back the $3k in airline tickets charged to her visa (not a debit card).
- andrewstuart 1y agoMy bank: “Hello this is your bank can I please confirm your personal details?”
- seb1204 1y agoConfirmed
- GuinansEyebrows 1y agoi've gotten unsolicited calls like this before from my insurance company and when i tell them i don't provide personal information to people who just call me out of the blue and ask for it, they act like i'm from mars. then of course i have to call them back, sit on hold (and maybe get the same call center agent!) to verify their identity and conduct whatever business they originally called about. thanks, your bad practice just cost me an afternoon to deal with the inefficiencies of a private industry i think shouldn't even exist.
- seaucre 1y agoTo verify your account during online customer service calls, Comcast will text you a six digit 2FA looking auth code which you must provide to the Comcast customer support. Guys.
- deleted 1y ago[deleted]
- aivisol 1y ago> “Here is your Sparkasse. A very important document is waiting for your signature. Please visit paperless.io/548fkjgd7f to continue.” I mean this is just ... incredible. Are they living on the moon? Many real phishing messages are even more sophisticated than this.
- seb1204 1y agoI know this from sport events but often the lottery or prize draw are organised by external marketing companies. So likely this is one reason for not making it a subdomain. The other is that Germans seem very bad at this kind of stuff. Why the heck would the application for the German passport or Ausweis be published by some random GmbH and not Bundesregierung.gov?
- sp1rit 1y ago> Why the heck would the application for the German passport or Ausweis be published by some random GmbH and not Bundesregierung.gov? This way the government doesn't have to release information to the public (think FOIA) about it. Moving central part of government operation into a private GmbH wholly owned by the government has (sadly IMHO) become a somewhat common strategy for the government. Not just Governikus (the one with the passport) but also the Telematik (Health system) and probably some more.
- netsharc 1y agoBut .gov are for American government sites, and Elon's friends (oh geez I loaded doge.gov, it looks so dodgy...), and I assume the assignment of the domain names under .gov is done by somebody in the federal government, if they haven't been DOGEed as well. If any country's government can get a .gov domain, I can imagine the hacking that could happen, similar to hackers managing to infiltrate Bangladesh's central bank and almost managing a heist, but for a typo: https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery At least for Switzerland the federal government puts its sites under the domain admin.ch . And the Cantons have their own domains, e.g. zh.ch for Zurich.
- h4ckerle 1y agoFrom what I've seen, Austria also does this pretty well, with everything being on xyz.gov.at. The problem I see for germany is that the principle of subsidiarity is taken very seriously here. Everything is decided at the lowest sensible level of government. Consequently, there are many very tiny local authorities that have to manage things independently and lack IT admins.
- gwbas1c 1y agoI find there are a lot of people who just don't "get" written communication. Once I got a vaccination, and in order to do it I had to fill out a form where I chose the arm. The form said to circle either "right or left." The word "right" was on the left and "left" was on the right. I pointed this out to the nurse and she laughed, and then realized her error, because she made the form.
- pbhjpbhj 1y agoThis seems like it was correct - the view of the front of the body shows a third-person view. The labels are relative to the subject (first-person). Or in other words, looking at me, my right arm is on your left.
- phendrenad2 1y ago> So the next idea is to register the domain as a subdomain I think the problem is, someone in the IT department understands the high risk associated with handing out subdomains, so they refuse to do it. So other parts of the company "work around" this by registering their own domain name. I wonder how companies like Google handle this. A subdomain of google.com is probably the most valuable hack target in the world, but google does use subdomains occasionally (...or maybe more than occasionally! https://gist.github.com/abuvanth/b9fcbaf7c77c2954f96c6e556138ffe8 https://gist.github.com/abuvanth/b9fcbaf7c77c2954f96c6e55613...)
- mike_hearn 1y agoNearly. It almost certainly never even touched IT. The issue is that marketing is organizationally separate from IT and doesn't want to interact with them. IT is probably behind a slow, outsourced ticket based process and will take weeks to do a simple thing. They may also have random opinions about stuff marketing doesn't want them to have opinions about. So building out promos like this is delegated to SaaS services or contractors who also have no relationship with corporate IT. Then nobody in marketing really knows or cares what a subdomain is, because everything they do is just searching Google or clicking links. They never look at the address bar because it's always full of meaningless junk so why would they or anyone else care what's in it? Anti-phishing training doesn't make sense, when you look at how people really use the internet. Not many people look at the actual text of a URL. The best anti-phishing training is "go to google and type what you're looking for, only click links from there" and not "carefully examine the domain name to try and intuit if it's owned by the organization you think it is".
- cyberbanjo 1y agoHave you tried what you're recommending without an ad block extension recently?
- mike_hearn 1y agoI never use adblockers, so yes.
- edarchis 1y agogewinnen-mit-wero.de: It is pretty common to use a dedicated domain for a large campaign so that the spam complaints don't hurt the deliverability of your main domain.
- meindnoch 1y agoCool! Yet another way in which marketing is making the world worse!
- taneq 1y agoSome of the worst practices I've seen are from FedEx. When you order an international package, you get a text from some random FedEx employee's personal mobile number, containing a link to a website where you're meant to enter your credit card details to pay import duties. WTF? NO. I've called up about it and the support team were just like "ugh, yes, I know, yeah that's actually probably legit."
- I_dream_of_Geni 1y agoAnd here we are: twenty five years into the 21st century, and it is STILL this bad... SMH
- rightbyte 1y agoHah what. I would never have thought those scam sms I get all the time to pay duty had no real world counterpart. Like, companies are making it so easy for scammers to pretend to be them.
- hopelite 1y agoIt seems to me the better and simpler solution is to continue teaching your users that this pattern this bank engages in is in fact still the pattern of hostile actors and let the bank deal with the consequences. The system will surely rectify itself eventually when their spammy, manipulative, promotional banker campaigns do not produce results (is that a bad thing?) and they seek out firms that do produce results based on knowing what they are doing. The author could even use it as an opportunity to promote his or someone else’s services and use this write-up as an artifact of evidence. I don’t want to get too generalizing, but it is a perspective that does not surprise me coming from what seems to be a German, for better or worse. Complaints about not being in compliance with universal norms instead of taking advantage of a presented opportunity to break ranks for one’s their own individual advantage, strikes me as a very German perspective; like I said, for better or worse, without judgement, since both of these perspectives have their advantages and disadvantages.
- cheesepaint 1y agoI don't think that everything needs to be a sales pitch all the time. But I am curious, what kind of service do you see promotable in the article?
- sitkack 1y agoI know of a bank that it asked for every piece of PPII they have on you for account validation. This allows their phone support folks to have every piece of information to steal your identity.
- clarkdale 1y agoI see Conway's Law at work here. The marketing department must have its own IT department separate from the IT that maintains the core website and business functions. It's impossible for them to get on the same web domain (much less build something in the phone apps). Instead, they built their own disparate site and experience.
- this_user 1y agoIt gets worse. These German "Sparkassen" are small to at most medium sized credit unions. They are organised in a larger umbrella organisation that takes care of some of the services like IT, but the individual banks can pick and choose what and how much they want to handle themselves. Some of them are larger and pretty well organised, but there are also a lot of small ones that just don't have the people and expertise for things like proper IT security practices. But customers trust them, because they position themselves as these local neighbourhood banks, even though most of them are pretty incompetent and will rip you off with high fees on accounts and shitty, underperforming investment products.
- cheesepaint 1y agoI had a similar thought, but I suspect that this campaign is run by the umbrella organization
- meindnoch 1y agoMy bank used to call me with random marketing crap, and insisted on telling them my birthday and my mother's name before they can reveal their latest exclusive offer or some other crap. They were always dumbfounded when I retorted that it is them who need to prove that they're really calling from my bank first.
- deleted 1y ago[deleted]
- criddell 1y agoWhen a random call asks me to confirm some information, I always reply that I'm not going to share any personal information because I have no idea who they are. Half the time, they just hang up, the other half of the time they launch into the sales pitch.
- Tade0 1y agoMy bank eventually understood this, which is why currently you can check in the app whether on their end they're seeing that you're talking with their sales rep and which one specifically.
- s3p 1y agoI have this happen all the time in healthcare. I had someone from a specialist office call me and immediately ask me for my date of birth. Their surprise when I said no was incredible. But I agree with you, if THEY are the ones calling, they need to prove their identity.
- jonathantf2 1y ago> "The SSL certification is from Let’s Encrypt and not from one of the major root CAs" This is NOT a reason to distrust a website.
- bob1029 1y agoNot outright, but it's more likely that a malicious actor utilizes the simpler or cheaper solution. $300/yr+ adds up, especially if you need to go through due diligence to acquire the EV.
- jonathantf2 1y agoTrue - but if browsers don't show the EV cert until I click 3 buttons and my bank don't use one is there really a point?
- bob1029 1y agoFrom a customer & technical perspective, not really. From a compliance, regulatory & risk perspective, definitely. The EV certificate often comes with additional liability protection to cover any end customer claims related to certificate issues (i.e., if the authority is compromised and the customer's PII becomes exposed).
- spiffyk 1y agoThis absolutely IS a reason to distrust a website claiming to be owned by a bank (or any other institution working with such sensitive assets). To be precise, such a website absolutely needs to have a certificate granted not only on the basis of "yes, I control the machine this domain points to" (which is what Let's Encrypt does), but also based on other, more physical and reliable means.
- deleted 1y ago[deleted]
- mnw21cam 1y agoYou're talking about EV certificates. They're dead.[0] I personally would trust something signed by Lets Encrypt more readily than many other certificate providers. They appear to know what they are doing. [0] https://www.troyhunt.com/extended-validation-certificates-are-really-really-dead/ https://www.troyhunt.com/extended-validation-certificates-ar...
- quitit 1y agoMy bank has a secure messaging system inside their website and app. However every time I use it, instead of answering through the secure channel, they try to call me on the phone. Now they've put out security warnings about scammers impersonating bank staff making calls to customers.
- massung 1y agoI use USAA for banking. Something they do when they initiate a call to me on the phone is they start by making sure they are talking to me (they don’t ask me to prove it) and making sure I have the app on the my phone or access to a web page. Then they initiate a MFA check within the app. I have to get it and read back a number. Then they ask me for my phone PIN or password. Once that’s done, then we can start talking.
- BobAliceInATree 1y agoYou're giving a MFA number to someone that called you?!
- GolDDranks 1y agoThe bank I used to use had a per-verification request code that the app showed. If the party dealing with you knew the code, you could be sure they were the party who initiated the verification request.
- LorenPechtel 1y agoBut you said you read back the code. It should be the other way around--*you* compare the code they give you with the code the app gives you. Give zero information until identity is confirmed.
- ainiriand 1y agoThat's really not safe...
- mnw21cam 1y agoThat is a really bad idea. That's letting anyone who phones you prove to the bank that they are you. You should only reveal an MFA code to someone that you have called, knowing that it is the right person.
- massung 1y ago
- mitthrowaway2 1y agoThis is pretty bad, but not as bad as Plaid asking for my bank account log-in credentials.
- andrewmcwatters 1y agoThere’s no other way to do it. Not all banks expose an API.
- RandomBacon 1y ago> There’s no other way to do it. Don't they allow you to manually enter the bank routing number and account number, then verify it by depositing and withdrawing a few cents?
- cvoss 1y agoYou can't query account balances and transactions through ACH.
- andrewmcwatters 1y agoThat’s just account verification. ACH has some really antiquated practices on purpose that make the system more robust than a naive automated banking system and less robust than a comprehensive one. I own a business that works directly in this space.
- kodzoman 1y agoI've been preaching about this issue for years, even to my friends working in banks as IT security, but for some reason they are more obsessed about solving the wrong problems with buying expensive hardware.
- detourdog 1y agoEvery bank I deal with except Schwab forces me to allow cross-site scripting to use bill pay...
- rwmj 1y agoMy bank replaced their phone authentication with something that asks you to speak a phrase (the same one every time) and tries to recognise your voice. Luckily that's completely bulletproof, there's no way it can be forged :-/
- reginald78 1y agoI read the FAQ on mine and it assures me it is totally safe and the voice cannot be forged. This mechanism was defeated in a hacker movie from the early 90s using a tape recorder but is actually being pushed as state of the art. I can't imagine how this method could ever be safe, even if it were possible to use some kind of advanced detection which would fail any time I had a cold my voice can be recorded and played back in high fidelity!
- nobody9999 1y ago>This mechanism was defeated in a hacker movie from the early 90s Sneakers (1992)[0] [0] https://en.wikipedia.org/wiki/Sneakers_(1992_film) https://en.wikipedia.org/wiki/Sneakers_(1992_film)
- deleted 1y ago[deleted]
- _1tem 1y agoThis is on us, as software “engineers” for not having standards that may be used to regulate software development. There are building codes, fire codes, but no software codes.
- pyuser583 1y agoWhen buying or selling a house, this can get really bad. You have all sorts of entities which extensions of other entities. The bank has a mortgage sector which uses a different domain. I also had to deal with a medical device recall, which was terrible. I had to trust some skeezy domains. This isn't hard to fix, all you need to do is list on your website your "partner domains." My personal security protocol was to search a .gov website for contact info of financial institutions, go to the domain listed, look for a customer service number, and call that to find out what domains to trust. Customer service people thought I was weird. At one point, a customer service person said, "you know it's legitimate because if you go to LinkedIn, you can see the person you're dealing with has <Bank Name> listed as their employer."
- AnimalMuppet 1y ago> At one point, a customer service person said, "you know it's legitimate because if you go to LinkedIn, you can see the person you're dealing with has <Bank Name> listed as their employer." "Yeah? Give me two minutes, and mine will say the same. So, will you give me your personal info?"
- astura 1y ago>When buying or selling a house, this can get really bad. You have all sorts of entities which extensions of other entities. The bank has a mortgage sector which uses a different domain Huh? I got my mortgage thru a mortgage broker and I only dealt with a single person.
- pyuser583 1y agoI did the first time too, and he screwed us. We realized we could get a mortgage just fine without a broker. Domain insanity aside, or course. I have a strong anti-mortgage-broker bias. Mostly because of that one bad apple.
- dsabanin 1y agoI've been getting lots of scam calls lately, especially AI voice generated once, and there was one particularly annoying. Very persistent call about being approved for some loan, no reference to any particulars, all very vague, and I kept ignoring. In my mind I had no doubt it was a scam. Well, long and boring story short, now I have a missed payment on my credit report for my new HVAC system..
- j_seigh 1y agoHere's an interesting scheme. Some credit/debit card merchant accounts can arrange to get updated card info if your card expires and/or gets replaced. So if the merchant is a bad actor and doesn't charge your card directly but just tracks your updated card info so it can be used fraudulently elsewhere, you, your bank, and the card company will never know they were the source. And the card is linked to your bank account, you can replace it ad infinitum and the bad actors will get the updated info for the new card every time. The only way to break out of this is to close your bank account and open a new one.
- lxgr 1y agoBanks usually have a mechanism to prevent automatic billing/card data updates for exactly that reason for suspected/confirmed fraudulent used cards, but unfortunately not all of them, and I suspect even for those that do, not all customer service reps know how to do that. In an ideal world, all merchants would be using tokenization already – then the bank could offer you a UI where you can just kick out the merchants you don't want to have access to your payment credentials anymore before reordering a new card. (If tokens were mandatory, like they are e.g. in India, you wouldn't even need to reorder the card in the first place, but that'll probably never happen in the US – too many legacy systems.)
- pflenker 1y agoAh, Sparkasse. I fondly remember the needless restriction for my password to be at most 5 characters long, all numbers.
- wccrawford 1y agoI had this happen worse from my car loan bank. I got an email with a header that was obviously badly scanned from a paper document. It demanded that I provide proof of insurance or my car loan would be canceled. It had the name of the bank and my name and my email, but nothing else of import. The only URL was to a domain unrelated to the bank. I ignored the first couple, and finally looked into it the third time. It was legit. When I told them all the ways this looked like phishing, they couldn't understand my concerns. I gave them the info they wanted in person at a local branch. I soon after paid off that loan and got away from them.
- 1shooner 1y agoI left Chase because their anti-fraud detection was so suspicious that Chase's own customer service told me it was fraud and had me close my checking account in the middle of a vacation. Only later I put together it was legitimate fraud detectiontriggering on an unexpected transaction location.
