logoalt Hacker News

rolphyesterday at 9:05 PM1 replyview on HN

those banks that do that are grooming customers for failure, they create a workflow that is close to an attack.

in my region AT&T has a very explicit statement not to reveal MFA codes to anyone who asks, is not part of thier system to do that.

there is 1 bank in my area that does voice call relay over the phone, the others keep it 10 fingers relayed from phone to authentication form.

guess who has the most problems with account compromise, and fraud claims? yes, that one bank. it has a phishing vector in its system.


Replies

docmarstoday at 1:07 AM

Half the issue is, people need to acquire the same wisdom about cybersecurity hygiene as they do looking both ways before crossing the street, but even that's too much to ask for some people. They just don't do it.

At some point, it has to become the responsibility of the potential victim, if liability is such a concern from big tech companies.