Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My rule is simple: if you contact me, you are the one that had to authenticate. Otherwise you are probably a scammer.

Although, I haven’t had many instances of communications from my bank where I cared about them authenticating. Like, if they tell me there is a problem, I can go check it out through the app, website, or whatever the user-initiated channel is. When I feel like it.



I don’t have a good way to authenticate someone is calling from the bank on my end.

I ask what the basic issue is, then call the general bank number (or a number to their department, which I validate online before calling it). That way I’m initiating the call to a trusted number, and they can go through their process to authenticate me. Every time I’ve done this the person calling has understood and seemed to appreciate the caution.


> I don’t have a good way to authenticate someone is calling from the bank on my end.

You could ask them to list your last 3 transactions, and their exact amounts. Easy to cross-reference by looking at your banking website / app.


Unless the system you use the check that balance is compromised on your end or their end. If you have malware, they can be looking at the same numbers you’re looking at, so that isn’t fool-proof. If your account is already compromised, they may just be phishing for 2fa tokens to initiate some kind of account change, like the kind that would complete their total account takeover, at least until you or the bank notices suspicious activity.


i mean if you have malware, all bets are off IMO. But good point.


It is such a goddamned tragedy that we’ve come to this. And also an avoidable one: every E2E messaging app (WhatsApp, Android Messages, iMessage) should be able to properly authenticate the caller. But I presume services are asking too much money for this, and nobody wants to hand yet another vital service to Apple/Google/Meta. So instead we all suffer.


Be careful what you wish for. This problem is solved in China — you can contact many government agencies and major companies over WeChat and be sure that you're talking to the real entity, but the downside is that WeChat has a copy of your passport and knows everything about you.


>This problem is solved in China

It isn't. China is the best example that draconian identity verification / KYC processes don't stop scammers.


could you explain more? im always under impression that chinese scam/fraud are rare. what keywords should i search for?


Most scams in China are a mix of romance and investment scams.

Since WeChat allows accounts created outside of China, it's these accounts that are used. And it's why there are times it's a pain to create a WeChat account outside of China.

The financial transactions all take place outside of WeChat.


I stick to this except when I make some unusual credit card purchase and immediately get called to verify it. I don't like it, but usually I need to make the purchase. If someone had the feed of risk denied CC purchases, they could gather a lot of personal information. Probably there is lower hanging fruit for fraud.


Can be both. You need something from a bank (for example a money transfer), and they call you to confirm. In my case this is 99% of all incoming bank calls to me.


How do you authenticate them?

I've never heard of this, I'm very curious.


I can’t, lol. It is a roundabout way of saying I ignore who organizations claim to be when they contact me.


I don't know what your point is then. I've gotten important calls about fraud that it was certainly in my interest not to ignore. And it's easy to call back to verify it's the bank.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: