funsec mailing list archives

Re: Online banking insecurity


From: Jeffrey Walton <noloader () gmail com>
Date: Thu, 19 Sep 2013 13:08:59 -0400

On Thu, Sep 19, 2013 at 12:43 PM, Rob, grandpa of Ryan, Trevor, Devon
& Hannah <rmslade () shaw ca> wrote:
....
The agent (no, sorry, "service manager," these days) was careful to point out that
he was *not* going to ask me for my password.  Then he set up a conference call
with the online banking system, and had me key in my password over the phone.

(OK, it's unlikely that even a trained musician could catch all six digits from the
DTMF tones on one try.  But a machine could do it easily.)
They've already learned ways to beat that (and more):
http://www.theguardian.com/money/2012/may/23/credit-card-users-phone-call-courier-scam.
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: