While that's striaghtforward for anyone who is reading this, that's actually a show-stopped for a number (a significant number I'd bet) of folks for any number of reasons including:
* no reliable internet connection
* just don't "get" the whole Google/internet search thing
* accidentally installed a trojan that redirects internet searches to scammer site so internet searches are useless
And these aren't random excuses I just made up, each of those are situations I've encountered with otherwise well-educated, upper-middle class to higher income individuals in the last few weeks.
So while I agree a better approach to telephone authentication is needed, a solution really needs to address the needs of 100% of customers, which this doesn't.
There actually seems to be a trend amongst some corporations (for example ISPs/telcos) of a certain size to hide their phone number as well as possible. They'd rather route requests through an online ticketing system that is often of questionable value to the person requiring support. Usually you can find it somewhere in their impressum, but when you click on anything called "contact" or "support" you end up in a maze.
A Google search usually does it, but the phone number really should be easily available from the website.
An organisation such as your bank is in the Yellow Pages. Your customers or users will know how to use that at least.
In fact, people who don't understand Google have a better understanding of the Yellow Pages.
So then I have to explain that if I don't trust them to be who they say they are, then I certainly don't trust them to give me a phone number...
Caller: I'm calling from blabla collections agency. May I speak with the owner of Acme.com
Me: Speaking...
Caller: Sir, are you the owner of Acme.com?
Me: Yes...
Caller: Can you confirm your name?
Me: What is this about?
Caller: I cannot reveal anything until I confirm I am speaking with the owner of Acme.com. May I have the last 4 of your social?
...
Me: (I relent) It's 4823
Caller: That does not match my record.
Me: That is my last four of social (truth)
Caller: Do you have your corp no?
Me: Listen, why did you ask me to confirm my social if what you really need is my corp no?
Caller: Blabla. I will have to hang up if you won't confirm.
Me: Good bye
---
Is this crap legal?
I had a similar experience when I tried to redeem some Travelers Cheques. Clerk claimed signatures wouldn't not match, and wanted me to sign again at the back of the Cheques. She handed me slip of paper and asked me to practice before I tried again.
I was baffled but certainly preferred that over being arrested;-)
When I declined to give them my details as they'd called me they proposed I give my date of birth with one number changed, and they'd tell me which one was changed and what the true value was.
That's obviously not a completely secure system, but validating by birth date isn't very secure anyway.
1. Give them a wrong piece of contact information, like the wrong house address on the correct street. A scammer without this information would probably accept it; a company that already has this information will point out that that it's wrong.
2. Only give them a part of the information, like the last digit of my house number, and ask them to supply the rest - this assures both of us that we're the person we're expecting to talk to.
They solved the first half of the puzzle: That is how to verify the knowledge of an information without any of the parties leaking too much of it. But they did this with an information, which knowledge is not worth verifying.
The best way around this is to end the call and then call the company back at their publicly listed phone number.
The difference between "Hello MR X this is your bank, before we talk any further we need to ask you a few security questions about you" and "Hello, what you wearing" are not that far apart.
I recall one long conversation with my mobile telco provider at the time becasue they called from a number I did not recognise and ended up in a you move first in the quest to verify each other. I asked ok so you want my date of birth, tell me the year and I will confirm the rest - you see the stalemate that ensured. For them to prove they were who they said they would of had to devuldge private information they can only devuldge to me after they have proven that I am me, yet you see the lament of it all.
The focus is all about individuals having the abiulity to prove who they are to people who do not prove who they are and then cause both stress with fraud and the like wondering how can this happen.
Sure you can use a different email address for every secure contact and even phone numbers and address's to some level of protection. But you only get one date of birth, one mothers maiden name, one my first pets name and with that I like to vary the pet and maiden names in that I never devuldge the true actual answears. Nothing at all saying your mothers maiden name is "Joan of arc" or other random answears that you will remember.
I do advicate getting a preium number or a number that pays you be it some mobile service that gives you minutes for every minute people call you or some payback premium number. Then let that spam out and enjoy all the cold calling and sales calls you like knowing you gain from it.
But when you get a call from somebody who has to ask you security questions then ask yourself, how do they prove who they are to you before you give them private confidentual information.
Assume everyone asking for such things are scammers.
That's excellent advice, and everyone should follow it. Unfortunately some banks disagree and will cancel your credit cards when you fail one of their fraud check phone calls.
> And guess what, the only way to be sure that it’s your bank you’re talking to, is to call them yourself. Period. Some callers tell you details of your account as a way of identifying themselves.
There's a scam in the UK where they call you, and ask you to call them back. You hang up, then pick up the phone and dial the number. But because they initiated the first call the line doesn't clear until they hang-up, and they don't hang up while you're dialling the number. (And the sometimes play recorded ring tones before they "answer").
"This is XYZZY bank calling about your account, your pre-established secret word is 'plugh.'"
Then you know with some certainty that the caller is legit. Assuming you remember what your secret word is.
Still better if you initiate the call though.
Provide them false information; if they are who they say they are, they'll be confused, at which point you know it's probably the bank. :)
On the contrary, that's perfectly valid. They've already partially validated that they're talking to you. The attack scenario of stealing identities by getting banks to call someone while you intercept the phone call isn't plausible.
Back in 2008, Wells Fargo called me up and asked me to verify myself via a similar system. I refused and called the number on the back of my credit card and identified myself to their fraud department that way.
This year, same scenario (suspicious purchases), but this time the fraud department just asks if they are speaking to me and then asks me whether I recently bought two tickets to China and a new car stereo. So learning has occurred.
For example, the call center you reach when you call the number on the back of your credit card is not the same one that calls you when the bank flags a suspicious transaction on the card. The first is an inbound call center hired and trained on service scripts, the second is an outbound call center that only handles the fraud checks and is probably serving multiple banks.
They're possibly not even in the same country. They're possibly not even the same depending on what time you call -- Comcast, for example, has inbound call centers in the US open during business hours, but routes calls to the same number to Indian call centers during late night hours.
Each call center has different training and different access to the customer accounts. The inbound tech support call center doesn't have access to the company's billing systems, while the outbound fraud verification call center doesn't have access to support tickets.
Having everyone a company tries to reach by phone call back at the company's phone number would lead to a phone menu with more options than buttons on your phone.
Surely this is ripe for disruption - can't the telcos provide a "Verified Caller" service is the same way as browsers now do to prevent phishing?
So let's say HSBC call me, their name will be in red on my iPhone with "verified caller" listed below, having confirmed their details with the telco beforehand. That would solve the problem, and provide a little extra revenue for telcos...
I'm not sure what would that accomplish. What would prevent someone else than me that they reached by accident from calling them back with the ticket number that they gave him when they assumed it was me?
IMHO everybody should have government issued keypair with public part easily checkable on government site.
When they want to confirm your identity they just ask you to sign something random with your key. "To confirm your identity sir please enter the following into your government issued identity card and read to me back what you see on the display of the card."
Before giving you that message, they might ask you security questions, etc., which you'd be able to answer (because you called them back at their listed phone number and you know it's them).
A - the bank, asking for some details, is trying to confirm the identity of the customer.
B - the proposed protocol - calling back with a ticket number - is trying to confirm the identity of the caller.
both seem to be trying to solve reasonable problems, but they're not equivalent.
maybe the point [aha! - see reply - also, hi leif, i think i knew you on quora] is that you should not give personal details (A) until the company identity is clear (B). that makes sense. but that means that you need both - you call back and then they ask for personal details (B then A).
[and i am not convinced the original author understood all this.]