15 ms·
It is fantastic that a company operating with such horrific practices is dead. While we are at it, when can we fix similar issues below with mainstream financia
by datadata 3y ago
It is fantastic that a company operating with such horrific practices is dead. While we are at it, when can we fix similar issues below with mainstream financial systems that millions of people are still using?
- Social security numbers are used as a secret for identification, despite being in plaintext and having so low entropy as to be guessable, and originally issued on a card literally saying "Not for Identification".
- Every bank check lists the bank account number, which serves as the only information needed for a party to issue a request to withdraw money from that account.
- Credit card numbers are similarly a private number used as a public number, and printed on plaintext on the card.
Is there any effort working on bringing asymmetric encryption to these systems or to replace them that has a reasonable chance of working?
- janaagaard 3y ago> Every bank check lists the bank account number, which serves as the only information needed for a party to issue a request to withdraw money from that account. Just here point out that the issue is that it's enough to have the bank account number to issue a request to withdraw money from that account, and not that the bank accounts numbers are listed.
- deleted 3y ago[deleted]
- misterprime 3y agoMe, many years ago setting up electronic payment. -OK, it's asking me for my bank account and routing number. These must be pretty secret. -Oh wow, they're both printed on my checks. Uh...this system works?
- themagician 3y agoTraditional banking is sufficiently slow enough that things can be reversed before permanently settled. The "slow" speed of moving money is a feature. It's designed for humans who make mistakes all the time.
- datadata 3y agoI agree that it is a feature, but that feature didn't come with any downsides initially when the speed of everything else was also slow. The downsides are now substantial as the customer expects higher speeds. The downsides of not having the option to have final settlement quickly also seems to be a source of many other problems. We also don't even need to change this aspect of traditional banking in order to add strong asymmetric encryption in front of the system. That would nip most fraud in the bud, and if nothing else save a lot of effort that goes into fraud schemes, prevention, and reversal.
- themagician 3y agoHonestly, I don't really see this. Small personal transactions happen via Cash, Venmo, PayPal, Zelle, etc. without much issue or friction. As far as the general consumer is concerned it is instant. Large business transactions generally (not always, obviously) do not have the sense of urgency that would require fast settlement. There's some market maker stuff that benefits from fast settlement, but that's not exactly a reason to push whole new system out to everyone. The biggest "benefits" of crypto are not benefits to the average consumer going about their daily life. Instead of dealing with fraud you'd have to deal with customer service issues for actual customers who forgot/lost their keys. And, honestly, you'd probably have to deal with more fraud. Your phone gets hacked, your keys get stolen, and then what… all your money is irreversibly gone?
- datadata 3y agoYou are imagining a false dichotomy where things like fast and final settlement, or self custody are forced onto every user, and pointing out the obvious problems with that scenario. They are not good defaults, but they are great to have as options to protect customers against a fraudulent or over leveraged system. It is a bit like any protected right-- you don't have to directly make use of it for it to be valuable, the real value is in the optionality you have to be able to use it, and the risk that optionality poses to those who would exploit the absence of the right.
- HL33tibCe7 3y agoI mean you’re right in that, thinking about this on an abstract level, your suggestions seem like no-brainers. But the current system works well enough in the vast majority of cases. And the fixes to the problems you list would add considerable complexity. I don’t think it’s actually that clear that fixing these problems would have a net positive effect on the world.
- datadata 3y agoThe size of the market just for identify theft protection is 10 billion USD [0]. There is 30 billion USD in credit card fraud a year [1]. I don't think that is working well enough, that is a multiple-FTX sized loss of money every single year going into a problem that is fueled mostly by really bad underlying security systems. 0: https://www.globenewswire.com/en/news-release/2022/03/23/2408190/0/en/Identity-Theft-Protection-Services-Market-to-Surge-Exponentially-Increasing-Risks-of-Cybersecurity-to-Nurture-Market-Growth-Fortune-Business-Insights.html https://www.globenewswire.com/en/news-release/2022/03/23/240.... 1: https://www.bankrate.com/finance/credit-cards/credit-card-fraud-statistics/ https://www.bankrate.com/finance/credit-cards/credit-card-fr...
- lxgr 3y ago> Every bank check lists the bank account number, which serves as the only information needed for a party to issue a request to withdraw money from that account. The same principle (i.e. knowing an account number means being able to debit it) works surprisingly well in many European countries for direct debits, and the account number is considered even less of a secret than it is in the US. For example, many freelances routinely print it on their invoices sent out to clients, have it as part of their e-mail signature, or even prominently feature it on their website. What makes it work is that, under the SEPA Direct Debit framework, the risk of fraud and insufficient funds is 100% on the party initiating the direct debit. An accountholder can literally click a button on their bank's app or website and they get the funds back immediately, no questions asked, within 8 weeks of the original debit date. This, in turn, means that it is in the initiating party's self-interest to only accept this form of payment in high-trust situations, and not just like a low-fee replacement for credit and debit cards that shifts some amount of fraud risk to the accountholder or their bank.
- marcosdumay 3y ago> What makes it work is that, under the SEPA Direct Debit framework, the risk of fraud and insufficient funds is 100% on the party initiating the direct debit. It also helps that the accountholder has to allow each party that will debit money from their account. By default, those requests are denied. AFAIK, the US works the other way around.
- Denvercoder9 3y ago> By default, those requests are denied. This depends on your bank, mine allows them by default.
- oblio 3y agoWhich European bank is it?
- organsnyder 3y ago> AFAIK, the US works the other way around. "Positive pay" is available for checking accounts in the US, though I've never heard of it used outside of business accounts, and only then by request (and probably extra fees).
- sithadmin 3y agoFor credit cards, mobile wallet transactions are tokenized, and EMV chip transactions function similarly.
- thephyber 3y agoEach one of these systems has a better replacement, but not all of the industry has moved to it. The largest related issue I believe is that the use of “knowledge databases” by credit bureaus (and all of the companies and governments that trust credit bureaus). Each of these has been solved, but until the last system using the inferior authentication is upgraded, they all remain weak points. I have argued that the US (or each state) should create a digital certificate system similar to Estonia’s “digital residency card” or S Korea’s online transaction signing (although hopefully not implemented as an ActiveX control for Internet Explorer 5).
- lxgr 3y ago> Estonia’s “digital residency card” The EU is actually federating systems like that under an umbrella of regulations and technical services called eIDAS [1]. I haven't been able to use it in too many places yet, but if it takes off (which is a pretty load-bearing "if", to be clear), I think it could be an important step towards making these systems usable internationally. Especially the US, which seems to prefer to handle ID card issuance at the state or even municipal level, could benefit from a federated approach like that – assuming that people would be willing to trust their local/state government to that extent, in any case. [1] https://en.wikipedia.org/wiki/EIDAS https://en.wikipedia.org/wiki/EIDAS
- thephyber 3y ago> assuming that people would be willing to trust their local/state government to that extent We have too many religious people who fear government ID cards are the “mark of the beast”. We still can’t get all states to migrate to RealID, which includes a digital verification method within the ID (something stronger than a barcode).
- briffle 3y agoYou think that is bad, every doctors office I have ever dealt with over the phone has just asked for my name, and birthdate. Think of all the friends on social media I can impersonate!
- ChrisMarshallNY 3y ago> Credit card numbers are similarly a private number used as a public number, and printed on plaintext on the card. I have an Apple Card. The only text on the card is my name. I think a lot of bank cards are starting to do similar stuff. It isn't foolproof, though. Someone somehow was able to charge against the card, a couple of months ago.
- giobox 3y agoThe lack of identifying numbers causes no end of confusion when I travel with it too, especially in European countries that Apple haven't launched the card in yet. It got so annoying on a recent trip, I just reverted to using another conventional credit card. The Apple Card is generally fine any time I use tap to pay from the phone, but the physical card simply isn't as reliable as some other cards I have that generally "always work" abroad. I've even had restaurant staff treat me very suspiciously over the blank card. Its also an odd card in that the physical card itself has no tap-to-pay functions at all; of course Apple want you to use the iPhone it can't operate without to do this part instead. Again though, if I do have to hand over the card, in Europe people will of course try and tap it instead of a swipe and once again confusion reigns. Oh and if a server drops the card, it makes the most irritatingly loud clang being a small metal object - I would happily go back to plastic for the card!
- daydream 3y agoI went to Europe and used Apple Card almost exclusively with zero issues. Both via Apple Pay on my iPhone as well as using the physical card. Seamless experience.
- grishka 3y agoThis is mostly unique to the US. Where I'm from, we don't use our SSNs as passwords, bank checks and direct debit are simply not a thing, and credit cards have two-factor authentication for online purchases.
- Semaphor 3y ago2FA for online purchases is, at least in Germany, is not always a thing. I don't know how it's decided, but I'd say only about 50% -70% of online purchases trigger the 2fa of my bank.
- RandomLensman 3y agoMy understanding is that it is related to the fraud prevention capabilities (incidence?) of the other party and the amount.
- jeltz 3y agoIt is virtually always a thing here in Sweden. The only exception I have encountered the last like 5 years is Paypal.
- stronglikedan 3y ago- Banks not doing their due diligence to make sure they are lending to the correct person, and then being allowed to blame the victim for it.
- gumby 3y ago> Every bank check lists the bank account number, which serves as the only information needed for a party to issue a request to withdraw money from that account. A check is simply a contract -- a promissory note. Like any contract you wouldn't sign it with someone you didn't trust, right? (Obviously that statement, while true, is risable these days. But I remember a Bogart film in which he was setting a debt at a casino so asked the owner for a check -- he filled in not only the amount but his name, address and bank). All the info on your check is just printed there as a convenience to you, or at least used to be. Until ~20 years ago physical checks were still sent back to your bank where they would check the signature, which could take a while! I think since the 72 hour rule went into place (and sending checks physically no longer allowed) the format was set by regulation
- singleshot_ 3y agoIf you trusted the person from whom you accepted a check, why didn’t you simply accept a promise to be paid later? Put elsewise, the salient feature of a check is that your trust in that bank backstops your lack of trust in the bearer of the checking account. (Right? Or did I misunderstand your trust model perhaps?)
- gumby 3y agoThe check is a promise to be paid later. You are trusting the check writer that they are good for the money. The bank could refuse to honor the request if there isn’t enough money in the account or they don’t believe the document is legit (looks altered). In the not so old days* you’d have to wait for the check’s bank to accept it before you got your money. And the writer is trusting you not to modify the check or otherwise fraudulently use the account info (in my parents’ time the check didn’t have account numbers on it so this was less of a risk). The only backstop the bank offered was to verify the signature against the signature card and refuse the check if it looked suspicious. I think the same is still true today. * I worked for Atari back when Warner owned them (1980s). Congress had required that companies offer direct deposit, but the minimum was they only had to offer it to you if you banked at the same bank as the company. So Atari’s payroll came out of a small bank in Sunnyvale with only one office. The rest of us got paper paychecks on Friday. Even if you went to the bank before 3 on Friday it wouldn’t be processed until Monday, which meant they’d send the physical checks to Synnyvale to be validated. Warner got to use the float on the money while all that was going on.
- rossdavidh 3y ago"While we are at it, when can we fix similar issues below with mainstream financial systems that millions of people are still using?" The literal answer to your question is, no, probably not. It's not that it's impossible, it's that a lot of the technical talent required for doing it at every financial institution that would need to, is deployed elsewhere (some of it in finance, but not in the improving-security part of it).
- closeparen 3y ago>- Social security numbers are used as a secret for identification, despite being in plaintext and having so low entropy as to be guessable, and originally issued on a card literally saying "Not for Identification". This is by design: millions of Americans believe that the clunkiness of the SSN protects them from tyranny.
- jrm4 3y agoI can't echo the general point here strongly enough. It's tempting to make this all "about crypto." But crypto's just a technology. Maybe it ends up being a thing, maybe it doesn't. The fundamentals remain, and one of the present fundamentals is that (along with good old fashioned grift) stupid and terrible cybersec practices run rampant still.