funsec mailing list archives

Re: RE: bankone/chase non-scam


From: der Mouse <mouse () rodents montreal qc ca>
Date: Wed, 29 Nov 2006 20:15:35 -0500 (EST)

Of course [online banking] helps banks, but it also helps customers a
lot.  I can pay bills much more cheaply and efficiently because of
online banking.

But at significantly higher risk.

Convenience and security are almost always at odds with one another.

I don't need to get and save paper statements and cancelled checks; I
can see them online.

...until there is a disagreement between what you did and what the bank
says you did, and you find that the paper trail that could have allowed
sorting it out has been destroyed.

There's a reason I require a paper audit trail for my banking - for
example, I tell my bank to send my cancelled cheques back to me.  (Yes,
paper can be forged.  The legal system is mostly pretty good at dealing
with that.  It is far less good at dealing with the digital analog
thereof.  And my bank - which I have no reason to think is atypical in
this regard - has done a number of things which to me bespeak an
outright reckless attitude towards their customer's online security,
making me even less willing to trust them online.)

Whenever anyone asks me about online banking, I tell them I won't go
near it because I know too much about the underlying technology.

Online banking is highly advantageous for customers.

But (comparatively) highly risky.

To cite one simple example, look at phishing losses.  I am 100%
phish-proof, because I *never* do any banking digitally.  Not even
*non*-fake emails and webpages get anything from me.

Naturally, not everyone makes this risk/benefit tradeoff the way I do.
Not that there's anything wrong with that; I'm just pointing out that
it's not as one-sided a balance as you make it sound.

/~\ The ASCII                           der Mouse
\ / Ribbon Campaign
 X  Against HTML               mouse () rodents montreal qc ca
/ \ Email!           7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: