Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Instead of giving them an advice, we who understand how it works should make these things defaults and not let them exposed. What can the users do in a world where banks are asking you to read the CC details loudly in a phone conversation and give them all the details over the phone. Next thing is that there is a fake call from a criminal organization pretending to be the bank. How would a user detect that it is fake? I think security should be about rules and enforced practices rather than advices that they can happily ignore.


> Instead of giving them an advice, we who understand how it works should make these things defaults and not let them exposed.

This is missing the point. The article states the security advice is actively harmful, in that applying it is more costly than the expected returns warrant. Just enforcing those costs on users doesn't help.


Yes I was just pointing out that not only the advice giving part is bad but also the practices that even banks follow today are harmful.


>How would a user detect that it is fake?

I use challenge response. They ask a question, you give them the wrong answer, they confirm that it's wrong. You and the banks have shared secrets.


What is to stop the bad guy from calling the bank at the same time they call you, and passing your challenge and responses on to the bank teller?


Nothing. This is a classic MITM attack. Only out of band verification or a preshared secret would prevent that.


Also, even if I did get taken by a criminal organization pretending to be the bank, I'm going to get the money back anyway once I report fraudulent charges. Not much risk on my end…




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: