Bank scammers using genuine push notifications to trick their victims


`In app popup. "Are you on the phone with Chase? We need to check it's you on the phone to us. Let us know it's you and enter your passcode on the next screen. @ Not you? Your details are safe. Just tap 'No, it's not me' and we'll end the call."`

You receive a call on your phone. The polite call centre worker on the line asks for you by name, and gives the name of your bank. They say they're calling from your bank's fraud department. "Yeah, right!" You think. Obvious scam, isn't it? You tell the caller to do unmentionable things to a goat. They sigh. "I can assure you I'm calling from Chase bank. I understand you're sceptical. I'll send a push notification through the app so you can see this is a genuine call." Your phone buzzes.…

Continue reading →

People Don't Want To Run Their Own Bank


Photos of some porcelain piggy banks in the shape of pigs in clothes. Photo taken by William Warby.

When I was young, I had a piggy bank. A piggy bank is incredibly secure. It's fairly big - so it is hard to lose. It is brightly coloured - so you can find it easily. No one else can see how much money there is in there. The only way to get money out is to smash it - providing visible evidence if someone has robbed you. And smashing makes a noise - deterring would-be thieves. A piggy bank is close to perfect security. If you are seven and your adversary is a younger sibling. Storing your own …

Continue reading →

The 74,000 numbers of Barclays Bank


Long list of phone numbers in JSON format.

The UK faces an epidemic of telephone scams. Fraudsters are constantly calling people up pretending to be their bank. But how can you be sure the number displayed on your screen in genuine? You can't. The telecom system is hopelessly insecure and shouldn't be trusted for anything more complicated than dialling the speaking clock. Barclays bank knows that customers are worried about this. So they've produced a handy website where you can see if a telephone number belongs to Barclays. Because…

Continue reading →

Passive Aggressive Trolling Co-Op Business Banking


Having recently moved house, I have become very aware of which companies have modern back end systems. The most top-notch ones let me log on to their website, fill in a form, and all the address changes are made. A few required me to ring up and speak to a human being, which was a little annoying, but not the end of the world. Only one company insisted that I write them a letter. Co-Op Business Banking. Despite having a moderately competent website, they couldn't process a change of…

Continue reading →

RBS Treat QR Codes Like They Treat Our Cash


Oh RBS! Is there anything you touch that doesn't turn to shit? You take our money, lose it, then pay it out to yourself. Still, at least your latest advert contains a QR code. Bet you haven't managed to screw that up. Oh... On the back page of the 25 February 2011 edition of the City AM newspaper, is this lovely specimen. Thankfully, City AM have placed their paper under CC BY NC. Let's take a zoom in on the code and the instructions that accompany it. You Know What's Coming Next,…

Continue reading →