Lo tech #
Posted Tuesday 30th October 2007 18:20 GMT
Clever scam (i.e they thought something up reasonably new), but why even bother faking a bill?
The guy is on holiday, you presumably know where he lives, so break into his pad, take some bills, get the bank to replace the debit card and send a new PIN, then go get them and spend his dosh.
As a consumer it's pretty much impossible to stop that type of attack short of getting a house sitter in. Which means the banks need to get their houses in order - mine asks for characters X and Y from my secret pass phrase (so even the operator only sees those 2 chars) The numbers X and Y seem to be random so you'd need to know the full phrase (or most of it) to be able to talk about the account.
If they managed to trick his pass phrase out of him then you can't blame the bank, but if the bank just let a random guy report the card lost and allowed it to be picked up from a PO then we have a serious weakness.
Poor bloke - at least they paid up.



