14 ms·
Do not ask me personal details when calling me
- mooreds 14y agoA reverse caller id app like NumberGuru might be a good idea too.
- e1ven 14y agoThe problem is caller ID is on the honor-system. It's very difficult to be sure who is actually calling.
- jevinskie 14y agoCaller ID is easily spoofed and the telco's have no intention of fixing that.
- illuminate 14y agoThese systems don't use Caller ID, I believe they use http://en.wikipedia.org/wiki/Automatic_number_identification http://en.wikipedia.org/wiki/Automatic_number_identification which is more difficult (but not impossible) to spoof. I had pretty good luck with http://www.trapcall.com/ http://www.trapcall.com/ when I had a phone stolen and the thief called me back. Didn't get the phone back, but the system worked as promised.
- simon20121116 14y agoIf you use a internet phone system, you can easily put the name you want on the caller id. Which make it alot easier to fool people. So, just like he said, I think its better to just say I will call back. ;-)
- andrewcooke 14y agoisn't this confusing two different problems? A - the bank, asking for some details, is trying to confirm the identity of the customer. B - the proposed protocol - calling back with a ticket number - is trying to confirm the identity of the caller. both seem to be trying to solve reasonable problems, but they're not equivalent. maybe the point [aha! - see reply - also, hi leif, i think i knew you on quora] is that you should not give personal details (A) until the company identity is clear (B). that makes sense. but that means that you need both - you call back and then they ask for personal details (B then A). [and i am not convinced the original author understood all this.]
- leif 14y agoThe problem is that authenticating the customer is harder than authenticating the bank. If I call my bank, I can pretty well trust (within reason) that I've reached my bank. Once that happens they can authenticate me by asking for my private information, which I am not comfortable with unless I authenticate them first. Calling back with a ticket number doesn't solve both auths, but it does order them in a secure way.
- leif 14y agoYou edited before I submitted :)
- dsr_ 14y agoMore to the point: don't give out such details to people who call you. Or email you, chat you, or use Apple's new iMind telepathic enabler. Assume everyone asking for such things are scammers.
- DanBC 14y ago>Assume everyone asking for such things are scammers. That's excellent advice, and everyone should follow it. Unfortunately some banks disagree and will cancel your credit cards when you fail one of their fraud check phone calls. > And guess what, the only way to be sure that it’s your bank you’re talking to, is to call them yourself. Period. Some callers tell you details of your account as a way of identifying themselves. There's a scam in the UK where they call you, and ask you to call them back. You hang up, then pick up the phone and dial the number. But because they initiated the first call the line doesn't clear until they hang-up, and they don't hang up while you're dialling the number. (And the sometimes play recorded ring tones before they "answer").
- Evbn 14y agoWow UK has antiquated hardware.
- growse 14y agoThat's the problem with inventing everything - you end up with 'v1' of everything. And v1 is always awful. :p See also: London Underground.
- pavel_lishin 14y agoThat seems like an odd way to run a phone system. Couldn't I keep someone from making any outgoing calls just by calling them once, and leaving my phone off the hook?
- DanBC 14y agoIt's very frustrating hearing someone walking around when they think they've disconnected but they haven't.
- michaelt 14y agoMy phone company has a neat way around this. When I declined to give them my details as they'd called me they proposed I give my date of birth with one number changed, and they'd tell me which one was changed and what the true value was. That's obviously not a completely secure system, but validating by birth date isn't very secure anyway.
- mikeash 14y agoFigure 1/3rd of people will change the month, then you have 11 possibilities for the true value, so a scammer would be able to get about one correct answer for every 33 people they called... probably enough to make it worthwhile for them. The best way around this is to end the call and then call the company back at their publicly listed phone number.
- krisoft 14y agoNeat. Problem is that I would not consider my birthday private data, so I must assume that an aspiring scammer can get hold of it. (If for nothing else, just because I broadcast it on facebook.) They solved the first half of the puzzle: That is how to verify the knowledge of an information without any of the parties leaking too much of it. But they did this with an information, which knowledge is not worth verifying.
- shasta 14y agoI like to talk the guy on the other end of the phone through computing a secure hash of my personal data, by hand.
- pavel_lishin 14y agoI typically do one of two things if I don't feel like calling them back. 1. Give them a wrong piece of contact information, like the wrong house address on the correct street. A scammer without this information would probably accept it; a company that already has this information will point out that that it's wrong. 2. Only give them a part of the information, like the last digit of my house number, and ask them to supply the rest - this assures both of us that we're the person we're expecting to talk to.
- riz_ 14y agoMy bank recently asked for my password on the phone in order to identify me. They literally wanted me to tell them the password I use for my online banking account. I made a scene of course, then we settled for the birthdate.
- sneak 14y agoThanks for that, by the way. I was able to leverage that into a real password reset at the real bank. ;)
- kaolinite 14y agoThe way my bank does it is to ask me to confirm details. So they will give me a choice of 3 months, 3 days and 3 years for my date of birth and I have to pick the correct one. They also ask me to confirm recent transactions (though there has never actually been a fake one). It's not perfect and I agree a ticket/reference code I could ring back and give them would be better, but it's better than just flat-out asking for details.
- ZoFreX 14y agoMy bank insists on checking personal details when they ring me. My protocol is to answer incorrectly the first time, and if the caller doesn't realise my details are incorrect, they didn't know them in the first place!
- delano 14y agoWhen they ask you to identify the correct date, they're validating you. Either way, you're giving them your birthday just the same (a malicious caller could use that technique to confirm a date).
- philhippus 14y agoIf they called me and leave a ticket number, I might not call them back. Maybe I don't want to pay for their phonecall.
- Shenglong 14y agoAlternative: Provide them false information; if they are who they say they are, they'll be confused, at which point you know it's probably the bank. :)
- Anechoic 14y agoIt takes a 10 second google search to find contact numbers. While that's striaghtforward for anyone who is reading this, that's actually a show-stopped for a number (a significant number I'd bet) of folks for any number of reasons including: * no reliable internet connection * just don't "get" the whole Google/internet search thing * accidentally installed a trojan that redirects internet searches to scammer site so internet searches are useless And these aren't random excuses I just made up, each of those are situations I've encountered with otherwise well-educated, upper-middle class to higher income individuals in the last few weeks. So while I agree a better approach to telephone authentication is needed, a solution really needs to address the needs of 100% of customers, which this doesn't.
- scott_w 14y agoThat's only half true. An organisation such as your bank is in the Yellow Pages. Your customers or users will know how to use that at least. In fact, people who don't understand Google have a better understanding of the Yellow Pages.
- jamaicahest 14y agoOr they could just, you know, put the number on the bills/letters sent to the customer.
- oxplot 14y agoPoint taken. A solution for wider customer coverage is to include the appropriate contact number on the back of all bank issue debit/credit cards.
- zaidf 14y agoFew days ago: Caller: I'm calling from blabla collections agency. May I speak with the owner of Acme.com Me: Speaking... Caller: Sir, are you the owner of Acme.com? Me: Yes... Caller: Can you confirm your name? Me: What is this about? Caller: I cannot reveal anything until I confirm I am speaking with the owner of Acme.com. May I have the last 4 of your social? ... Me: (I relent) It's 4823 Caller: That does not match my record. Me: That is my last four of social (truth) Caller: Do you have your corp no? Me: Listen, why did you ask me to confirm my social if what you really need is my corp no? Caller: Blabla. I will have to hang up if you won't confirm. Me: Good bye --- Is this crap legal?
- aw3c2 14y agoDid you not even ask who was asking?
- zaidf 14y agoShe gave me the name of the collections' agency and her own first name.
- weinzierl 14y agoExactly, what's the point of a security check if they keep asking you until you pass. I had a similar experience when I tried to redeem some Travelers Cheques. Clerk claimed signatures wouldn't not match, and wanted me to sign again at the back of the Cheques. She handed me slip of paper and asked me to practice before I tried again. I was baffled but certainly preferred that over being arrested;-)
- tomjen3 14y agoMy dad hadn't signed his credit card, so she handed it back to him, told him to signed it, took it back -- and _compared_ the two signatures. The only reason this kind of behaviour makes any kind of sense is if she (and the clerk in your example) were just going through the motions and didn't actually care about the security.
- Zenst 14y agoThe whole verification of somebody over a phone without a previously agreed non-personal identification code has always bemused me. The difference between "Hello MR X this is your bank, before we talk any further we need to ask you a few security questions about you" and "Hello, what you wearing" are not that far apart. I recall one long conversation with my mobile telco provider at the time becasue they called from a number I did not recognise and ended up in a you move first in the quest to verify each other. I asked ok so you want my date of birth, tell me the year and I will confirm the rest - you see the stalemate that ensured. For them to prove they were who they said they would of had to devuldge private information they can only devuldge to me after they have proven that I am me, yet you see the lament of it all. The focus is all about individuals having the abiulity to prove who they are to people who do not prove who they are and then cause both stress with fraud and the like wondering how can this happen. Sure you can use a different email address for every secure contact and even phone numbers and address's to some level of protection. But you only get one date of birth, one mothers maiden name, one my first pets name and with that I like to vary the pet and maiden names in that I never devuldge the true actual answears. Nothing at all saying your mothers maiden name is "Joan of arc" or other random answears that you will remember. I do advicate getting a preium number or a number that pays you be it some mobile service that gives you minutes for every minute people call you or some payback premium number. Then let that spam out and enjoy all the cold calling and sales calls you like knowing you gain from it. But when you get a call from somebody who has to ask you security questions then ask yourself, how do they prove who they are to you before you give them private confidentual information.
- jeromeparadis 14y agoYeah. These practices are plain stupid and I do the same. YOU tell me who you are and I'll call you. Don't even give me your number because it could still be a trap. For example, if it's a credit card company, if I can't call back at the number on the back of the card to know what's this about, they're doing something wrong.
- archildress 14y agoIt seems though that the problem is that even if reliable companies discontinued this practice, people truly attempting to scam you could be mistaken for tactless companies.
- JarekS 14y agoWe've created Discourse ( https://www.discoursehq.com https://www.discoursehq.com ) to let big corpo have a direct link with their customers so they don't have to call them - instead they just send a message and nature of our channel is that customer can engage in a conversation, get more details etc. Would you, dear HNers, use it? We will launch first big brand customer in December.
- ams6110 14y agoMuch simpler is to establish a "shared secret" when you open the account. "This is XYZZY bank calling about your account, your pre-established secret word is 'plugh.'" Then you know with some certainty that the caller is legit. Assuming you remember what your secret word is. Still better if you initiate the call though.
- BHSPitMonkey 14y agoMy credit union does this in the other direction (I have a pre-established secret word that they ask for in order to prove I'm myself; I think there's even another one I'm supposed to use if I'm under duress, but I can't recall).
- mseebach 14y agoYeah, that's exactly the same as the scenario outlined in the OP. How do you know that whoever called you is in fact your credit union?
- corin_ 14y agoPossibly overthinking but... Bank calls my phone, someone other than me answers, bank says "plugh", that someone else can then at a later date call me and I will believe they are my bank.
- mrbill 14y agoWhat I hate, and don't quite understand why they do it - are the "survey" places that call up and insist on me confirming what my job title or position is. Obviously working off a script, because "I'm sorry, I don't see what that has to do with anything, how can I help you?" throws them for a loop. "I just need to confirm that you are blahblah". "Again, that's irrelevant, how can I help you?"
- alimoeeny 14y agoI needed to reset my Comcast password, the support person asked me what was your last password? and he was upset that I didn't tell him/her! unbelievable,
- dangrossman 14y agoThe reason calling a company back at a listed number doesn't work is that companies very rarely operate their own call centers, and they very often outsource functions to more than one call center at a time, and they very often shift work between these call centers over time. For example, the call center you reach when you call the number on the back of your credit card is not the same one that calls you when the bank flags a suspicious transaction on the card. The first is an inbound call center hired and trained on service scripts, the second is an outbound call center that only handles the fraud checks and is probably serving multiple banks. They're possibly not even in the same country. They're possibly not even the same depending on what time you call -- Comcast, for example, has inbound call centers in the US open during business hours, but routes calls to the same number to Indian call centers during late night hours. Each call center has different training and different access to the customer accounts. The inbound tech support call center doesn't have access to the company's billing systems, while the outbound fraud verification call center doesn't have access to support tickets. Having everyone a company tries to reach by phone call back at the company's phone number would lead to a phone menu with more options than buttons on your phone.
- kevinpet 14y agoThere's a valid point in this, but the article seems to miss it when he says "In fact, if I hear the caller telling me personal details about myself, I hang up even faster." On the contrary, that's perfectly valid. They've already partially validated that they're talking to you. The attack scenario of stealing identities by getting banks to call someone while you intercept the phone call isn't plausible. Back in 2008, Wells Fargo called me up and asked me to verify myself via a similar system. I refused and called the number on the back of my credit card and identified myself to their fraud department that way. This year, same scenario (suspicious purchases), but this time the fraud department just asks if they are speaking to me and then asks me whether I recently bought two tickets to China and a new car stereo. So learning has occurred.
- oxplot 14y agoOh, that was more of a personal comment. What I meant was that I ignore the call because I simply disagree with this method.
- devb0x 14y agoBeen here, my wife too. I will not respond to calls like this nor phone offers for financial services. Especially not when they say they do not have any info that can send to me beforehand.
- scotty79 14y ago> Call the customer and give them a reference/ticket number and ask them to call you back quoting that number. I'm not sure what would that accomplish. What would prevent someone else than me that they reached by accident from calling them back with the ticket number that they gave him when they assumed it was me? IMHO everybody should have government issued keypair with public part easily checkable on government site. When they want to confirm your identity they just ask you to sign something random with your key. "To confirm your identity sir please enter the following into your government issued identity card and read to me back what you see on the display of the card."
- iamdave 14y agoWhy do you suggest leaving this information with the government, again?
- scotty79 14y agoI'm not sure how it goes in USA but in the countries I know when the child is born his/her name gets registered at government office and when the child reaches 18 he/she gets plastic card that is his/her proof of identity. I think this id card should contain private key securely embedded and public key easily readable and that government should publish public keys. To avoid leaking of private key this ID card should be able to cryptographically sign given data without revealing private key.
- jtheory 14y agoThe ticket number isn't to confirm your identity -- it's just so that you can pick up whatever message they need to deliver. Before giving you that message, they might ask you security questions, etc., which you'd be able to answer (because you called them back at their listed phone number and you know it's them).
- Tzunamitom 14y agoI agree this is very annoying, as are the conversations with the call-centre staff who can't believe you won't give out this information freely "I'm sorry sir, you have to, it's company policy". I generally challenge them to provide 3 half-pieces of non-critical information to verify who they are, but there must be a better way? Surely this is ripe for disruption - can't the telcos provide a "Verified Caller" service is the same way as browsers now do to prevent phishing? So let's say HSBC call me, their name will be in red on my iPhone with "verified caller" listed below, having confirmed their details with the telco beforehand. That would solve the problem, and provide a little extra revenue for telcos...