Yes, that's one of the cases that led me to this theory.
Not only have they been baffled, but even after I've explained why I want them to do this, they don't seem to understand why it's important.
In fairness, I do think the bank ought to have thought this through and introduced a stage where they verify their identity, or at least included an extra bit of script in case the user asks for it. By the time I've answered the phone they've already got one-factor security ("something I have") on who I am, so a sensible policy would encourage people like me to demand something from them before I hand over information.
The best come-back I heard (from someone asking for my DOB and mother's maiden name) when I asked that they verify their ID first was "but I only want your DOB and mother's maiden name, anyone can get hold of those". Er... yes, they can. So why are you using them for your security checks?
no subject
Date: 2010-03-31 11:48 am (UTC)Not only have they been baffled, but even after I've explained why I want them to do this, they don't seem to understand why it's important.
In fairness, I do think the bank ought to have thought this through and introduced a stage where they verify their identity, or at least included an extra bit of script in case the user asks for it. By the time I've answered the phone they've already got one-factor security ("something I have") on who I am, so a sensible policy would encourage people like me to demand something from them before I hand over information.
The best come-back I heard (from someone asking for my DOB and mother's maiden name) when I asked that they verify their ID first was "but I only want your DOB and mother's maiden name, anyone can get hold of those". Er... yes, they can. So why are you using them for your security checks?
no subject