← Back to context

Comment by rolph

3 hours ago

its ridiculous how many people will ignore the warnings and relay the security challenge/solution to the attacker.

"we will never ask for this over the phone" takes second place to:

"we will send/save you money/time if you make it convenient"

dress it up to taste like developer needs, and you can hook the newbies.

> "we will never ask for this over the phone" takes second place to:

Doesn't help that the banks then do, in fact, call you, and ask for this over the phone.

  • those banks that do that are grooming customers for failure, they create a workflow that is close to an attack.

    in my region AT&T has a very explicit statement not to reveal MFA codes to anyone who asks, is not part of thier system to do that.

    there is 1 bank in my area that does voice call relay over the phone, the others keep it 10 fingers relayed from phone to authentication form.

    guess who has the most problems with account compromise, and fraud claims? yes, that one bank. it has a phishing vector in its system.