Reply to topic  [ 7 posts ] 
NatWest admits fraud has led to suspension of bank app 
Author Message
Doesn't have much of a life
User avatar

Joined: Fri Apr 24, 2009 12:43 pm
Posts: 1798
Location: Manchester
Reply with quote
NatWest admits fraud has led to suspension of bank app:
http://www.bbc.co.uk/news/business-19897527

NatWest wrote:
We have currently disabled the Get Cash service while we increase the level of security required.

FFS, this is our money - we would hope you've already got the highest level of security!! It seems not.

This has got to be more than phishing, which is NatWest's official standpoint. One of the NatWest customers who was defrauded thousands of pounds last week hadn't even heard of this service, let alone registered for it. Something's seriously wrong with their security processes if someone else can register a customer for this service, download the app onto their own device and use it at ATMs to withdraw cash - all without the customer being aware of it.

In principal it sounds like a useful service if you're stranded without cash or a card, but something's not right with the implementation of it.
Another example of marketing jumping ahead of security.

_________________
* Steve *

* Witty statement goes here *


Wed Oct 10, 2012 3:15 pm
Profile
What's a life?
User avatar

Joined: Fri Apr 24, 2009 10:21 am
Posts: 12700
Location: The Right Side of the Pennines (metaphorically & geographically)
Reply with quote
This is what you get when you ask your customers security questions that are easy for other people to guess or research the answers to.

_________________
pcernie wrote:
'I'm going to snort this off your arse - for the benefit of government statistics, of course.'


Wed Oct 10, 2012 3:46 pm
Profile WWW
What's a life?
User avatar

Joined: Thu Apr 23, 2009 6:27 pm
Posts: 12251
Reply with quote
I had to phone my bank (some dodgy card cling going in it seems) and they wanted portions of a number. If I have one, I've forgotten it, so the usual round of questions.

Then they wanted to set up a number. They told me the rules for the number:
1 - no sequential digits
2 - No repetitive numbers
3 - it can't by me date of birth, or any member of my family
4 - Nor can it be a phone number
5 - Has to be between 6 and 12 digits long

I doubt I'd be allowed to write it down either.

So, not prepaid for this at all, and not able to think of a number I had a cat in hell's chance of remembering, I declined to set one up. The problem is that all these security things are very machine centric. There has to be a way for me to verify myself to the bank without these protracted processes.

The other day, I had cause to phone PayPal. To call them, I had to log on (with my long password), type in a code that they send me by MMS. The page with their hen number on gives me a 4 digit code. I type that in to the phone when asked and the person dealing with my call knows I'm me. No security questions, and we got straight to the point of my call. Not I believe that it is likely that that could be spoofed too, but it's a far, far friendlier way to checking who I am.

_________________
All the best,
Paul
brataccas wrote:
your posts are just combo chains of funny win

I’m on Twitter, tweeting away... My Photos Random Avatar Explanation


Wed Oct 10, 2012 4:24 pm
Profile
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
The problem is that with an app it means that phones are even more valuable if stolen. They could use your phone to find a cash point and request cash using this app. While in theory this sounds like great customer service, there are so many loopholes that criminals benefit.

I have my Paypal account secured by a 30 digit randomly generated password and a rolling pin generator.

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Wed Oct 10, 2012 5:10 pm
Profile
What's a life?
User avatar

Joined: Fri Apr 24, 2009 10:21 am
Posts: 12700
Location: The Right Side of the Pennines (metaphorically & geographically)
Reply with quote
Another reason why I don't want NFC on my mobile phone or credit cards.

_________________
pcernie wrote:
'I'm going to snort this off your arse - for the benefit of government statistics, of course.'


Thu Oct 11, 2012 6:55 am
Profile WWW
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
l3v1ck wrote:
Another reason why I don't want NFC on my mobile phone or credit cards.

Yes I am not that fussed that the iPhone lacks NFC. I would need to get a Faraday caged wallet. From the Apple Keynote I think that Apple have a way around the lack of NFC that makes sense and is practical.

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Thu Oct 11, 2012 2:47 pm
Profile
I haven't seen my friends in so long
User avatar

Joined: Tue May 05, 2009 3:29 pm
Posts: 7173
Reply with quote
l3v1ck wrote:
Another reason why I don't want NFC on my mobile phone or credit cards.

You can turn NFC off on your phone.

_________________
timark_uk wrote:
That's your problem. You need Linux. That'll fix all your problems.
Mark


Thu Oct 11, 2012 10:10 pm
Profile
Display posts from previous:  Sort by  
Reply to topic   [ 7 posts ] 

Who is online

Users browsing this forum: No registered users and 7 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.