29 ms·
He turned to me and said, "Do you really think the only thing the bank does to log people on is to check the username and password?" Banks are way more sophisti
by mquander 7y ago
He turned to me and said, "Do you really think the only thing the bank does to log people on is to check the username and password?" Banks are way more sophisticated than this and it goes well beyond merely string-matching credentials; there's all sorts of other environment, behavioural and heuristic patterns used to establish legitimacy. You won't ever see a bank telling you how they do it, but those "hidden security features" make a significant contribution to the bank's security posture.
Their response to having visible security that sucks is to say that they also have a lot of super complicated invisible security which is actually really good? Why am I supposed to believe that? Their invisible security probably sucks even more.
- Someone1234 7y agoIt is likely just a GeoIP database and some basic user agent heuristics. I've worked at places that claimed stuff like this in public, and when you got to see behind the curtain it was a huge disappointment. The people who really spend big bucks on this stuff are the ad-networks. Click-fraud is hugely costly to them, so determining "real" users (and the quality/type of user) is huge multi-billion dollar stuff. Creepy, but it works.
- pbhjpbhj 7y agoSurely the bank giving the wrong people their money is a huge problem too? I know they mitigate it by trying to claim it's a customer's money and not their responsibility, but that doesn't always work for them.
- AnIdiotOnTheNet 7y agoIt works enough. They've managed to push the term "identity theft" into the public consciousness as a description of the problem, when the real problem is that they can't be bothered to actually identify people.
- thaumasiotes 7y agoIt's considerably better than that. Some examples: The first time I went to China, I tried to pay for something with a debit card and my account got locked. I had to call the bank to OK it. Subsequently, being in China has never been a problem, though I don't bother to tell the bank where I am at any given time. On the other hand, after a trip to Georgia (the US state), my card information was apparently skimmed and used to make a fraudulent purchase, in Georgia, a week later. My legitimate purchases on the trip triggered no alarms, but the fraudulent one triggered a phone call to me alerting me that the bank had detected suspicious behavior on my account. I'm still amazed they could tell the difference.
- seanmcdirmid 7y agoMy bank has SMS alerts, I can ok a suspicious transaction just by saying Y. I also chose HSBC because they have branches in China, otherwise they are not a great bank.
- TeMPOraL 7y agoThe simplest heuristic I can think of is that if you made another purchase yourself not long before or after the fraudsters did, it's easy to tell that you'd have to go supersonic for both transactions to be valid.
- paranoidrobot 7y agoReminds me of a video on the VINWiki youtube channel[1]. The tl;dr: Apparently Amex have some algorithm that includes flights and road travel options. Doing a Canonball Run (very high speed driving from one side of the US to another) triggers that. [1] Relevant portion starts at roughly https://youtu.be/HkZNddd9Pxc?t=354 https://youtu.be/HkZNddd9Pxc?t=354
- jedberg 7y agoThey most likely saw a bunch of charges from the same place at the same time and yours was one of them. They were probably card running and got caught.
- tialaramex 7y agoI agree, Troy is way too gullible here. > Do you really think the only thing the bank does to log people on is to check the username and password? Yes. I assure you that when bad guys with your username and password log in and steal all your money the bank _won't_ say: "Doh, our sophisticated environment, behavioural and heuristic patterns used to establish legitimacy let you down this time. We'll pay for this" No, they'll say it is your fault because the bad guys had your username and password. And that's all you need to know.
- VBprogrammer 7y agoI'm inclined to agree. I was checking my bank account on my phone yesterday and the office Wifi was having an off day. So I disconnected the wifi and proceeded to try to login over 4g. I got locked out of my account for 10 minutes because that is suspicious. After checking my account I couldn't find a payment I was expecting to see so I opened my account on my laptop and got locked out for another 10 minutes. Sounds like the dumbest IP checking to me, not some super clever heuristic based check.
- heavenlyblue 7y agoIt's that assumption, literally: if the attacker had managed to steal your session information from the browser, then they would not be able to use it since they would also need to share my IP. In real life if the attacker is capable of stealing my session credentials the chance of them _not_ being able to tunnel through my local network is infinitesimal.
- VBprogrammer 7y agoThe thing is though, what they seemed to object to was trying to login (not using the same session cookie) across different IP addresses. At least that was the case when I opened the site on my laptop. Maybe my phone did login on the dodgy wifi and then when I reconnected via the 4g it tried to use that session, perhaps causing my account to be flagged. I'm not really convinced though. It clearly makes sense to tie the session to the IP address but the 10 minute delay doesn't make much sense to me.
- pjc50 7y agoThe corollary to this is that a user can fix a "wrong password" error, but if they're locked out by the invisible security, they can do nothing. I'm not looking forward to the mandatory phone auth on "3d secure": https://www.sagepay.co.uk/support/12/36/3d-secure-explained https://www.sagepay.co.uk/support/12/36/3d-secure-explained
- FussyZeus 7y agoI was coming here to say the same thing. This might explain why every time I try and login to and manage our Costco Citi card (which is in the wife's name) I constantly run into issues with the password in our shared 1Password vault not working. It's gotten so obnoxious she manages it entirely now via the mobile app, because every time I would try and make payments it would lock the stupid thing.
- kryogen1c 7y ago>Their response to having visible security that sucks seems like you missed the whole point of the article - their security doesn't suck. EDIT: as reply points out below, not bits of entopy, just possible combinations. ORIGINAL: 3 trys - thats it. theres no account autounlock. 5 lower case letters is ~12 million bits of entropy, and thats if you even know the username which, the article points out, you often dont. furthermore, even if i accepted your claim that this "visible security" was bad, the "invisible security" is well established. any reputable bank will flag your account for any number of reasons. ive had cards (correctly) locked for <$1 charge at an air pump a few miles away. >Why am I supposed to believe that? again, as the article says, "Banks like ING will give you your money back". they have skin in the game and will refund your fraudulent charges.
- zAy0LfpBZLC8mAC 7y ago> 3 trys - thats it. Until the users logs in, then you have another two tries. Until the users logs in, then you have another two tries. Well, and so on, ad infinitum. > 5 lower case letters is ~12 million bits of entropy, That's more like 23.5 bits, which, as far as I know, is quite a bit less than 12000000. > again, as the article says, "Banks like ING will give you your money back". they have skin in the game and will refund your fraudulent charges. So, if everything looks like you authorized a transaction, they'll give you your money back because you said so? And you seriously believe that?
- kryogen1c 7y ago>> 5 lower case letters is ~12 million bits of entropy, >That's more like 23.5 bits, which, as far as I know, is quite a bit less than 12000000. woops! youre totally right. added an edit. >ad infinitum. this is not true. banks take action and will not give you probably any more than 2 or 3 sets of lockouts before taking action. >So, if everything looks like you authorized a transaction, they'll give you your money back because you said so? And you seriously believe that? You must not be from the US. To my knowledge, most banks will refund fraudulent purchases. in addition to being believable at face value, I have also personally had fraud charges reversed.
- ohduran 7y agoLike "military encryption" and buzzwords like RSA, which leads me to believe that banks do just the bare minimum that some consultant has told them to do...
- cygned 7y agoI can’t tell you why, but I know some of the anti-measures bank use and I can assure you that they are pretty sophisticated. However, all I have seen are security efforts to secure the network, not the banking interface of customers - which means, if someone has your name and passcode, they can access your account online. I bet they have something like IP address origin checks and nothing more.
- nomagicbullet 7y ago> I can’t tell you why, but ...
- doctorpangloss 7y agoYeah it would be great if Bank of America just worked with Safari and uBlock Origin on with my username and password, and it didn't have these moronic "patterns."
- steventhedev 7y ago> Why am I supposed to believe that? Because it's required by law, at least in the US, UK, and most of the EU. The quality varies somewhat, but the main goal is less to prevent fraud than to detect it after the fact. Basically every single bit of information your computer is willing to send will be recorded. That includes request headers at a minimum (if you've disabled JS) and quite a bit more if you do have it enabled. Try a packet capture when you open your bank account next time to see just how much they transfer out of your computer. Source: used to work on one such product
- berdon 7y agoWhat laws?
- steventhedev 7y agoI worked dev (hence the username) and left the company more than 5 years ago, so I don't remember the exact regulations. I do remember it was a big deal towards end of 2012, so you're probably looking for something from around 2008 with a final enforcement date of 2012. I'll update if I remember the name.
- xmodem 7y agoThere was a bunch of stuff to do with this in the first payment service directive, most of which was enforced around 2012-2013 https://en.wikipedia.org/wiki/Payment_Services_Directive https://en.wikipedia.org/wiki/Payment_Services_Directive PSD2 has requirements on "strong customer authentication" basically requiring 2-factor, that were meant to come into force on Saturday the 14th of September just passed, but ended up being delayed at the last minute in most countries.
- TeMPOraL 7y agoIt would be interesting to see how this squares with GDPR, the purpose of the latter being to minimize recording of what your computer is willing to send.
- berdon 7y agoI've had the opportunity to chat with many ex-bank developers and based on those discussions I'm as positive as I can be, without my own personal experience, that this is assuredly utter garbage. The last two I've spoken with had read-only access to _everything_. The entire company did.
- jen729w 7y agoI’ve worked at 2 of the 4 major banks here in Australia and I’m calling bull on that last statement. The entire company had read-only access to everything? Yeah nah. Who put the Siebel client on Janice the HR lady’s laptop? Who created an account on the mainframe for Barry the bloke who re-stocks the milk in the fridge? You get my point.
- cyphar 7y agoI think they meant that the last two ex-employees they spoke to had read-only access to everything, not that every employee at a given bank had access to everything.
- berdon 7y agoI was a bit exaggerative - the entire "development" arm of the bank had read only access to all customer financial data. One of the devs was a customer and pulled up all of his information.
- PretzelFisch 7y agoIt's questionable when you can turn bank passwords over to a random third party to check/verify your account information or import the data into another system.
- 99052882514569 7y ago"Why am I supposed to believe that?" Because if someone gets in, they're going to refund you.
- scrumper 7y agoWell here's some of it. This is what ublock origin has to say about us.hsbc.com: google.com adsrvr.org amazon-adsystem.com appdynamics.com bing.com demdex.net doubleclick.net facebook.com googleusercontent.com gstatic.com hsbc.com linkedin.com liveperson.net lpsnmedia.net omtrdc.net tiqcdn.com yahoo.com youtube.com ytimg.com Plenty of behavioral stuff in there!
- giancarlostoro 7y agoThey wouldn't put that in the front-end allowing you to block it. It's all in the back-end using third-party services such as Guardian Analytics. Dislcaimer: I briefly worked as a software consultant in the finance industry, that is one of (I'm sure) many out there. You don't want to expose third parties you use for parts of your online banking process. I assume bigger banks homebrew it all.
- shadowprofile77 7y agoBut why would this really be? Are they actually attempting to harvest specific user data for HSBC account holder X from all these sources? (something I sure as hell wouldn't want my leaky bank to do no matter what kind of security it promises) Or are these just links for the sake of typical bigcorp bullshit ad tracking attempts.. Any ideas?
- scrumper 7y agoProbably the latter in fairness. But presumably the data from those trackers feeds into the hidden backend heuristics the parent commenter mentioned.
- shadowprofile77 7y agoYes but if one has many of these disabled or logged out (the social media-type pages in particular) I imagine they couldn't get much for the sake of heuristics data collection anyhow,or if say you log in from a device where none of these accounts are also opened. I can't imagine Facebook openly letting a third party banking site or app scrape up its precious specific user data without first paying for it in "anonymized" form, ditto for Google, so how might that work if the bank was attempting that?
- rkagerer 7y agoI've done work for a few major banks and seen their back-ends. Most of the products and tools they use in support of security are purchased from 3rd party vendors, and some of them aren't bad. Where I've seen it break down is in practice, where you end up with a bunch of compromises that boil down to "lowest common denominator". e.g. Banks are buying each other up all the time. After a few dozen acquisitions you end up with a giant hodgepodge of diverse systems not designed to work together, but need to integrate them. Username and password is common to all, so you wind up with raw dumps to synchronize credentials. (That's less common now that most vendors have adopted better practices like password hashing, etc. but it wasn't so uncommon back in my day) I'm not surprised at the character limits. It simply means there's at least one legacy system somewhere that can't accommodate more. It's not necessarily tied to a plaintext database field as Troy suggests; it could simply be a validation in some line of custom reporting code a programmer put in two decades ago based on ancient requirements devised long before current-day practices. Or more simply, bank IT themselves may be unsure what their real limit is at a given point in time, and chose to go with something "safe". I'm not denying banks need to step up their game, after all it's nearly 2020. But personally I think the reason it won't matter is most of them won't be around long enough - they're in for a world of painful disruption from the likes of Stripe, Apple, Google, cryptocurrencies, Libra-like instruments, peer-to-peer services and micropayments, etc. and who-knows-what other big innovations about to be invented by geniuses from areas of the world presently starved for financial services.
