On mySimon: Backpacker Magazine Award Winners
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 9 of 127:
Next »
« Previous
Some Banks make it easier.
Key Bank visa security hole. 08/01/05

Some banks make it easy, they have flaws in their own software.

I believe I have found a serious security problem with Key Bank Visa where customer information
is given out with only the account number.

I called Key Bank Visa to make some changes to my account,I dialed 1=800-444-4539, I didn't want
to go through all the automated nonsense so I keyed 0 the machine asked me to either key-in or
say my account number so I said my account number and was surprised when it told me my balance,
credit limit and the maximum amount of cash I could draw. All of this with only my account
number. When I complained that this had happened they put me through to the fraud department
where I explained again what had happened and they told me that is what it was supposed to do, I
Challenged them on this saying that everywhere I use the card has my name and card number and
could call and get the same information, they still didn't think this was a problem. This is in
fact a disclosure of personal information which would be useful for an identity thief or any
other fraud.

It may well be that the automated system of Keybank Visa company may also use caller ID as part
of it's authentication process, however it has been demonstrated that it is possible to easily
spoof caller ID to give any number you wish. As many places where purchases are made also gather
your address and or phone number they have all the information needed to access your account.

Although they said they would pass it onto the relevant department, I some how doubt that
anything will be done. I think all Key Bank Visa users and maybe the other banks that are
serviced through this service company should also know of the risks.

I have now closed my account I do not wish to take that much of a risk.
Posted by: Gravitas@...   Posted on: 08/08/05 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Might as well get it over with.....  Code Poet | 08/08/05
You mean Unix is the Light and the Way  BXLE | 08/08/05
Might as well get it over with  born4fun@... | 08/08/05
Translation:  jolumoar | 08/08/05
re Translation: Revealing Insight  Urdolf | 08/08/05
Yes, it means something  lengua99 | 08/13/05
Windows is teh het  jwbales@... | 08/09/05
Windows  Apple ipod | 05/28/07
Some Banks make it easier.  Gravitas@... | 08/08/05
Why would you trust your money to a BANK  IceTheNet@... | 08/08/05
Cool...  ArtMac | 08/08/05
Cool ...  davedufour | 08/08/05
Couldn't agree more  mactolinux | 08/08/05
Catagorical Statement?  Ken E | 08/08/05
well, well  mactolinux | 08/09/05
Trust your money to a bank????  Nan1204 | 08/08/05
He keeps all of his money in his piggybank  toadlife | 08/09/05
saving up for a piggybank  linuxoverwindows | 08/11/05
trust your bank  Apple ipod | 05/28/07
BALONEY dood!  DarbyOhara | 08/09/05
And your alternative is what?  vinnie327 | 08/09/05
We all end up paying...!  hoate2001@... | 08/08/05
Although it seems like an issue  IT Scion | 08/08/05
Calm down, nothing sinister occurred...  mlynch1234 | 08/09/05
You can spoof caller ID  Gravitas@... | 08/10/05
My bank takes no responsibility!  yzergirl@... | 08/09/05
Banks Must Pay  Gravitas@... | 08/10/05
personal data problem  G Fedorchuk | 08/21/05
FYI - Firefox need I say more  IceTheNet@... | 08/08/05
Fireflop  benf_z | 08/08/05
pdf files and FireFlop  netminder | 08/08/05
problem is web designing for IE  zzpear | 08/08/05
PDF's?  HiRezL | 08/09/05
yeah -  ArtMac | 08/08/05
MY BANK ONLY ALLOWS IE  daver_z | 08/08/05
Time to change banks  gypkap@... | 08/08/05
Are You Sure????  EBathory | 08/09/05
Not true  tcavadias ZDNet Moderator | 08/09/05
You are correct - they fixed it  daver_z | 08/10/05
At least one works happy  tcavadias ZDNet Moderator | 08/12/05
Aren't you due back at your IRC channel?  toadlife | 08/08/05
my thoughts exactly.  OliverSeal | 08/09/05
something secure  Apple ipod | 05/28/07
Fireflocks is the hero!  blacksheepxlch1 | 08/10/05
i would trust it with my daughter...  linuxoverwindows | 08/11/05
TIME FOR CLASS ACTION SUIT  RobertoSalazar | 08/12/05
hmmm...  Krazyken39 | 08/12/05
Expose the Culprits & Ban the Registrars  lodaver | 08/08/05
...and Expose The Banks  hapaki1 | 08/08/05
post your experiences  Gravitas@... | 08/08/05
Happened to me  EBathory | 08/09/05
Additionally!!!!  DarbyOhara | 08/09/05
hundreds of thou$ands are at stake...  ArtMac | 08/08/05
Could Someone Explain the DriveBy Downloading and Installing Mechanism?  PMC-CON | 08/08/05
Is this a for real question?  ArtMac | 08/08/05
Umm, Still An Urban Legend ...  PMC-CON | 08/09/05
You are very wrong...  BitTwiddler | 08/09/05
yep  toadlife | 08/10/05
And once again...  ArtMac | 08/08/05
..and Deposit Slips.  hapaki1 | 08/08/05
Like we didn't see this comming  Crestview | 08/08/05
I'm with you on this  hoate2001@... | 08/08/05
throwing the baby out with the bath water  dlyne | 08/09/05
crimanals are rampent  Apple ipod | 05/28/07
ID Theft  mcp111 | 08/08/05
new doorway into our hard drives...  tonydi | 08/08/05
The US Government is keylogging too.  Heebie | 08/08/05
Governmental Keylogging - Absolutely  NightLife6 | 08/08/05
RE: Governmental Keylogging - Absolutely  HiBeamR_z | 08/08/05
Look, you can't trust anyone these days...  Allstar_z | 08/08/05
Not quite true...  hoate2001@... | 08/08/05
U been had by a Hoax  Squawkbox | 08/08/05
Pop up  G Fedorchuk | 08/21/05
ROFL!  Chad_z | 08/09/05
Dell Keylogger hoax  HiRezL | 08/09/05
What is sad  Squawkbox | 08/09/05
And what is ironic...  toadlife | 08/10/05
Already done by Microsoft  kokuryu | 08/09/05
DLL file  reznik | 08/12/05
Hmmmmmmmm..........  cpritch007@... | 08/08/05
ID theft  lynner55@... | 08/08/05
ID Theft & Data Privacy - An American Problem  NightLife6 | 08/08/05
Yes.  OliverSeal | 08/09/05
Re keylogger on computers.  dmumby1967 | 08/08/05
What is the platform that ALLOWS all the creeps to install all kinds of  michael_t | 08/08/05
Oh yes....  WillemGrooters | 08/09/05
easy to install  Apple ipod | 05/28/07
OS-makers should be made responsible  witan | 08/08/05
Why?  blacksheepxlch1 | 08/10/05
OS-makers should be made responsible  witan | 08/08/05
Users have their's as well  WillemGrooters | 08/09/05
PNC Bank clients are especially vulnerable  daver_z | 08/08/05
PNC Bank  RonsMail4U@... | 08/09/05
Spybot is one of the Best!  MojoKiller | 08/08/05
********  WillemGrooters | 08/09/05
Try COUNTERSPY  kokuryu | 08/09/05
Silence from Loverock  jasonp@... | 08/08/05
Maybe because he was the guy in this story  Squawkbox | 08/08/05
Damn, Squawky, I've heard of  Real World | 08/09/05
With "friends" like that, I'll take my enemies  Squawkbox | 08/09/05
Nope, wrong state  Loverock Davidson | 08/09/05
You are a good sport Loverock  Squawkbox | 08/09/05
Ditto (NT)  Loverock Davidson | 08/09/05
LOOK EVERYONE!!! HE MENTIONS ME!!!  Loverock Davidson | 08/09/05
malicious code/pornware  tonydi | 08/09/05
Message has been deleted.  An_Axe_to_Grind | 08/09/05
I'll bite whatcha got?  Squawkbox | 08/09/05
personal attacks  Apple ipod | 05/28/07
this writer assumes three things that are not covered in questions to the  wessonjoe | 08/09/05
Spyware Rocks !!!  GeoMartinez | 08/09/05
title shoule read "FBI stakes out ID theft file and lets bank accounts get  wessonjoe | 08/09/05
Noticed that too did ya?  Squawkbox | 08/09/05
All you people got it wrong...  avatar_z | 08/09/05
Time for Retaliation Software!  the_webninja@... | 08/10/05
What will every happen to the id theft rings, the spammers and virus makers  FilledOut | 08/10/05
Sent to Porno Site Unsuspected  mrscc3201 | 08/10/05
Save your self  ctuteur | 08/10/05
I sometimes have to open IE!!  dbrimlow | 08/10/05
Who A R E the 50 banks? Does Anyone Know???  mclehr@... | 08/10/05
Spyware  jess81452 | 08/10/05
And What Banks are These?  caeciszek | 08/10/05
50 banks huh???  jan5055@... | 08/10/05
ID Theft Protection, harmful computer access, & Law  Transaction7 | 08/12/05
private data  Apple ipod | 05/28/07
ID thefts  daisie26 | 08/14/05
Uhh why won't the article post the offending websites addy?  Mike2575 | 09/06/05
AHEM!  EBathory | 09/07/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

SmartPlanet

Click Here