- RandomBacon 1y agoI called the number on the back of my Chase credit card (which goes to a call center in what sounds like India), and the person told me he has to verify me by hanging up, and then not to call anyone because he will call back in a few minutes... (Probably while he's on a "bathroom break" running to the scam center on the next floor of the same building.) All the other times, they just ask for my verbal password to verify me. I reported it and they said they created a ticket, but a month later when I called for a follow-up on the ticket, they said they had no idea what I was talking about :-/ (If anyone from Chase reads this, I have the recordings of those calls if you want them.)
- nullc 1y agoIn some instances where scambaters have hacked the scammers network video recorder you can see them working legitimate calls from the same desks... the outsourced call center can achieve 100% utilization by using all idle capacity for outbound fraud and if data access from the legitimate side helps with the criminal side, well that's just the synergy of horizontal integration for you.
- one_of_a_kind 1y ago[dead]
- nobody9999 1y ago>Only later I put together it was legitimate fraud detectiontriggering on an unexpected transaction location. If I use my Chase debit card more than fifty miles from my home, transactions are denied as potential fraud. Then again, if someone uses my card details at a gas station in Santo Domingo, DR, that's just fine, even though I'm using the card in my home town on the same day. It's maddening.
- everdrive 1y agoPhising and phishing education are inherently misguided. If my normal workflow includes much the following, then phishing will always eventually succeed: - HTML emails where links and remote images obfuscate the 'real' content of the email. - URLs which are not clearly and easily human-readable. - A workflow where my normal and expected daily behavior is to receive valid emails that I don't recognizes with URLs from vendors, and then I'm meant to click on those URLs, go to web pages, and enter my credentials. The fact that _any_ normal products or business processes expect this means phishing will always eventually succeed. No, I don't have all the UIs and URLs for every vendor memorized. I'd have no way to know if they changed validly, and my job trains me on a daily basis to click on emails and enter my credentials. It's just that _every so often_ this same scenario is set up by a bad actor.
- BobaFloutist 1y agoSharepoint is crazy. I get an email sending me documents, but to view them I need to click a link to an outside website and enter in my email login details??
- fortran77 1y agoThe US city I live in 9 months/year has a yearly burglar/fire alarm licence fee. A few years ago, I got a postcard that said "renew your alarm licence on-line" and the domain wasn't the .ca.gov domain the city uses, but something like "alarm-renewal-online.info" I had to spend 30 minutes on the phone with my city to verify that this was a legitimate way to renew the alarm. They had contracted with an outside company to do the payment servicing. In the end, I just decided to mail them a check.
- RandomBacon 1y agoAt least when my local government outsource their alarm permitting, they linked to the .com from their .gov website.
- smsm42 1y ago> has a yearly burglar/fire alarm licence fee. Wow, they never ever stop nickel-and-diming people, do they?
- nmstoker 1y agoA friend told me about a company where the CISO instigated security newsletters aimed at staff to build up their experience on such topics, yet the newsletters were emailed from an external email and contained links to a hosting site that wasn't related to any of the employers regular website domains and like this case would often come across as a phishing attempt, especially when they ran competitions (apparently they appeared too good to be true, as friend's employer was famously tight!)
- mnw21cam 1y agoEvery weekly newsletter I get at work is sent from an external spam-sender, containing links to an external hosting site that have a unique ID for tracking clicks. Those links are then munged by Outlook which makes them hard to identify. I searched on the company web site for any confirmation that the external sender or external hosting site were legitimately being used by the company and found none, so I refuse to click on those links. I should also report them as phishing scams really.
- meroes 1y agoMy bank’s fraud department uses text shorthand like “Stop2end” and “call ph#” and their dates lack spaces “24Jun” in their texts to me. Is this some kind of meta-level play to sound less fake?
- LorenPechtel 1y agoText messages used to be limited in size to IIRC 140 characters. (And I still have that limit on my Garmin inReach--about an abysmal a texting device as you can get, but it works off Iridium, not the cell net. I can be on the back side of nowhere and still talk to emergency services.)
- kalleboo 1y agoSMS is limited to 140 characters, but there has been a standard to send multiple messages in a row and have the receiving phone concatenate them automatically since about the year 2000. For older devices that that don't support it, they will get multiple messages and just show it as "(1/2)" etc (I had a Panasonic phone that didn't support it during the transition so I remember it well)
- deleted 1y ago[deleted]
- jszymborski 1y agoRoyal Bank of Canada hasn't done anything this egregious but it always gave me a lot of confusion. They use so many different domains. I'm not talking about redirects either. Like their landing page is at rbcroyalbank.com and then the login is at secure.royalbank.com. for ages rbc.com was another website for ages, but now also appears to be the Royal Bank (or is it?). I forget under which domain the dashboard is hosted. Like, I get buying all the variations of your bank name, but please just redirect to one cannonical one! Marketing should also be for one domain. Way to easy to be scammed by royalbankofcanada. com or rbcbank.ca, because who the heck knows what their actual site is!
- clbrmbr 1y agoDo what I did: move to a new bank that respects your security. When you close your account, give formal feedback about why you are closing. Outflows of depositors should send a signal. (i had on issue with PNC in the US where they kept calling and asking for a 2FA code. Totally indistinguishable from phishing. Clearly they lack proper infosec, so I moved to Schwab and have not looked back.)
- fsckboy 1y agoI was on the phone with my bank recently (I called them) and they wanted to send a code to my phone to confirm my identity. I agreed. In came a text with a code and the phrase "nobody from the bank will ever ask you for this code..."
- tharos47 1y agoHere is american Express "secure email" documentation : https://www.americanexpress.com/us/customer-service/secure-email.html https://www.americanexpress.com/us/customer-service/secure-e... I've mistakenly deleted from our mail quarantine multiple times as spam/phishing. Imho it's wilful négligence toynkeep such a system operating in 2025.
- kalleboo 1y agoI love how even in their own screenshot, their app only has a 1 star rating on the App Store.
- zero_k 1y agoI'm also with Sparkasse and it's the worst. Their digital systems and their technical understanding is the bottom of the barrel. On the other hand, the "most digital bank" in Germany, N26, a so called "neobank" has laughable security [1]. It's a huge mess over here. I used to also bank in Singapore, the difference is night and day. Fun story: Sparkasse has an integration with a stock brokerage, and the stock charts are PNGs generated at the backend. It's literally 1995-level HTML usage, One can only laugh. [1] https://archive.org/details/33C3-Shut_Up_and_Take_My_Money https://archive.org/details/33C3-Shut_Up_and_Take_My_Money
- mcv 1y agoI would hope your national bank regulatir would slap this down hard, but if the government does exactly the same thing, your country might be doomed. Training about this kind of thing is mandatory for bank employees in my country, as far as I know.
- VBprogrammer 1y agoMy employer regularly sends out phishing honey pot emails. Which is great but they then will send out legitimate emails which are genuinely difficult to separate from actual phishing (using novel new email addresses and domain names in links). They also like to use some email filtering which has a habit of mutilating URLs.
- lqet 1y agoMy local Volksbank does basically the same, linking to https://www.wero-gewinnspiel.de/ https://www.wero-gewinnspiel.de/. The site also uses a Let's Encrypt certificate, which seems strange. This appears to be a massive, coordinated and not very well-executed effort to promote this Wero service. My guess is that the sites were all build by the same advertising agency.
- renewiltord 1y agoLol Chase always calls me. "We'd like to confirm this wire. We just need some details." "Okay, I am me, that's true. But I should probably call Chase back for this right? This is textbook scam stuff. What do I tell them to get to you as fast as possible." "All right, sir. That's fine. Let me just make a note on the account. You should be able to find the phone number on the website" And then I usually just find my way. It's funny, but you kind of have to be disciplined.
- meatmanek 1y agoMajor US banks sometimes do similarly dumb things: TD Bank owns onlineaccessplus.com and myonlineaccount.net. Citi's credit card site used to have you log in at accountonline.com.
- bsoles 1y agoWhen I got locked out of my mobile banking app, I got a security code in email to reset the app or something, but it didn't work. Then, I've called my customer representative for help, who promptly asked me to tell her the security code in the email so that she can reset the app. Yet, the email, in bold letters, said to never divulge the code to anybody, including the bank personnel...
