back
86 comments
It takes a 10 second google search to find contact numbers.

While that's striaghtforward for anyone who is reading this, that's actually a show-stopped for a number (a significant number I'd bet) of folks for any number of reasons including:

* no reliable internet connection

* just don't "get" the whole Google/internet search thing

* accidentally installed a trojan that redirects internet searches to scammer site so internet searches are useless

And these aren't random excuses I just made up, each of those are situations I've encountered with otherwise well-educated, upper-middle class to higher income individuals in the last few weeks.

So while I agree a better approach to telephone authentication is needed, a solution really needs to address the needs of 100% of customers, which this doesn't.

It's not only non-techsavy customers that are to blame.

There actually seems to be a trend amongst some corporations (for example ISPs/telcos) of a certain size to hide their phone number as well as possible. They'd rather route requests through an online ticketing system that is often of questionable value to the person requiring support. Usually you can find it somewhere in their impressum, but when you click on anything called "contact" or "support" you end up in a maze.

A Google search usually does it, but the phone number really should be easily available from the website.

Point taken. A solution for wider customer coverage is to include the appropriate contact number on the back of all bank issue debit/credit cards.
That's only half true.

An organisation such as your bank is in the Yellow Pages. Your customers or users will know how to use that at least.

In fact, people who don't understand Google have a better understanding of the Yellow Pages.

I've had people call me, where I explained all this to them and said I would call them back, only for them to say "do you want me to give you the phone number".

So then I have to explain that if I don't trust them to be who they say they are, then I certainly don't trust them to give me a phone number...

For my bank, my response is always "I'll call you back on the number printed on the back of my bank card. Now, who do I ask for when I call?" So far, they've never expressed surprise and it's always been fairly easy to get back to the right department. So at least some banks seem to understand.
Few days ago:

Caller: I'm calling from blabla collections agency. May I speak with the owner of Acme.com

Me: Speaking...

Caller: Sir, are you the owner of Acme.com?

Me: Yes...

Caller: Can you confirm your name?

Me: What is this about?

Caller: I cannot reveal anything until I confirm I am speaking with the owner of Acme.com. May I have the last 4 of your social?

...

Me: (I relent) It's 4823

Caller: That does not match my record.

Me: That is my last four of social (truth)

Caller: Do you have your corp no?

Me: Listen, why did you ask me to confirm my social if what you really need is my corp no?

Caller: Blabla. I will have to hang up if you won't confirm.

Me: Good bye

---

Is this crap legal?

FYI, the last four digits of your SSN are the only ones that are difficult to guess. The first five digits can be guessed pretty accurately based on your date and location of birth.

http://www.heinz.cmu.edu/~acquisti/ssnstudy/

That was a really bad move on your part. Could be social engineering. Collections agencies don't need to confirm your social before making a collections call.
Exactly, what's the point of a security check if they keep asking you until you pass.

I had a similar experience when I tried to redeem some Travelers Cheques. Clerk claimed signatures wouldn't not match, and wanted me to sign again at the back of the Cheques. She handed me slip of paper and asked me to practice before I tried again.

I was baffled but certainly preferred that over being arrested;-)

Why did you give out those 4 digits? Really, I would have never ever done that. If they want to confirm and they're calling you then they should authenticate themselves, not you!
Did you not even ask who was asking?
My phone company has a neat way around this.

When I declined to give them my details as they'd called me they proposed I give my date of birth with one number changed, and they'd tell me which one was changed and what the true value was.

That's obviously not a completely secure system, but validating by birth date isn't very secure anyway.

I typically do one of two things if I don't feel like calling them back.

1. Give them a wrong piece of contact information, like the wrong house address on the correct street. A scammer without this information would probably accept it; a company that already has this information will point out that that it's wrong.

2. Only give them a part of the information, like the last digit of my house number, and ask them to supply the rest - this assures both of us that we're the person we're expecting to talk to.

I like to talk the guy on the other end of the phone through computing a secure hash of my personal data, by hand.
Neat. Problem is that I would not consider my birthday private data, so I must assume that an aspiring scammer can get hold of it. (If for nothing else, just because I broadcast it on facebook.)

They solved the first half of the puzzle: That is how to verify the knowledge of an information without any of the parties leaking too much of it. But they did this with an information, which knowledge is not worth verifying.

Figure 1/3rd of people will change the month, then you have 11 possibilities for the true value, so a scammer would be able to get about one correct answer for every 33 people they called... probably enough to make it worthwhile for them.

