← Back to context

Comment by TeMPOraL

3 hours ago

> "we will never ask for this over the phone" takes second place to:

Doesn't help that the banks then do, in fact, call you, and ask for this over the phone.

those banks that do that are grooming customers for failure, they create a workflow that is close to an attack.

in my region AT&T has a very explicit statement not to reveal MFA codes to anyone who asks, is not part of thier system to do that.

there is 1 bank in my area that does voice call relay over the phone, the others keep it 10 fingers relayed from phone to authentication form.

guess who has the most problems with account compromise, and fraud claims? yes, that one bank. it has a phishing vector in its system.