12 ms·
> the data being asked about in these KBA quizzes is culled from public records Yesterday, when opening a savings account with a major US financial institution
by css 8y ago
> the data being asked about in these KBA quizzes is culled from public records
Yesterday, when opening a savings account with a major US financial institution, one of the KBA questions asked for my Zodiac sign. The other two were about a mortgage and the year I was born (±1 year). I do not understand why any competent institution would find these secure and it appalls me that is all the information needed to open an account in my name.
Edit: Here is the screenshot https://i.imgur.com/Mr8gOOA.jpg https://i.imgur.com/Mr8gOOA.jpg
- hsk0823 8y agoNo one thinks this is actually secure, it's security theater. The thing is, the cost of identity theft of consumers to credit reporting companies is less than the cost to actually adopt secure methods to judge one's credit.
- arcticbull 8y agoYou’re exactly right. It’s the same reason we’re required to sign checks then the bank promptly ignores the signatures. It’s cheaper to handle the fraud than check the signatures, but it makes us feel good to do it anyways.
- ktjfi 8y agoI guess the signatures are there in case someone complains? They can just pull the check and see if the signature is legit. But checking every signature is simply too much work.
- usea 8y agoIt's my understanding (from hearsay) that they use software to look at signatures, and use that data as a fraud signal, among other data.
- css 8y ago> the bank promptly ignores the signatures You're technically supposed to sign and endorse the back of every check you electronically deposit; I have never done this since my bank offered mobile deposit and have never had a check rejected. It honestly just makes me sad.
- floatingatoll 8y agoThey’re upgrading this to require you to write “mobile deposit for XYZ bank” as well, so that you can’t double-deposit without getting caught early on.
- vharuck 8y agoMy bank upgraded their branch ATMs to accept multiple checks at the same time for deposits. What surprised me was the displayed instructions said one did not need to sign the backs.
- spookthesunset 8y agoI mean, whats the point of signing the back of a check? Most businesses don't sign the backs of their checks. They use a stamp that has their business name printed in some ordinary font. At that point you might as well let the mobile app superimpose its own signature or have the ATM apply its own stamp.
- SketchySeaBeast 8y agoI wish - a few years ago I was trying to pay for rent with a cheque and it bounced. I ended up sending another cheque, having that one get rejected, go into the bank and give them a new signature sample, and then have the next cheque be rejected as well due to the signature. Apparently my bank checks cheques.
- pocketstar 8y agoCanada? Or Common Wealth? Judging from how you spell “cheque”. Signatures still mean something in some countires, just not the US.
- SketchySeaBeast 8y agoCanada. I've never heard of anyone but myself experiencing this issue though.
- davchana 8y agoYes, Indian Banks too check Signatures on anything submitted to them. I once had to deposit cash in my own account but in different city in India. It was free if I deposited it, but fees for anybody third party. Cashier told me my signature doesn’t match with whats on file and thus either I need to re-sign or need to pay fees. Here in US I have seen policies in Stores saying we accept check, but we will onetime use the account & routing number on check to pull the amount. I am so confused if by merely giving someone a cheque they are able to “pull” money from just two numbers, and can do it for any amount & any number of times.
- athenot 8y ago> I am so confused if by merely giving someone a cheque they are able to “pull” money from just two numbers, and can do it for any amount & any number of times. That is exactly how checks work. It's optimized for happy-path, with a big mess of a process to handle fraud. The cash equivalent would be to carry a bucket with all your money and when you pay, you present your bucket so that the shop can pull out the amount you and them agreed on.
- suresk 8y agoI know some banks actually do check them. Last year, my wife paid a contractor with a check from Ally, and the check bounced because the signatures were not close enough.
- orky56 8y agoFor one payroll, I completely forgot to sign a set of checks for 40 employees. Not one employee came back and said their check did not clear. Scary world we live in.
- acranox 8y agoI was also asked about my Zodiac sign. I was shocked. A credit reporting company using that is just appalling.
- techsupporter 8y agoThat looks like Ally Bank. --BUT, it isn't, per the reply below. It's Discover, though Ally asked me the same zodiac question in what looked like the same font.-- They won't open a joint savings account for my wife and I because my wife doesn't have a phone bill in her own name "for verification." (We've been on the same Southwestern Bell/Cingular/AT&T, recently T-Mobile, family plan for the past, oh, fifteen years, and it's under solely my name because of employer discounts.) When I mentioned this to the rep, she told both of us--we were all on speakerphone--that my wife could send in a copy of her driver license. Except Washington doesn't require us to get new licenses when moving and the address on both of our licenses is both the same...and four years out of date. I get the need for ID verification but funny how we never run into this problem when my wife wants to borrow money in her own name. No one has ever cared about her license or a phone bill when she's taken out credit cards.
- techsupporter 8y agoOh, and one more thing: This is the same bank that called me the other day to inquire about our application and--even though they called me--their representative got mad when I wouldn't give him the last four digits of both of our Social Security numbers and our dates of birth and Mother's Maiden Name / Security Answers from the application. When I pointed out that a) he called me and b) this is, quite literally, exactly how scam calls trying to steal money go, he got upset at how I wouldn't "believe him." I told him that's exactly what a scammer would say and hung up. My "private" information has been leaked to other governments and various malicious actors at least six times, just in 2018, so I'm a little more wary than I used to be and that pissed me off.
- Robelius 8y agoI had a similar issue with Chase calling me, as a follow up to fraudulent charges on my card. They were asking for basic identifying information, but I didn’t feel comfortable so I hung up. I then called Chase and asked if it really was them that called, and they confirmed it was actually them. But then they also apoligized and resumed the previous call from where I hung up. It was just nice to not be judged for being cautious.
- adrr 8y agoI used to work at a fintech and seen Kba providers ask questions that provide zero security like “what county was your 1 Main Street Santa Monica,ca address located in”
- sbr464 8y agoIf it’s not multiple choice, You can answer with random digits and keep your answers in a password manager.
- mikeash 8y agoNot only is it multiple choice, but there are only five choices.
- nkrisc 8y agoZodiac sign? Seriously? I don't know what mine is because that is not a belief system/religion I subscribe to so I had to Google it. Turns out my birthdate must be on the border because different sources have it as a different sign. They might as well ask what color my aura is.
- aura_inquiry 8y agoHello. What color is your aura?
- tasty_freeze 8y agoLie about which is your sign. If the bad guy knows your birthday, they will guess the wrong sign.
- astura 8y agoThey already know the answer from your credit report and other databases... If you answer incorrectly then you get denied opening a bank account online and you'd have to jump through extra hoops, either going to a branch or mailing documents.
- thetrumanshow 8y agoAnd now you have to keep all of your lies straight.
- nothrabannosir 8y agoAbsolutely; use a password manager. This is the least bad way to go for these types of "security questions": give a plausible, but wrong, answer. Correct is too easy to guess. Obviously wrong will be recognised by the customer service representative, who is a kind person, and will help you out by just disabling the question (anecdotes galore for this, to the point we can call it data). Lie, in a believable way. Put the answer in a password manager. Open your password manager up before calling any CS rep. Be a star in the security theatre. :)
- ben174 8y agoThat is incredible. There are only twelve signs. I mean why not just ask your birth month? And even then, incredibly easy to guess or to find out. I honestly want to know who came up with that security gateway and question them on how they thought that was secure.
- isoskeles 8y agoI remember being asked the name of a street I lived near once. I still don't know the right answer, but I think it was some official or unofficial name of I-80 or the 101 that no one calls it any more (e.g. Lincoln Highway). I would rather be asked my Zodiac sign, although that is definitely weird. You shouldn't have to spend time doing research on different versions of road names to prove my identity. That's absurd. I can imagine some dystopian future where I'm strapped to a chair and my kidnapper is demanding I answer to obscure names of highways as my only reprieve from torture.
- bonestamp2 8y agoI wonder if these questions were less about identity validation and more about stopping bots from opening accounts? Either way, it's not the ideal solution, but one is a little better than the other. The chance of a bot guessing all three right is pretty slim, but at least if a real person did research and made educated guesses then it would slow them down considerably.
- ShakataGaNai 8y agoYea. I recently had two run ins with this exact same KBA system. One for a bank and one for a health insurance type thing. Both asked a question of which hospital was closest to me. How is it "KnowledgE" when I had to google map 4 different hospitals to figure out where they even were? One of two variations also listed two 'different' hospitals that were less than 2 blocks apart, leaving the 'closest' question up to a flip of the coin.
- zelon88 8y agoThey're not competent. That is the problem.
- reaperducer 8y agoUnited Airlines asked me to fill in a bunch of crazy password questions a few weeks ago. Things like "What's your favorite flavor of ice cream?" Well, I dunno. It depends on my mood. Or "What if your favorite vacation destination?" Another bad question because my favorite today may not be my favorite when I get back from the next place. Unfortunately they were all mandatory — there wasn't an option to pick only the sane ones; all ten had to be answered. Most of them felt more like marketing trying to build a profile on me rather than IT trying to keep my data secure.
- css 8y agoThese are KBA questions, which are generated by a third party based on information on your credit report. For the types of questions you describe, I just use my password manager to generate random strings for each of those answers and make a note of what question each string matches with. To make sure the strings are not rejected for special characters I use passwords a la https://xkcd.com/936/ https://xkcd.com/936/
- MR4D 8y agoI wonder if anyone has gone through the password lists to see if "correct horse battery staple" shows up, and if so, how many times.
- baobrain 8y agoAccording to haveibeenpwned.com, they've seen "correcthorsebatterystaple" 114 times
- sib 8y agoI have a hard time believing that a KBA database would have GP's favorite flavor of ice cream.
- ceejayoz 8y ago> For the types of questions you describe, I just use my password manager to generate random strings for each of those answers and make a note of what question each string matches with. Can't do that with United. The answers are drop-downs. https://krebsonsecurity.com/2016/08/united-airlines-sets-minimum-bar-on-security/ https://krebsonsecurity.com/2016/08/united-airlines-sets-min...
- deleted 8y ago[deleted]
- godelski 8y agoIIRC there was a post here awhile ago about how you could refresh the pages and the options would change. Except, of course, the correct answer. Maybe someone else remembers and has the link.
- russh 8y agoIt has nothing to do with security only plausible deniability.
- cannonedhamster 8y agoWhen I opened my mortgage they required us to share via email everything in plain text. We did not have a choice of lender. I told my wife that these people were going to be hacked. Within 3 months we got a letter saying all of our information had been exposed. Oh whale, nothing that wasn't already out there from the numerous other breaches that I had zero control over.
- Gpetrium 8y agoThis is probably the way the business found to ask the same question as a date of birth while requiring an extra step from the user, which then: * Decreases the number of bots able to get into your account * Make it harder for a foreign agent with limited knowledge of English to do the same. No, I did not write that question for you to answer.
- mindslight 8y agoThis is not a problem - it's a feature! Whenever I'm confronted with surveillance-based "identification" and I'm unable to just choose a better option like receiving a letter in the mail, I make sure to only answer questions that can be directly deduced from the basic information I've already entered, or otherwise researched online (like the ones about what street is in what city). When confronted with questions about past addresses and whatnot, I make sure to answer "don't know" lest I confirm something they actually aren't so sure of. I haven't had any problems as a result of doing this. I wouldn't be surprised if there is some "confidence" score based on how much the surveillance databases have actually recorded about you, and even if they aren't super confident will still supply a pass result to keep the client from losing customers.