22 comments

[ 5.0 ms ] story [ 68.5 ms ] thread
TD Bank recently tried to sell me on how using my voice is a great way to authenticate me when I use their customer service over the phone. Seems banks are still are not getting security right.
One of my bank authenticates me whenever I call them by asking my date of birth, my id number and a simple question about how I use my account that is easily guessable and that's why I don't put a lot of money in that bank account.
Same here. In response to a question about the most recent transaction, I guessed saying "Umm I took out about 500 dollars, I think." This was good enough to authenticate.

My guess was about $400 off, so now I have $20 in that account

I called Royal Bank of Canada to update some information, at their normal phone prompt I entered my client card number as usual. After reaching an agent they automatically used my voice to authenticate me, foregoing any security questions or verbal passwords. Normally I considered RBC to be fairly reliable in that they would ask 5-6 personal questions and ask for my verbal password. It made me uneasy knowing that a scammer could call me, record our conversation, and play it back to gain access to my account.
It comes down to who gets stuck holding the bag if anything happens. As long as it is easy for them to blame you or me for being careless with our account info, they will not tighten security.
...but the customer is very rarely stuck holding the bag. If you report a transaction as fraudulent you get your money back usually within hours...not really sure what you're on about.
It's like fingerprints as a password. They are immutable so once it is out in the wild, how do you change it like a password?

You could use voice as a screening process, but not for final verification. Lots of podcasters, YouTubers and TV/Radio people would be at risk otherwise.

Why would you call your bank? I've been a customer at my bank for over 15 years now. I have never spoken to anyone, on the phone or otherwise...
One more reason why I will not answer calls from people who are not in my address book. If it's important they can leave a voicemail.
It looks like nobody has ever actually been 'scammed' by this,http://www.snopes.com/can-you-hear-me-scam/
Surely we're not still using Snopes as a source of truth?
You say that as though there were some well-known reason we should have stopped. So far as I am aware Snopes continues to be a reliable source of information about urban legends.
They've been wrong on a number facts, and have been shown to largely ignore any corrections or feedback + they've also shown a fairly clear political agenda in the last 12 months and have been creating 'facts' that simply aren't true to support that agenda.
That's a shame, but this is the first I've heard of it - can you point me toward any specifics I could read up about?
Simple way to prevent this... utilities should not allow voice authorizations for new services. Require a signed contract. They can still allow phone based signups for convenience with a contract to follow later, but let consumers cancel any service without a contract for a full retroactive refund.
I've gotten a couple of these and have always hung up. I always assumed it was just a delay tactic while you get routed to a human to talk to about whatever the spam topic of the day is.
Apple put this headline in my iPhone News App... it reads like clickbait in the hardest way.
We stopped answering the phone entirely. All calls go to voicemail, unless the caller is in our mobile phones' address books. 99% of calls are hang ups. The remaining 1% are my mother-in-law complaining that we never answer the phone (we call her back immediately ;-) )
Sort of off topic, but relevant.. my fear about iOS call blocking apps might be coming true. Now that there's TrueCaller, Mr Number, Hiya, etc, there are islands of data and I doubt that they're sharing with each other. This is just letting more and more stuff slip by.

i'm almost at the point where I wish that Apple had their own huge gargantuan database of reported spam numbers. Or that they would have licensed Oomas or nomorobo (even though they're a paid service) or something.