• MrEff@lemmy.world
    link
    fedilink
    arrow-up
    13
    arrow-down
    1
    ·
    edit-2
    14 hours ago

    This is actually a really common thing for banks to do for fraud security. It works better than just freezing the account because if someone is using a stolen identity they can still go in person and fake their way around a frozen account. But if the security team deducts $100 billion dollars, then you can’t take anything out and it essentially warns anyone who works in banking who isn’t directly in your bank (3rd party bank) about what is happening to the account.

    • TessaRekt@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      12
      ·
      edit-2
      13 hours ago

      If you can talk your way out of it in person the account isn’t frozen, at most it is flagged as potential fraud. Most bank fraud departments have first line fraud detection analysts in a call center where if the system detects fraud that department are the only ones who can remove the account freeze and if they get even a whiff of suspicion from a “customer” calling in to get the freeze removed it gets pushed up the line to specialists whose whole job is to do deep investigations into accounts to catch potential fraudsters. The first line might have you get in person to a branch for ID verification but the fraud department are usually still the ones who have to manually remove the freeze once it hits the work queue.

      Putting an account negative like that on purpose is an easy ticket to the bank being audited. Hell doing it on accident would probably get the bank audited.

      Source: worked as a fraud detection analyst for a major bank

    • nomad@infosec.pub
      link
      fedilink
      arrow-up
      8
      arrow-down
      1
      ·
      13 hours ago

      I have been working in software for quite a while and one thing has remained constant over the years: users will find to exploit any feature in a way it was not intended to if it suits their needs.

      We usually fix that shit by adding another field for remarks or maybe adding a flag that allows to tell anybody not to touch that even with a ten foot pole…

      That there haven’t done that and instead something like this is common in banking, not just at one bank, is a dead giveaway on the state of the software banks are using.

      There is usually a reason why they refuse to touch anything. In banking software is old… As in older than me. My dad used to build this software when he was in his prime which was about 60 years ago. It hasn’t changed since then…

      • n7gifmdn@lemmy.ca
        link
        fedilink
        English
        arrow-up
        6
        ·
        13 hours ago

        Yeah it did, the used to use two digits for the year, than they had to change it because people’s credit cards were being denied for expiring in 2000

      • halcyoncmdr@piefed.social
        link
        fedilink
        English
        arrow-up
        4
        ·
        12 hours ago

        Don’t discount the chance that implementing a better solution could be functionally impossible.

        Chase still has their systems running through a COBOL mainframe after all.