Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That can still be gamed by any malicious SEO wizard. People will trust the top Google hit for "bank of america phone number" before they bother with finding it on the website.


I’ve been asked to “call the number printed on the back of [my] card” which would be much harder to spoof.


Yeah, every time my credit card provider has needed to contact me, they send me an recorded message telling me to call the number on my card.


I've had different cards for 35 years at least, never got a call. What do they call about generally?


Suspicious activity. Suddenly using your card in the UK, when you're in the US. "Swipes" several hundred miles from your normal location, but also occurring in your normal location on the same day.


Ah, I never use my real card on the net, maybe that's why. I used to get a virtual card unique for every purchase but that has been discontinued now. Got a separate card for online usage that I only put money on when I want to buy something. Also needs to be opened up for Internet usage and many places require an electronic signature with the bank id app. Hoping this will be mandatory soon.


But numbers can change (lapses of mergers), is website would be best as card info can become stale over time —and enterprising outfits could scoop up that number.


> But numbers can change

They could, but I just tried calling the numbers on the back of two cards from merged/acquired banks and they both forwarded to the acquiring bank. Yes it's a small sample size, but I suspect that there's enough money on the line and enough legacy contracts and systems that banks keep their communication channels active for some time.


> But numbers can change (lapses of mergers), is website would be best as card info can become stale over time —and enterprising outfits could scoop up that number.

How long are bank cards valid? I'd say they expire within 5 years? Also, if there is a merger, wouldn't they send you a new card with updated branding?


Credit cards typically expire after some number of years, and mergers will typically include those phone numbers. If for some reason the acquiring company decides it wants to sunset its acquired phone numbers, it just needs to do so after the expiration date for the last card issued with that number still printed.


Even worse than SEO, fraudsters edited Google Maps bank information directly http://archive.vn/PPJYW


I wouldn't call it worse. Google maps entries seem to receive less scrutiny than search results, but I also suspect that nobody use as a phonebook. Most people would use google search, or the back of their card.


Google Maps is part of Google Search


How is a random fraudster going to suddenly get the top Google result for "Bank of America phone number"?

I'm sure it's possible, but it strikes me as a pretty large hurdle. And even if they manage to pull it off, they also need no one from the bank to notice and report it.


You've got it backwards.

One gets a call from the bank, they give you a number to ring, you type the number in to Google search, the results come back listing that number and the bank's name -- identity confirmed!?!

The fraudsters just need _a_ website listed by Google.

My insurer called me out of the blue: I said I'd call back. Their number was not listed on any of the companies websites. I called the company, and said what has happened, took them about 10 minutes to confirm they'd called me and that the phone number I was called on was valid.

As it happened someone was trying to commit insurance fraud, saying we'd crashed in to them; but that's by-the-by (ie not relevant to the main story).


> How is a random fraudster going to suddenly get the top Google result

They pay for it. Most people can't distinguish search ads from search results.


> They pay for it. Most people can't distinguish search ads from search results.

Would the new transparency requirement be useful to go after these fraudsters after the fact? https://news.ycombinator.com/item?id=22955606


I'm really hoping so, I specified my thoughts on that here: https://news.ycombinator.com/item?id=22955801

It depends how aggressively Google pushes on it, and how carefully they verify the actual identity of the entities putting ads up.


You don't need your site to be #1, especially if you can manipulate one that is already high-ranking-- just astroturf GetHuman with fraudulent numbers.

But I admit-- having just done a search for every institution I could think of, it seems Google AMP has done a lot to promote legitimate numbers. It used to be sites like GetHuman competing with or outranking the actual company website for contact information.


"Alexa, make me the number one search result on Google for Bank of America."

"Alexa, confirm."


Should be solvable by making sure there's an easy, reliable, uniform way to get this info within the call.

> "Hello. Please find the callback number on boa.com/contact. Please enter code XYZ to be connected directly to the agent regarding this matter. Thank you & goodbye."

It's not perfect & you'll still have some percentage of fraud that goes through, but I'd be interested to see the impact this has on fraud rates.

* EDIT: Callback number via the card as the other commentor noted probably works too.


There is a very large number of people who would not be able to do this properly and would completely bone up the process at some point.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: