4 ms·
My bank has done similar for a few years. If someone calls you, they ask you to open the phone app and you get an in-app notification (banner in the app itself,
by sen 3y ago
My bank has done similar for a few years. If someone calls you, they ask you to open the phone app and you get an in-app notification (banner in the app itself, not OS related) that says “Click OK to confirm <rep name> is talking to you” (or some such). They can’t access you account details until you click it.
- david-gpu 3y ago> If someone calls you, they ask you to open the phone app and you get an in-app notification You mean that if a genuine bank representative calls you then they prompt you to verify it. A fraudster will not do that and if the customer doesn't challenge them then the scam can continue. One of my fears around getting older is not having the wits to protect myself from bank fraud like this. I don't have a solution.
- pbhjpbhj 3y agoEnduring Power of Attorney (in the UK, now called Lasting Power of Attorney [1]) is a solution of sorts. You given up the ability to access your accounts to a third party, usually a relative. It's used when people lose their mental faculties and are incapable of acting for themselves; it can be elective, or imposed by the court in a very long process. [1] https://www.gov.uk/power-of-attorney https://www.gov.uk/power-of-attorney
- traceroute66 3y agoOof ... a PoA is a bit of a sledgehammer to crack a nut for many people, especially those who still have a perfectly fine mental faculty. Most UK financial companies will have a third-party authority process. Its the sort of thing used to give professional advisors access to the account, but there is absolutely no reason it cannot be used to give other sorts of third-parties access. The core difference is that a TPA is technically temporary (and thus will need to be renewed on a schedule, typically annually), whilst a POA is a more permanent affair and that's why a POA is a pain in the rectum to setup.
- adhesive_wombat 3y agoScams can be so sophisticated in execution now that I'd quite expect someone to become a victim to one far before they otherwise appear to need the LPA to be used. I have made it extremely clear to my older (not even elderly) relatives to never, ever agree to anything involving TeamViewer or any other kind of remote connection on a computer or phone. Take a number to call back if they want (do not agree to be called back later), then hang up and call me. And never, ever click anything in an SMS: not only can I not really explain how URL structures work, but companies keep using scammy-looking short URLs that even I can't tell apart, so complete interdiction on ever clicking a URL in a text is the safest way. And if I call saying I'm in jail, ask me for my car model and colour. But I don't really know how to explain to them what is and isn't a scam on the 40 billion apps you're expected to use for banking, travel, parking, utilities, communications, everything with it's own security systems, quirks and bugs[1]. It's probably only a matter of time before a scam gets through (luckily the relatives are mostly not credulous enough or greedy enough to fall for most of them), but that doesn't mean I should execute an LPA and remove access to everything for their own good. Not least at that point they'll probably not be considered to be lacking capacity, a necessary condition for using the LPA, by the OPG just because they don't understand their mobile network's new login flow. [1] which won't be fixed because most of these apps are consultancy effluence and they've been delivered and signed off on. So, the consultancy doesn't care any more and the recipient doesn't know how to maintain it even if they wanted to. Not only have they probably not got their own engineering these days, the app is an unmaintainable rush-job that is 90% technical debt and enough duct tape to get it over the acceptance wall before anyone notices. At best the issues will be fixed when the app is so completely untenable that another consultancy gets hired to rewrite from scratch. Then everyone gets a new app and a new set of "is this a scam" decisions to make.
- switch007 3y agoMinor point but I’m pretty sure it’s just a grant of permissions to someone else without you yourself losing access
- IshKebab 3y agoRight this thing only works if people are aware of it, but the only way for them to be aware of it is to do it every time. This Monzo approach is near useless. The one Sen described sounds quite good.
- david-gpu 3y ago> Right this thing only works if people are aware of it, but the only way for them to be aware of it is to do it every time* It need to be done every time and it needs to happen frequently enough that people internalize an expectation that anything else is sketchy. Now, how often does a bank representative call you? For me it's like once a year when their fraud department thinks that one of my monthly bills is sketchy, even though they've been unchanging for years. Is that enough to build an expectation? I don't think it is, particularly for elderly clients. Whenever I get a call from somebody claiming to be X organization I assume it's a fraud by default and don't provide them with any personal information. It has worked fine so far, as far as I can tell.
- adhesive_wombat 3y agoThis sounds like as much of an defence against internal attacks than against scammers. Though it might be helpful if the customer noticed the attacker didn't ask for the confirmation and became suspicious, but that's probably a small number of people and scammers are very good at allaying such worries with plausible excuses.