Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

why? isn't getting the number from the website the right action? you can verify that you have the bank website, get the right number, and i presume even go to the bank branch to get the number in person, and then save the number as it should not change.

or are you referring to the call itself? i wonder why they need to do that.



It is the right action, and they should say exactly that when they call: we need to talk to you so call us at the number in our website.

Instead they try to do the wrong unsafe thing, but when pointed out they switch the script. So they can't even claim ignorance of basic security .




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: