Whenever I'm asked for some identifying piece of information via phone, I give a wrong answer.
If they say, "hm, that's not what I have here," I can be at least somewhat certain that they already have that information, and are probably legitimate. If they blindly accept it, then I know they ain't on the level.
If they ask for your password, an attacker can simply try to log in with it and then if it fails say "looks like that's not correct, could you try again Mr. Smith?"
Comments
Whenever I'm asked for some identifying piece of information via phone, I give a wrong answer.
If they say, "hm, that's not what I have here," I can be at least somewhat certain that they already have that information, and are probably legitimate. If they blindly accept it, then I know they ain't on the level.
It's possible to check passwords in real time against the site.
What do you mean?
If they ask for your password, an attacker can simply try to log in with it and then if it fails say "looks like that's not correct, could you try again Mr. Smith?"
If an alleged customer service rep straight-up asked me for my account password, I would 100% assume that I was being phished.