LWN: Comments on "Full disclosure and the banking industry"
http://lwn.net/Articles/23687/
This is a special feed containing comments posted
to the individual LWN article titled "Full disclosure and the banking industry".
hourly2Full disclosure and the banking industry
http://lwn.net/Articles/24457/rss
2003-03-05T18:58:23+00:00sethml
In '96 I had an account at a semi-local bank in Santa Barbara CA (I don't remember the name of the bank, but I think they had half a dozen branches total). One day when withdrawing money with my ATM card I noticed that the balance seemed low, and decided to check my records when I got home. When I got back to my office, a person from the bank called, explaining the situation. Apparently the bank had a policy that account numbers couldn't be reused for at least 5 years, but when my account was created they accidently violated that rule and gave me the account number of somebody who had died (and had his account closed) recently. A while later his daughter found his checkbook, went to her local branch (different from mine), and asked to have herself added to the account. They happily added her to my account, even though they presumably noticed that my name and address weren't even remotely similar to the ones on his checks. She promptly started spending money from the account, so that it went from ~$1500 to a few hundred over a few days.<p>Anyhow, the bank had just figured out their mistake (before I did). They created a new account for me and deposited my former balance into it, and took the hit for the mistake themselves. I was impressed with their incompetence, but also impressed with their customer service. I received two statements for that month; the one for the old account included a few dozen slips that said "we have lost this check in processing" - one for each of the checks the woman had written.<p>Fast-forward to a year later. Six months before I'd closed the new account. Out of the blue I got an envelope with the last statement from my old account, and the dozens of checks that the woman had written on my account - including her address, phone number, and signature. Then I got a notice that my account (the old one!) was $500 overdrawn and would I please pay up. I called their rep and explained the whole situation, and he couldn't find any reference to it! But I eventually convinced him, and I never heard from them again.<p>The moral: banks are astonishingly incompetent. And by and large the individuals working at banks are nice people and want to help you, and often don't let litte things like other people's privacy and accounts get in the way.
Failure of bank's proof
http://lwn.net/Articles/24055/rss
2003-02-28T17:18:08+00:00Max.Hyre
<p>Even when the bank has the burden of proof, things are not so rosy
for the victim^U customer.
<p>Some years ago (a decade and a half, more or less?) a bank had a
thief dead to rights---including the photo from the surveillance
camera. Problem? The guy in the photo was innocent. It seems
whoever set the timestamp on the camera blew it, and even though the
fraud occurred at (say) 9:27, the frame stamped `9:27' had been
taken at an entirely different time. I'll leave it to the reader
to envision what the poor guy went through to disprove the `proof'.
<p>I almost certainly saw this in the <a
href="http://catless.ncl.ac.uk/Risks">Forum On Risks To The Public In
Computers And Related Systems</a> mailing list
(a sobering read if ever there was one), but I just as
certainly can't find the combination of search words which will
extract it from their archives.
Full disclosure and the banking industry: Burden of proof must be on bank
http://lwn.net/Articles/24015/rss
2003-02-28T10:26:49+00:00beejaybee
Sorry but the problem is that the PIN system is _technically_ broken. It simply doesn't matter what administrative safeguards are in place (though I accept that it is probably easier to get a bank to own up to a mistake, either honest or fradulent, in the US than it is in the UK).<p>In fact the situation is even worse than the decimalization table exploit that was the result of the Citibank gagging order. Jolyon Clulow, a graduate student at the University of Natal in South Africa, has published his thesis containing _no less than six_ discrete attacks which could obtain authorization information which could then be used to fraudulently obtain cash. The decimalization table exploit is but one of these. The paper has been replicated to help prevent overload or closure of the student's web site. There are probably enough other copies around already to make it quite certain that stuffing the cat back into the bag isn't going to be possible.<p>Whole paper: http://home.icon.co.za/~clulow/dissertation.pdf<br>http://www.cl.cam.ac.uk/~mkb23/research/Clulow-Dissertation.pdf<p>Chapter 3 only (this is the strictly relevant stuff)<br>http://www.cl.cam.ac.uk/_mkb23/research/Clulow-Chap3.pdf<p>With acknowledgements to the ukcrypto list, from where I obtained this information.
