▲ | jasode 5 days ago | ||||||||||||||||||||||||||||
>I’ve personally never had that happen. It should go on a name and shame list The key situation for giving out an SMS code that the gp is pointing out is the customer initiates the call to the support center. For example, suppose somebody wants to add a credit-card to their smartphone digital wallet. They have to call the bank issuing their credit-card to do that. Once the customer support person answers the call, a common security verification (e.g. Chase Bank does this) is for them to send you a 6 digit code to your phone. You then repeat this code back to the support person on the call. They want proof of your identity and also proof that you physically have the smartphone with you. Repeating the SMS code to the customer support person is safe because the customer called the official 1-800 number on the back of their card. That's a totally different sequence of steps from receiving a random call from somebody claiming they are from Chase Bank. Yes, in those cases, you never give out SMS codes to that untrusted person on the phone. | |||||||||||||||||||||||||||||
▲ | NikolaNovak 5 days ago | parent | next [-] | ||||||||||||||||||||||||||||
I agree with everything you said. Note, however, that those are two "totally different sequences of steps" to you and I, and "completely analogous / equivalent sequences of steps" to my father in law :-/ | |||||||||||||||||||||||||||||
▲ | vehementi 4 days ago | parent | prev | next [-] | ||||||||||||||||||||||||||||
Justifiable in a vacuum, but the end result is grandma knows "sometimes it's OK to give the code to the person on the phone" | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
▲ | dpifke 4 days ago | parent | prev [-] | ||||||||||||||||||||||||||||
The signin 2SV SMS verbiage used by Chase is: "Chase: DON'T share. Use code 12345678 to confirm you're signing in. We'll NEVER call to ask for this code. Call us if you didn't request it." I assume in the case where the customer initiates the call and support is verifying their identity via SMS, they use different text (i.e. not "to confirm you're signing in"). Otherwise, that'd be pretty ridiculous. | |||||||||||||||||||||||||||||
|