Hacker News new | ask | show | jobs
by kevinpet 810 days ago
It would be better if banks educated customers on best practices such as "don't trust anything on a different domain" and "only provide PII for verification if you are the one initiating the call". Of course, both of those would require that banks stopped engaging in those two practices which make legitimate interactions indistinguishable from phishing.
1 comments

> don't trust anything on a different domain

Then you receive an email from your "securebank.com"

from: "securebank-communications.com"

title: "Beware of fraudsters sending emails and text messages"

body: "Tap here to install our latest secure mobile app"