Page 2 of 3

Re: Banking in Australia

Posted: Thu Jan 06, 2011 8:49 am
by vv85
Oldrac the Chitinous wrote:Yeah, those things don't really do "forward" so much.
must just be my bad hip...

Re: Banking in Australia

Posted: Thu Jan 06, 2011 8:53 am
by Oldrac the Chitinous
Does it detach from the rest of your body?

Re: Banking in Australia

Posted: Thu Jan 06, 2011 9:24 am
by vv85
Pops in and out like a boxed kitten on catnip

Re: Banking in Australia

Posted: Thu Jan 06, 2011 9:25 pm
by Lethal Interjection
Do they make the same *clack* sound?
Do they swing independently of eachother?

Re: Banking in Australia

Posted: Thu Jan 20, 2011 4:32 pm
by Astrogirl
'nother question: When you make a transfer, do you use a TAN for verification? I.e. you type in transfer 12 dollar from my account to account 123 at bank X, and the web interface says: Please enter TAN number 17, and you have a sheet of paper with some dozen 6-digit numbers and you type in the one that it asked for?

Re: Banking in Australia

Posted: Thu Jan 20, 2011 4:36 pm
by Oldrac the Chitinous
That sounds really annoying.

Re: Banking in Australia

Posted: Thu Jan 20, 2011 5:00 pm
by Astrogirl
Annoying? Safe!

Re: Banking in Australia

Posted: Thu Jan 20, 2011 11:30 pm
by Kimra
Unless someone breaks into your house and steals your piece of paper.

And no. I have no idea what this is, but it sounds annoying.

Re: Banking in Australia

Posted: Fri Jan 21, 2011 1:32 am
by Astrogirl
That person would not know the password, unless you tape it to your monitor.

So, how do you prevent "evil hackers" (password stealers) from making transfers?

Re: Banking in Australia

Posted: Fri Jan 21, 2011 2:50 am
by Sahan
I don't think there really is anything to protect you from that here, you just have to be vigilant and make sure there are no transfers on your account that you didn't authorise. If there are you have to let the bank know immediately to stop any futher transactions and then it's up to the law enforcement to track who committed the theft.

Re: Banking in Australia

Posted: Fri Jan 21, 2011 2:51 am
by Oldrac the Chitinous
I employ the strategy of not having enough money to warrant stealing.

Re: Banking in Australia

Posted: Fri Jan 21, 2011 2:59 am
by Kimra
Oldrac the Chitinous wrote:I employ the strategy of not having enough money to warrant stealing.
If they steal my debt, I will only be too happy.

Re: Banking in Australia

Posted: Fri Jan 21, 2011 12:09 pm
by Astrogirl
Sahan wrote:I don't think there really is anything to protect you from that here, you just have to be vigilant and make sure there are no transfers on your account that you didn't authorise. If there are you have to let the bank know immediately to stop any futher transactions and then it's up to the law enforcement to track who committed the theft.
Weeeiiird :shock: .

Here it was like this:
- At first there were sheets with unnumbered TANs. "Enter any unused TAN on your sheet", and then you should cross it off so you don't accidentally try to use it again. But the black-hat hackers got better. E.g. they would capture the TAN entered for a real transaction. That transaction would fail ... either they display an error message, or they manipulated it to show a fake success message. Or, more easily, they sent fake mails, seemingly coming from the bank, not only telling the customer to log in, but also to do some kind of "verification" or whatever that supposedly required a TAN. So they got at least one TAN and as much money with it as one transaction or the daily limit allowed.
- Now we have the numbered TANs. "Enter the TAN next to the number 63". So when the bad guys steal one number, they usually have to wait for a very long time until exactly this one comes up ... and the whole sheet of TANs gets invalidated after three wrong tries, so their chances are pretty slim.
- Even newer: Mobile TANs. You register a mobile phone number and get sent the TAN right when you need it. (Problem for me: I share an account with my husband and I don't want to leave my mobile phone at home when I am traveling so that my husband can make transfers. So that's why I don't use that, even though my bank is urging me to do it for higher safety.)

Re: Banking in Australia

Posted: Sat Jan 22, 2011 1:42 am
by Apocalyptus
Astrogirl wrote:That person would not know the password, unless you tape it to your monitor.

So, how do you prevent "evil hackers" (password stealers) from making transfers?
You can add the option of having a confirmation code texted to your mobile that you have to enter to complete the transfer, for accounts you have not transferred to before. Which is what I do, it's pretty convenient.

e: plus some banks in an effort to thwart keyloggers (not my bank though) have instead of text boxes to type in account number and password, a set of number buttons which you have to manually press with a mouse and which are in different positions every time. It's a pretty cool system, and I'm annoyed my bank doesn't seem to have thought of it.

Re: Banking in Australia

Posted: Sat Jan 22, 2011 2:19 am
by Astrogirl
Oh, our banks haven't thought of that.

My uncle works in software development for a bank. Recently there was a giant scam attack with a fake mail, prompting people to log into a fake website that looked like the bank's website and do something. The fake website pulled the image from the original website. The bank quickly acted and replaced the images with images that looked completely different and contained text like "DO NOT ENTER YOUR PASSWORD" and "THIS IS A SCAM" (in German). 50000 of the attacks were successful anyway! Are people braindead or what? (Not sure if these were really 50k different people or 50k transfers, but as people rarely have more than 2 accounts and one transfer is enough to steal the money, this must still have been thousands of people.)