Skip to content

Comment on The Man Who Hacks Your Employees

Comments

Not sure how it is in USA/Europe - but in Australia, some of the biggest banks/telcos still ring up customers (from private numbers) and ask for all your personal details to confirm your identity before proceeding with the call. Some even ask for plaintext passwords over the phone. At the same time they have big warnings on their webpages about phishing and how they'll never ask for personal details over email.

More than once I've explained that providing all my details in this fashion directly contradicts the security policy of the banks, but it takes some convincing to get the phone operators to give you a number you can confirm is legitimate and call them back. Its clearly not on the call center script and they dont understand why I am being so pedantic.

Whenever I'm asked for some identifying piece of information via phone, I give a wrong answer.

If they say, "hm, that's not what I have here," I can be at least somewhat certain that they already have that information, and are probably legitimate. If they blindly accept it, then I know they ain't on the level.

It's possible to check passwords in real time against the site.

What do you mean?

If they ask for your password, an attacker can simply try to log in with it and then if it fails say "looks like that's not correct, could you try again Mr. Smith?"

If an alleged customer service rep straight-up asked me for my account password, I would 100% assume that I was being phished.

Just a few days ago I had someone from Cox call me up out of the blue to ask me how I liked their service and to tell me about some of their other services. But first they wanted to verify they were speaking to the correct person.

I refused, told the woman flat out she called me, I didn't call her, therefore she was getting no information from me. I also told her I was happy with my Cox account and had no interest in whatever it was she was trying to sell. To her credit, she thanked me and ended the call amicably which is exactly what should have happened imo.

I understand the need for it from the company's perspective, but for me it was strange, uncommon, and I'm just too damned cynical. Even if I were interested I would have insisted on calling back through Cox's number before speaking with someone.

There was a time when it was relatively safe to speak with someone who calls you like that, but it's been years since I've felt comfortable doing so.

There was a time when it was relatively safe to speak with someone who calls you like that, but it's been years since I've felt comfortable doing so.

I'm not so sure about that, I think it existed for all my life, just wasn't very common until now.

I remember over 20 years ago getting a phishing call trying to get personal information about me.

Please keep it up, I can't even write a coherent reply to this discussion because of how furious these policies make me. Its not just banks, its telcos, energy companies, government agencies, pretty much everywhere. They all think that knowing my D.O.B and address confirms my identity.

On the banks, I've never had westpac attempt this (I think,) but they do still have this bizarre 6 letter character limit to my online banking password where they just ignore any letters after 6 characters so it seems like you are secure but in fact are not very secure at all.

Comcast now requires the last 4 digits of your social security number to do anything. Even though it's not the whole thing, I'm extremely uncomfortable whenever I have to call them.

Are you actually required to give them your real social security number? Or can you give them a random string of digits that you would like to be identified by?

They require social for credit check when signing up, then they're now using the last 4 digits for account verification. It seems really awkward and forced. They then also have you provide address, name, phone number when speaking to the CSR, which seems redundant. If I have someone's social, I probably know where they live. And I certainly wouldn't be calling Comcast on their behalf.

They probably don't require your Social Security Number. I've avoided giving mine out by paying a deposit to my cable internet company, my electric company, and I use prepaid (which is cheaper than post-paid for the same service) to avoid giving it to a phone company. I also leave it blank on my doctor's forms and other forms. No one has ever hassled me about it.

They run a credit check on you beforehand, that's what the SSN is for. I'm sure you can ask to opt out of the credit check as long as you are willing to give them a hefty down payment.

Many times you can avoid the SSN by asking and being willing to jump though a couple extra hoops.

Interesting when I worked for the big telecom in the UK 20 years ago where give very strict instructions that NI numbers (uk' ss no) where NEVER to be used for any customer id purpose.

On pain of having the IB (Bt Security) jump up and down on you with size 9 boots - think the auditors in the laundry files but worse.

When I was in Australia, I refused to give the information and insisted on calling them back. Never caused any trouble.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.