Hacker News new | ask | show | jobs
by smsm42 4711 days ago
Security by obscurity means hiding the algorithms, not the keys. In this example account numbers, etc. are the keys

Unfortunately, it is how most of the banking world right now works. It is quite easy to initiate transactions and create accounts knowing a few basic numbers about you - bank account numbers, name, date of birth, SSN number (I'm talking about the US of course), home address. And it is very hard to change or hide many of these numbers and data items. The system is very fragile right now, and the only reason why it works is that overwhelming majority of users aren't crooks and losses from the crooks are small enough to be covered without triggering move to a more resilient system.