Hacker News new | ask | show | jobs
by Ensorceled 2488 days ago
My bank always says "There is an issue with your credit card/account, please call the number on the back of the card/your branch as soon as possible." and has for years.

The only time they do otherwise is on very specific instances where they provide the info, "did you just buy something at store XXX for approximately $YYY"

All banks and credit institutions should be required by law to do this.

2 comments

Capital One has an app, every time my card is used I get a push notification. This is the best solution in my mind. I can actively monitor my card usage and call if I see something suspicious.
I'm surprised that this isn't a requirement for banks considering the very large number of scams going on in the US.

In India, getting an SMS/Email confirming every card usage is a legal requirement imposed by the Rserve Bank of India. The same goes for card usage itself. All credit and debit card POS transactions need the card PIN to be approved. Likewise, all online transactions require MFA.

AMEX does this and it's honestly great. Unfortunately my credit union doesn't, but I use credit for most transactions anyway.
chase does this too.

applepay, for all my cards, gives me an immediate push notification, despite some cards not doing so for regular chip/swipe transactions. really like that feature & also wish all cards did it for all transactions.

My AmEx does that too. I really like that feature.
I wish all banks and CCs offered this feature.
It's worth searching on their site / calling them, since in my experience every time over the last couple years I have dug, I have found it offered.
My bank does this. Two texts:

1: "We need you to verify some transactions. You will receive a text from <number> with the transaction details"

2: "Do you recognise these transactions? <date/store/amount x 3> Reply Y if yes, N if no"

Y -> "Thank you for verifying the transactions. If any transactions have been declined, you may been to repeat them"

N -> "Your card has been blocked and a new one ordered. Please contact us if you need any further advice"

These are what I usually see, or else an automated call with the same approximate script. Is there anything insecure about doing this one? The only thing I can think of is a MiTM where your account credentials are already compromised and they are using your answers to reset your password.
These fraud alert calls (in my experience of course) generally don't have any ID verification so there's no real danger from the user side in interacting with them. They just ask do you recognize these charges and that's it and then initiate any fraud response. From the bank side the worst is if the number has been hijacked but the user would still be able to dispute the charges later through the normal means but CC cloners probably rarely do that so it's not a huge issue.