Phantom withdrawals not a risk to account holder
http://lwn.net/Articles/23960/rss
2003-02-27T18:02:38+00:00giraffedata
>All in all, it doesn't leave me wondering about whether (most) banks <br>>really are concerned about their customers (they are not), <p>Banks are obviously concerned about their customers. Without reasonably satisfied customers, they wouldn't be in business.<p>Just as obviously, the concern for customers stops where it costs money. Screwing some customers may be what is necessary to satisfy a lot of others (with e.g. low prices) and make a profit.<p>>they have to go to an actual teller now and sign a form<p>I would think a better course of action would be to switch banks. There's a good chance another bank has a more secure system or a more friendly policy. By making it free to the offending bank to operate like that, he his shirking his duty as a consumer in a capitalist society.<p><br>>Has anyone ever made positive experiences with his bank when it came to <br>>things like this?<p>I have a friend with an account at a large US bank that had a series of phantom withdrawals about two years ago. The bank reimbursed him for all of them, but closed the account and made him open a new one. The bank apologized for the inconvenience. My friend has no idea how this theft happened, but I know him well enough to know that there is virtually no chance he let someone find out his PIN.<p>Also, I think the bank noticed the problem before my friend did, based on the unusual pattern of withdrawals.<br>
Full disclosure and the banking industry: Burden of proof must be on bank
http://lwn.net/Articles/23946/rss
2003-02-27T16:59:18+00:00Baylink
A very well taken observation. I had a related problem many years ago with a videotape rental house and a collection agency: when I pointed out to the credit people that the rental house had no procedure for checking tapes *in* reliably... they stood down on their own.<p>Note: the common derivation of ATM (at least amongst us USAdians) is "Automat{ed,ic} Teller Machine".
Full disclosure and the banking industry: Burden of proof must be on bank
http://lwn.net/Articles/23922/rss
2003-02-27T14:30:42+00:00dwheeler
This is a case where the basic laws have critical consequences.
In particular, in this case the U.S. system is sensible, and the U.K.
system is completely broken.
<p>
The fundamental problem is that in the U.K. the burden of proof
is in the wrong place.
In the U.S., if there is a "phantom withdrawal", the <i>bank</i>
has the burden of proving that it was the customer.
This is reasonable, because the bank controls its facilities and can
arrange its processes to acquire that evidence.
Thus, for example, bank automated telemarketers (ATMs) have video
cameras installed in them, so that the bank can show who was at a given
ATM at any time. Banks can also arrange for all sorts of
internal checks and balances, reviews, and evidence collection
so that they can provide evidence to law enforcement.
<p>
In the U.K., the burden of proof is on the customer.
But the customer has no way to provide useful evidence;
they cannot spend their lives honing evidence collection techniques!
Since the banks have little financial risk from fraud, they have
no incentive to actually make their systems secure.
<p>
Thus, if you want banks to be secure, you need to make them
financially at risk to be secure.
U.S. banks aren't perfect, but I think the U.S. banks are far more
secure than the U.K. banks... because the burden of proof
is in the right place.
Full disclosure and the banking industry
http://lwn.net/Articles/23897/rss
2003-02-27T10:51:41+00:00arcticwolf
That's interesting, and it may well explain the phantom withdrawals a friend of mine has been seeing to his account. They have happened again and again over the years, and, of course, his bank was not helpful in the slightest - rather, they, too, showed a hostile attitude and less-than-politely informed him that it must have been him or his wive who had made those withdrawals.<p>These days, his wive and he have decided to disable electronic cash for their accoount - when they want to withdraw money, they have to go to an actual teller now and sign a form. It works, but it's quite a hassle, of course, and one wonders how long the bank will still offer the choice to not use ATMs, too.<p>All in all, it doesn't leave me wondering about whether (most) banks really are concerned about their customers (they are not), but it makes me wonder whether there isn't an exception to the rule. Has anyone ever made positive experiences with his bank when it came to things like this?<br>
Wrong link to Matt Blaze's paper
http://lwn.net/Articles/23894/rss
2003-02-27T10:02:52+00:00mmutz
<p>I guess you meant <a
href="http://www.crypto.com/masterkey.html">http://www.crypto.com/masterkey.html</a>
instead of the 1996 paper</p>