- astine 7y ago"I'm not denying banks need to step up their game, after all it's nearly 2020. But personally I think the reason it won't matter is most of them won't be around long enough - they're in for a world of painful disruption from the likes of Stripe, Apple, Google, cryptocurrencies, Libra-like instruments, peer-to-peer services and micropayments, etc. and who-knows-what other big innovations about to be invented by geniuses from areas of the world presently starved for financial services." I'd be surprised if these services actually disrupted the banking industry. Banks are heavily regulated, and with reason. The moment any service starts to step onto bank turf, they're going be subject to the same regulations and will have to effectively become a bank as a result. What's more, these services don't address the social role that banks play where they enable governments and large business to function by loaning them money. Or the economic control function that banks play. Banks will remain in existence for generations to come.
- JumpCrisscross 7y ago> Why am I supposed to believe that? You aren’t. You trust that if your money is stolen in a hack, the bank is liable for your losses.
- criddell 7y agoExactly! We had some money fraudulently withdrawn from our Wells Fargo checking account and though we got it back, I had a bunch of questions about bank security. My bank manager arranged a phone call from somebody on the inside to me. I pressed her about their password length restriction saying that as long as they are hashing the password, length doesn't practically matter. The fact that length is limited to a small number of characters makes me think they are storing the clear password in a database. The response was basically don't worry about it because you aren't responsible for fraud.
- nybble41 7y ago> The response was basically don't worry about it because you aren't responsible for fraud. That's assuming you can prove it. The banks' poor authentication practices certainly don't help on that front. If their own systems don't flag the transaction as fraudulent then it becomes nothing more than your word against theirs. And storing cleartext passwords is a risk to the user in the event of a breach regardless of their liability, or lack thereof, for fraudulent activity in their account. (Yeah, each password should be a unique, random string used only for that account—in theory. It rarely works out that way in practice.) Personally I'd rather they implemented standard strong authentication mechanisms and backed off a bit on the data-mining and general paranoia about atypical transactions. Chip+PIN cards are a good start on this but they're still far from universal (especially the PIN part) and don't work at all for online payments. The card should be a proper HSM with standardized interfaces for PCs and mobile devices, and the PIN should be both mandatory for every transaction and randomly assigned.
- criddell 7y ago> That's assuming you can prove it. Once you tell them some transaction wasn't authorized, it's up to them to prove otherwise. All the suggestions you make are great if your goal is to minimize fraud. If you are trying to maximize profit then you don't tighten security if the cost to do so exceeds losses due to fraud.
- triceratops 7y agoNot always. See https://www.pindrop.com https://www.pindrop.com
- dukoid 7y agoDon't get me started on their "invisible security" on credit card transactions....
- flurdy 7y agoI think Troy has too much trust in financial institutions, or rather their staff that he encountered. I have worked for and with several banks and financial institutions, and my impression is that this industry takes security theatre very seriously whilst quite slack and outdated on actual security. There were a lot of ivory tower architecture (and architects) that imposed random restrictions but full of gaps and workarounds, and not very impressive once you saw past the gimics. Unfortunately, their own staff and management mostly bought into this theatre so I can't see it improving very much. Some parts were done well and useful, but a lot was just outdated and ineffective, and just restrictive. But they have so many layers, so hacking a bank is hard, and various delays so that they can recover and recompensate you before you know it if there even was some fraud or other discrepancies. Though there were some niches of clever heuristics and analysis but not much real-time, so my I don't buy the "Do you really think the only thing the bank does to log people on is to check the username and password?". For most that is nearly the only thing they do. Last time I worked for a financial institution they were starting to introduce some useful user and device fingerprinting anomaly detections so I hope it has gotten better...
- rednerrus 7y agoI'm sure that Equifax used these security features.
- fortenforge 7y agoHow on earth is that relevant? Equifax's breach had nothing to do with password authentication whatsoever.
- FabHK 7y ago> there's all sorts of other environment, behavioural and heuristic patterns used to establish legitimacy. Here's what annoys me: These "environment, behavioural and heuristic patterns" check for cookies, IP/location, typing speed or so, don't they. Which means, that if I (for enhanced privacy and security) frequently clear my cookies and habitually use a VPN and/or travel a lot and use a password manager and copy/paste the password, then I'm flagged as suspicious and just DOSed myself. Thank you very much. I must admit though that most of the banks I use are reasonably good with that. Paypal, however, is just a total pain in the ass: basically every time I try to use it, it concludes that I'm brute forcing myself and blocks me.
- Spooky23 7y agoSeriously. They do the bare minimum requirement of their regulatory regime and other insurance requirements in most cases.