4 ms·
These are the rules
- e40 12y agoI'm still blown away that most of the banks I do business with send URLs in emails. I once tried to explain why this was a bad idea to a customer service rep. What a waste of time.
- lisper 12y agoThe number of layers of management between a CSR and someone with actual decision-making authority at a bank is staggering. The entire financial industry is more like fast food than it is like, say, medicine. In medicine people regularly interact with doctors who actually know what's going on. In the financial industry, the vast majority of workers have no clue how it works under the hood. They are mostly technicians and sales people. Unless you have made a concerted effort (it took me four years) you have almost certainly never interacted with a banker with actual decision-making authority.
- _RPM 12y agoCan you explain here, why it is bad idea to send URLs in emails?
- LaikaF 12y agoIt gets people used to clicking URLs in emails. This is a bad habit.
- ptaffs 12y agoif people really cared, they'd follow The Rules. How many other conveniences do we drop? I rarely click links in e-mail, but my non-technical eternally trusting-of-strangers friends will always be tricked into doing stupid stuff. If it's not links in e-mail, it's pop-up-windows, or salesmen with extended warranty.
- pessimizer 12y agoIgnorant people aren't fungible, they're people. The more idiot proof you make things, the more idiots you save - it isn't binary. >How many other conveniences do we drop? We evaluate them on a case by case basis, because we're thoughtful people.
- e40 12y agoPhishing. And a comment above: https://news.ycombinator.com/item?id=8243227 https://news.ycombinator.com/item?id=8243227
- cbhl 12y agoEh, AFAICT, from the bank's perspective, it's a matter of convenience that can be written off with insurance.
- stronglikedan 12y agoI'm just curious as to why it's a bad idea? I click URLs in emails all the time. I just hover over it to make sure that the hyperlink matches the text. Is there another possible security issue that I'm missing?
- Eiriksmal 12y agoCheck out the first sentence/paragraph of this post: http://feross.org/html5-fullscreen-api-attack/ http://feross.org/html5-fullscreen-api-attack/ (from https://news.ycombinator.com/item?id=4629906 https://news.ycombinator.com/item?id=4629906)
- tokenizerrr 12y agoMost mail clients won't execute javascript, though.
- stronglikedan 12y agoVery interesting. I suppose it would only affect browser based email clients, but a lot of the non-tech-savvy people I work with use the web mail client exclusively, so that is definitely an issue.
- e40 12y agoI'm still baffled why I was downvoted into negative territory for my original comment.
- enraged_camel 12y agoDon't worry too much about it. I say incredibly useful and 100% correct things all the time and people still downvote me sometimes!
- zajd 12y agoMost users don't hover
- e40 12y agoReally, I can't believe I'm being questioned on this. Hasn't everyone here heard of phishing? Just because it looks legit doesn't mean it is, especially if you are using IE or a really old browser with bugs.
- chc 12y agoIt makes more sense than doing it over the telephone. I'm not sure how you expect them to send URLs. If you are sophisticated enough not to need a URL emailed to you, then you won't need it, but I don't see a practical alternative for other people.
- e40 12y agoTell me, what URL could a bank need to communicate to me in email that they couldn't replace with instructions like "login and click on ..."?
- ptaffs 12y agoPeople will also follow re-key instructions taking them to phishing sites. They'll tell strangers their passwords and download and run unique video codecs (aka malware) to watch some special comedy video file they've been sent by a friend. The answer is to educate your friends, family and any stranger who will listen to perform some critical analysis on an unsolicited approach by e-mail, phone, sms, or whatever.
- deleted 12y ago[deleted]
- chc 12y agoWell, the obvious if somewhat facetious answer here is "the URL to log in." Another, less facetious one is "a password reset link." But even if we accept that expecting customers to follow long lists of directions without error is remotely reasonable, it doesn't matter because scammers are certainly not going to be fastidious about avoiding links, so by avoiding them yourself, you are only making it more convenient for your customers to get scammed than to actually do business with you. I can see the value in not blindly visiting URLs received via email. I do not see the value in refusing to send links via email. Unless you yourself are a scammer, making people do error-prone extra work to access your site does not protect anyone from getting scammed.
- hliyan 12y agoIt's amazing how many people forget (or ignore due to convenience) rule #1. My credit card company once called me up on some matter and the rep at the other end tried to verify my identity using the usual method (asking me about my mother's maiden name etc). I had to actually say "Wait, you called me. You should be verifying yourself to me". It actually turned out to be a legitimate call, but if I wasn't aware of this rule, a scammer might have easily got me. P.S. I knew this rule because most of Kevin Mitnick's exploits (as he explains in his book) were based on this one vulnerability.
- coldpie 12y agoYep, always tell them you'll handle the issue by calling them back using the number on the card. Maybe ask if they have a name or extension or something if need be.
- Pxtl 12y agoI once had my credit card company do the same thing - call to offer more credit, but needed some info. Complete with a bot greeting. It was virtually indistinguishable from a telemarketed scammer. I had trouble believing it when I called their main number to follow up and find out if this was for real.
- danielweber 12y agoThese are old (and Microsoft browsers are no longer made of paper), but generally timeless rules. A little bit of suspicion can save you a world of hurt.
- eponeponepon 12y ago> A little bit of suspicion can save you a world of hurt. Nicely put. It's just a shame that so much of the modern world works to "a little bit of suspicion is literally the same as claiming aliens probe you nightly".