7 ms·
The purpose of the original call was to get a change of address (for sending forms). I probably should have clarified that but it seems like a pretty generic r
by bjpless 14y ago
The purpose of the original call was to get a change of address (for sending forms). I probably should have clarified that but it seems like a pretty generic request.
No need to believe me about the "truthfulness of the claims". Just call Vanguard yourself and ask if they handle cases this way. They will confirm.
You ask about security responsibility. I absolutely agree with you that customers have to take on a lot of it (Vanguard is not responsible for creating a 20 char password on your behalf).
I do think, though, that you have to draw the line before training your users to accept phishing attempts. That is what is happening here.
My biggest reason for pitchforking Vanguard here is that, for many people, they hold more assets than commercial Banks. Their security protocols should have HIGHER standards.
- atwebb 14y agoI'm with you on this one and it has bothered me tremendously for years, but this is hardly limited to Vanguard, I know for a fact that many, many other institutions do this and will immediately ask for your secret password, or divulge too much information if I wasn't actually the intended recipient. Thanks for bringing more attention to this. Personally, I think it is a fairly big deal and a responsibility that Vanguard should shoulder more of. They aren't providing free checking, or free email, or anything of that nature. They are taking money (pretty good money) for a financial service. Their web presence has improved by leaps and bounds and I'm surprised that this hasn't changed.
- davidcuddeback 14y agoI agree with both of you that Vanguard has a responsibility to keep their customer's money secure. Vanguard holds a large chunk of my money (much more than any single bank), and I'd like to know that it's secure. bpatrianakos is also right. Security has to be balanced with service. I think Vanguard's call would be okay if the security questions they ask are compartmentalized. What I mean by that is that they have separate security questions that they ask in a low-security environment (like an outgoing phone call) that they will never trust for high-security actions, such as withdrawals or password resets. Those actions should require a further level of authentication and should never be done via outgoing correspondence. We should at least confirm that the security questions aren't compartmentalized before we break out the pitchforks. However, given that Vanguard limits passwords to 10 characters with limited support for punctuation, I don't have much faith that they have any sort of compartmentalized security.
- davidcuddeback 14y agoDo you happen to remember the phone number that the call originated from? If it's a phone number that's published on Vanguard's site, at least one could add that phone number to their address book so that your phone says "Vanguard" when receiving the incoming call. That would offer some protection from phishing attacks in this case. (But you're right that this still trains people to be vulnerable to phishing attacks.)
- idunno246 14y agoExcept caller id / phone number is easily spoofed