3 ms·
I have worked in fraud prevention, detection and analysis. Depending on a lot of factors the weakest link is either the retailer where fraud occurs, the bank's
by pSYoniK 4y ago
I have worked in fraud prevention, detection and analysis. Depending on a lot of factors the weakest link is either the retailer where fraud occurs, the bank's protections systems or the customer.
Retailers would a lot of the times not do additional security checks because those cost money. If someone buys something for 5-10$ the retailer doesn't pay for additional verifications to the bank and they are then liable for the loss. Sometimes they won't even pay for that for larger amounts OR that they avoid doing those checks because it breaks the transaction flow and the customer might just cancel the transaction - most of us are impulse creatures and if we're adding additional checks then the impulse could be stopped.
Banks also still use SMS messages for verification. SMS is horribly insecure[1] and it's shocking to see it's still the last line of defence between your life savings and a potential attacker. Yet having worked in this field, I know that the decisions are taken from a purely financial/time frame point of view. "We have 6 months to implement this, our devs have done this before and thus an SMS carousel is the easiest to implement. TADA". Or "we have already the contracts setup, we have done this for this other account type, so we're going to reuse it". There are very few incentives to use anything else and it goes back to adding friction in transactions. If our world wouldn't be obsessed with buying quickly and easily, more defences could be added.
Lastly, banks are horrible at talking to people. They don't know how to do it at all, so they cannot make communications clear. The biggest impact to fraud prevention would come from nationwide campaigns were users are shown some of the most common ways these attacks occur. Common sense suggestions also seem to lack entirely - "if you're ever unsure, pick up your credit/debit card and call the number on the back of it. That's your bank's contact number, it doesn't need a website, you don't need to call a number from a message, just call this one number". One bank I worked at did this small communication exercise and over the next few months it accounted for a significant decrease in phone-related fraud.
It's a very complex issue and I'm seeing Europe being the next big target from what I have seen regarding anti-fraud processes in European companies (a lot of them rely on outdated tech that cannot handle checks fast enough). European banks also move a lot slower than UK banks, transfers move slow, security checks are poor and in general they seem to spend A LOT less money on fraud prevention... Cybercrime is on the rise[2] and we're horribly unprepared.
Blaming people is the worst approach. We can all fall victims to these types of attacks, but we should spend time to educate those around us and exercise a bit of caution, yet understand that we can all be victims.
[1] - https://krebsonsecurity.com/2021/03/can-we-stop-pretending-sms-is-secure-now/ https://krebsonsecurity.com/2021/03/can-we-stop-pretending-s...
[2] - https://risk.lexisnexis.com/-/media/files/financial%20services/research/lnrs_cybercrime-report-july-dec-2021_research_nxr15415-00-0322-en-us_2.pdf https://risk.lexisnexis.com/-/media/files/financial%20servic...
- tlb 4y agoAlso, the fact that phone companies allow caller ID spoofing, even of well-known bank phone numbers, is extremely lame. And the fact that calling back means a looooong time on hold discourages people from doing it.
- jaclaz 4y agoWell, specifically, it seems like the ONLY thing that was not compromised in this particular scam was the SMS. The scammer must have known before: 1) the victim's telephone number 2) the victim's Login AND Password (or Pin) to the bank website What the scammer didn't manage to do was to intercept/mitm/whatever the SMS and thus needed the victim to read it aloud. Or is US bank website access different from here (EU, Italy)? Here to access the website you need to input login, password then request an SMS code for the authentication, and later you need to request an SMS code to validate any transaction.
- quercusa 4y agoIt's possible they had enough information on the victim to impersonate her to bank customer service to get the password changed.
- jaclaz 4y agoSure, which still means that they managed to get the password. But they neeeded anyway the login (here it is a customer number, usually). I was referencing the parent post because - like everyone else - is talking about SMS interception as one of the major flaws in the authentication process, the way this scam has been carried seems instead to make it (the SMS code) the only thing that would have stopped it (if the victim hadn't revealed it, several times).
- thimkerbell 4y agoA problem I encounter is that I'll want to ask the bank, "is X (a sequence I encountered) standard practice for you?", but they'll require that I authenticate myself first, to reach someone there to ask, which I'm reluctant to do in a possibly insecure environment.