Hacker News new | ask | show | jobs
by joosters 2488 days ago
I had that same issue with Amex, they phoned, said there was a concern with my card and then wanted me to go through identity checks before saying more. They also got quite stroppy when I refused and asked them to prove their own identity first!

Eventually they did suggest I call the number on the back of my card, but I was annoyed by their lack of professionalism by this point (I mean, they are asking me to do stuff - giving out information to unknown callers - which they themselves always tell customers never to do!) I said I wasn't going to phone a general number and get stuck on hold for hours over an unknown issue - either give me some reference to get through quickly to the right person, tell me what the problem is now, or send me a letter. But they kept claiming that they couldn't send out letters in the post :-(

In the end, I finally received a letter by mail telling me that there were problems with my direct debit payments. So it was a genuine call but their inability to securely make these calls is frustrating.

2 comments

I think if they gave you a number to bypass the general queue that you’re still vulnerable to an attack, right?

The only way to ensure you’re calling amex is to call the number you know, otherwise the scammer will have you call another one.

Call the number of the back of the card - "Press X if you have been given a code by us". Effectively, you're calling <number on the back of the code> + <reference to queue skip>.
It would be reasonably trivial to build a phone system that lets the agent generate a OTP of sorts.

"Hey, we need to talk about your account. Call our general enquiries number on our website, press 9 and enter 'XXXXXX' to be reconnected to me."

I was just thinking about how the agent could generate ephemeral PBX extensions. OTP-like would definitely be the way to go.

Edit: perhaps the extension would be per transaction, not per-agent, and when the customer calls the extension, the agents system can automatically pull up the customer’s account. These extensions should expire, but given the length of some customer calls, and how often I’ve been disconnected from customer service lately, perhaps it should be on the order of hours, not minutes or seconds

Not a different number to call, but instead a shortcut through the usual automated phone menus - e.g. I've had a bank tell me to phone their number and then enter an extension to take me straight through to the right person.
Just ask for an extension to reach them at when you call their public number.
Why would a letter be genuine? That seems easier to spoof then phone or email?
Cost.

Email is pennies per thousands.

Phone calls are cheap especially for nonconnected or robocalls (which would cost for a postal contact).

Postal mail costs $0.50 US in postage alone. The full-up cost of a mail campaign is often several dollars per mailed item, though in bulk, and with bulk rate, I believe it's closer to $0.40 (postage plus a few cents for paper and envelope).

That would cover many thousands of email contacts, possibly nearly as many phone/VOIP attempts.

And the systems required to successfully and accurately generate a postal response on request are also high.

Low-cost systems are high-fraud systems.

Not sure if it’s true, but I’ve heard that mail (at least in the US) is safer because the cost to send letters is high enough to deter bulk sends vs email/phone, that postal inspectors are relatively effective at catching people, and that the laws around mail fraud make prosecutions easier.
I got a scam letter from someone claiming to be Canada Revenue Agency, so I wouldn't bank on that either.
It might not be genuine. But what one should do to resolve the problem described in the letter is to go to the regular amex website, log in, and update your debit information.
My preference is to have multiple points of contact. Email+phone and the alert is sent simultaneously both ways. This happened recently when a purchase I made was flagged. I got a text asking to approve the charge. Not trusting SMS I checked my email and saw the same message as the text and a link to take further action.

I was disappointed that no alert was sent through the banking app. That would be the most secure option but is explicitly disallowed in the notification settings.

It's not so much that the letter is guaranteed to be genuine.

They can include information in the letter they can't include on a phone call, as the mail service is performing the authentication.

My health insurer won't talk to me on the phone without me confirming identity, even if they called me, but they'll happily mail the info.

Never call the number off the letter, though.