The best way around this is to end the call and then call the company back at their publicly listed phone number.

The whole verification of somebody over a phone without a previously agreed non-personal identification code has always bemused me.

The difference between "Hello MR X this is your bank, before we talk any further we need to ask you a few security questions about you" and "Hello, what you wearing" are not that far apart.

I recall one long conversation with my mobile telco provider at the time becasue they called from a number I did not recognise and ended up in a you move first in the quest to verify each other. I asked ok so you want my date of birth, tell me the year and I will confirm the rest - you see the stalemate that ensured. For them to prove they were who they said they would of had to devuldge private information they can only devuldge to me after they have proven that I am me, yet you see the lament of it all.

The focus is all about individuals having the abiulity to prove who they are to people who do not prove who they are and then cause both stress with fraud and the like wondering how can this happen.

Sure you can use a different email address for every secure contact and even phone numbers and address's to some level of protection. But you only get one date of birth, one mothers maiden name, one my first pets name and with that I like to vary the pet and maiden names in that I never devuldge the true actual answears. Nothing at all saying your mothers maiden name is "Joan of arc" or other random answears that you will remember.

I do advicate getting a preium number or a number that pays you be it some mobile service that gives you minutes for every minute people call you or some payback premium number. Then let that spam out and enjoy all the cold calling and sales calls you like knowing you gain from it.

But when you get a call from somebody who has to ask you security questions then ask yourself, how do they prove who they are to you before you give them private confidentual information.

More to the point: don't give out such details to people who call you. Or email you, chat you, or use Apple's new iMind telepathic enabler.

Assume everyone asking for such things are scammers.

>Assume everyone asking for such things are scammers.

That's excellent advice, and everyone should follow it. Unfortunately some banks disagree and will cancel your credit cards when you fail one of their fraud check phone calls.

> And guess what, the only way to be sure that it’s your bank you’re talking to, is to call them yourself. Period. Some callers tell you details of your account as a way of identifying themselves.

There's a scam in the UK where they call you, and ask you to call them back. You hang up, then pick up the phone and dial the number. But because they initiated the first call the line doesn't clear until they hang-up, and they don't hang up while you're dialling the number. (And the sometimes play recorded ring tones before they "answer").

Much simpler is to establish a "shared secret" when you open the account.

"This is XYZZY bank calling about your account, your pre-established secret word is 'plugh.'"

Then you know with some certainty that the caller is legit. Assuming you remember what your secret word is.

Still better if you initiate the call though.

My credit union does this in the other direction (I have a pre-established secret word that they ask for in order to prove I'm myself; I think there's even another one I'm supposed to use if I'm under duress, but I can't recall).
Possibly overthinking but... Bank calls my phone, someone other than me answers, bank says "plugh", that someone else can then at a later date call me and I will believe they are my bank.
Alternative:

Provide them false information; if they are who they say they are, they'll be confused, at which point you know it's probably the bank. :)

We've created Discourse ( https://www.discoursehq.com ) to let big corpo have a direct link with their customers so they don't have to call them - instead they just send a message and nature of our channel is that customer can engage in a conversation, get more details etc. Would you, dear HNers, use it? We will launch first big brand customer in December.
My bank recently asked for my password on the phone in order to identify me. They literally wanted me to tell them the password I use for my online banking account. I made a scene of course, then we settled for the birthdate.
Thanks for that, by the way. I was able to leverage that into a real password reset at the real bank. ;)
There's a valid point in this, but the article seems to miss it when he says "In fact, if I hear the caller telling me personal details about myself, I hang up even faster."

On the contrary, that's perfectly valid. They've already partially validated that they're talking to you. The attack scenario of stealing identities by getting banks to call someone while you intercept the phone call isn't plausible.

Back in 2008, Wells Fargo called me up and asked me to verify myself via a similar system. I refused and called the number on the back of my credit card and identified myself to their fraud department that way.

This year, same scenario (suspicious purchases), but this time the fraud department just asks if they are speaking to me and then asks me whether I recently bought two tickets to China and a new car stereo. So learning has occurred.

Oh, that was more of a personal comment. What I meant was that I ignore the call because I simply disagree with this method.
If they called me and leave a ticket number, I might not call them back. Maybe I don't want to pay for their phonecall.
Presumably they have a toll-free number, but isn't free domestic calling pretty widespread these days?
The reason calling a company back at a listed number doesn't work is that companies very rarely operate their own call centers, and they very often outsource functions to more than one call center at a time, and they very often shift work between these call centers over time.

For example, the call center you reach when you call the number on the back of your credit card is not the same one that calls you when the bank flags a suspicious transaction on the card. The first is an inbound call center hired and trained on service scripts, the second is an outbound call center that only handles the fraud checks and is probably serving multiple banks.

They're possibly not even in the same country. They're possibly not even the same depending on what time you call -- Comcast, for example, has inbound call centers in the US open during business hours, but routes calls to the same number to Indian call centers during late night hours.

Each call center has different training and different access to the customer accounts. The inbound tech support call center doesn't have access to the company's billing systems, while the outbound fraud verification call center doesn't have access to support tickets.

Having everyone a company tries to reach by phone call back at the company's phone number would lead to a phone menu with more options than buttons on your phone.

The way my bank does it is to ask me to confirm details. So they will give me a choice of 3 months, 3 days and 3 years for my date of birth and I have to pick the correct one. They also ask me to confirm recent transactions (though there has never actually been a fake one). It's not perfect and I agree a ticket/reference code I could ring back and give them would be better, but it's better than just flat-out asking for details.
My bank insists on checking personal details when they ring me. My protocol is to answer incorrectly the first time, and if the caller doesn't realise my details are incorrect, they didn't know them in the first place!
When they ask you to identify the correct date, they're validating you. Either way, you're giving them your birthday just the same (a malicious caller could use that technique to confirm a date).
Yeah. These practices are plain stupid and I do the same. YOU tell me who you are and I'll call you. Don't even give me your number because it could still be a trap. For example, if it's a credit card company, if I can't call back at the number on the back of the card to know what's this about, they're doing something wrong.
I agree this is very annoying, as are the conversations with the call-centre staff who can't believe you won't give out this information freely "I'm sorry sir, you have to, it's company policy". I generally challenge them to provide 3 half-pieces of non-critical information to verify who they are, but there must be a better way?

Surely this is ripe for disruption - can't the telcos provide a "Verified Caller" service is the same way as browsers now do to prevent phishing?

So let's say HSBC call me, their name will be in red on my iPhone with "verified caller" listed below, having confirmed their details with the telco beforehand. That would solve the problem, and provide a little extra revenue for telcos...

> Call the customer and give them a reference/ticket number and ask them to call you back quoting that number.

I'm not sure what would that accomplish. What would prevent someone else than me that they reached by accident from calling them back with the ticket number that they gave him when they assumed it was me?

IMHO everybody should have government issued keypair with public part easily checkable on government site.

When they want to confirm your identity they just ask you to sign something random with your key. "To confirm your identity sir please enter the following into your government issued identity card and read to me back what you see on the display of the card."

The ticket number isn't to confirm your identity -- it's just so that you can pick up whatever message they need to deliver.

Before giving you that message, they might ask you security questions, etc., which you'd be able to answer (because you called them back at their listed phone number and you know it's them).

Why do you suggest leaving this information with the government, again?
I needed to reset my Comcast password, the support person asked me what was your last password? and he was upset that I didn't tell him/her! unbelievable,
isn't this confusing two different problems?

A - the bank, asking for some details, is trying to confirm the identity of the customer.

B - the proposed protocol - calling back with a ticket number - is trying to confirm the identity of the caller.

both seem to be trying to solve reasonable problems, but they're not equivalent.

maybe the point [aha! - see reply - also, hi leif, i think i knew you on quora] is that you should not give personal details (A) until the company identity is clear (B). that makes sense. but that means that you need both - you call back and then they ask for personal details (B then A).

[and i am not convinced the original author understood all this.]

The problem is that authenticating the customer is harder than authenticating the bank. If I call my bank, I can pretty well trust (within reason) that I've reached my bank. Once that happens they can authenticate me by asking for my private information, which I am not comfortable with unless I authenticate them first. Calling back with a ticket number doesn't solve both auths, but it does order them in a secure way.
Been here, my wife too. I will not respond to calls like this nor phone offers for financial services. Especially not when they say they do not have any info that can send to me beforehand.
It seems though that the problem is that even if reliable companies discontinued this practice, people truly attempting to scam you could be mistaken for tactless companies.
A reverse caller id app like NumberGuru might be a good idea too.
The problem is caller ID is on the honor-system. It's very difficult to be sure who is actually calling.
Caller ID is easily spoofed and the telco's have no intention of fixing that.