4 ms·
My bank has implemented suggestions I've given them in the past (USAA), but recently they used a different domain for a legitimate-seeming email (the email was
by RandomBacon 1y ago
My bank has implemented suggestions I've given them in the past (USAA), but recently they used a different domain for a legitimate-seeming email (the email was about something I just did, and it was to an address I only use with that bank), and I called them up and spoke with someone in their fraud department to ask about it. I told them either they were hacked, or they were training their customers to fall for phishing, and asked them to create a ticket.
They said that domain name was not theirs, and they only use usaa.com in their emails. They locked my account without telling me. I had to call them back to get them to unlock my account, and I think that person in their fraud department understood the issue and they said they created a ticket.
We shall see...
- kakuri 1y agoI interviewed for a software engineering position at USAA. After seeing the incompetence of the interviewers none of the nonsense they do surprises me.
- unethical_ban 1y agoI worked in IT ops there for a long time, and since then have seen the inner workings of companies in several different fields. They had by far the most competent cybersecurity group I've witnessed. Things have changed in a decade maybe. But, they still use proprietary TOTP from Symantec which is annoying.
- freedomben 1y agoYeah I've never worked there, but been a customer since 2005. For many years there, USAA was really cutting edge of tech and highly competent. The system has slowly gotten a little less usable though, but at least it still works most of the time
- RandomBacon 1y ago> But, they still use proprietary TOTP from Symantec which is annoying. They at least used to, but I'm not sure they still do. (And when they did, I was able to copy the key into a MFA app of my choice.) But now as an end-user, it's all built in to their own banking app. I don't use the code from the app though, because I just use my personal 4 digit pin (after entering in my unique password from my password manager).