- JadoJodo 1y agoThe one that kills me is when a financial institution or healthcare facility calls and says, "Hi, this is so-and-so from The Place. I was calling about your request/account/etc" → "Oh, ok" → "Before we get started, I need to verify your social security number/address/other personal information" → "Yeah, you called me and I have no way of knowing if you are who you say you are. I'm not going to give you that information. Can you give me your name, and I'll call the number on the website and ask for you?" → "Flabbergasted Well, our system doesn't work like that, so you'll have to submit another request" → Repeat ¯\_(ツ)_/¯
- idkfasayer 1y ago[dead]
- ccorcos 1y agoI’m always surprised that banks don’t have a better way of authenticating themselves to their customers (Chase and Vanguard, in particular). They call, they say I can call back and wait in a queue, but that’s stupid. Also crazy they don’t have a TOTP (e.g. Google Authenticator)based two-factor authentication. It’s just way more secure than email or phone number.
- hinkley 1y agoIt's been a while since mine triggered on me, and the weird thing of it was a bought a TV that day, which is what I assumed they called about. Nope, it was for getting a car wash halfway between the store and home.
- wykmbh666 1y ago[dead]
- Kate5477 1y ago[dead]
- data_maan 1y agoGermany is a broken country, and this illustrates it on a micro-level
- cheesepaint 1y agoAs someone who lived abroad - I really do not agree.
- sam-apostel 1y agoSomething similar happened in Belgium in 2021. The Flemish government launched a compensation scheme for solar panel owners via a site called tellercompensatie.be. I registered the obvious typo variant: teller-compensatie.be right after the tv and radio announcements, added a visitor counter and a link to the real site. It got ~20k hits in a few days, my second most popular project thus far. I just went to check the “official” domain and it looks like the domain is now owned by an ad network. Classic. A news article link ( https://www.vrt.be/vrtnws/nl/2021/01/22/compensatieregeling-voor-eigenaars-zonnepanelen/ https://www.vrt.be/vrtnws/nl/2021/01/22/compensatieregeling-...) still ises that domain name in it’s article, but now redirects to a proper gov site: vlaanderen.be/veka
- rainforest 1y agoI had similar with my energy provider in the UK (Octopus). For one reason or another a regular payment bounced which automatically puts you on a "call daily until the debt is repaid" list. These calls come in on an unrecognised number, from staff who say "I don't know" when you ask them to prove they are from Octopus, and generate no call notes so you can't find out why they rang if you use the main customer service number. To top it off they ask you to key in your card info on the phone after asking for your personal information. I complained and they offered to fob me off with £30 credit instead of talking to their CISO, but they did at least say they can add phone passwords to individual accounts.
- upstandingdude 1y agoSame with DHL, they basically train their customer base to trust messages from random channels like whatsapp containing links. They have all the urgency/nonsense markers of spam.
- Neywiny 1y agoI know somebody who tried doing a standard vehicle emissions test (gov't facility) in the area they live in. Bank thought it was suspicious and locked their card. Then they tried sending money from the bank to buy a car (they were just borrowing it before buying from a family member), and the bank thought it was fraud so removed online banking too. No tickets or phone calls helped. Ridiculous. Never once did they call to ask "hey is this fraud?"
- valenterry 1y agoThe problem is that banks are too regulated. They get into problems (of different kinds) when it's actually fraud and they don't block the account. And then, customer support is expensive, more than losing a few customers.
- sneak 1y agoAmEx emails to customers often have marketing/tracking redirects replacing all of the links in the email. The links to that redirector service are http: You don’t even need to phish them, AmEx does it for you. All you have to do is rewrite the redirect on the wire.
- exabrial 1y agoMy Bank (ally) absolutely refuses to do any sort of secure authentication. No TOTP, no U2F key, no Passkey... however, they're unbelievably climbing over the garden gate to tie my account to my phone. Want to log it? yeah lets text you. Want to do anything else? Hey we sent a push notification to your phone. Seriously, fuck my phone. It's the least secure thing I own. Stop acting like its my damned identity. Oh as a bonus... Hey want to integrate with a third party website? Oh just enter this code that we are literally telling you not to give away to anyone else. Lol.