GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Aral Balkan (aral@mastodon.ar.al)'s status on Sunday, 07-Jan-2024 02:33:27 JST Aral Balkan Aral Balkan

    So somehow, I apparently mixed up #IBAN numbers and ended up setting up two direct debits in my ex-landlord’s account instead of my own, which leads me to the question: How the heck does that pass even the most basic security checks? Do they not even check that the name on the account matches the one provided? (I managed to get my name right, at least.) Otherwise, it basically means anyone can set up a direct debit for anyone else if they know their IBAN, which is absolutely bonkers.

    #ireland

    In conversation Sunday, 07-Jan-2024 02:33:27 JST from mastodon.ar.al permalink
    • Embed this notice
      SkyNebula (skynebula@mastodon.social)'s status on Sunday, 07-Jan-2024 02:37:40 JST SkyNebula SkyNebula
      in reply to

      @aral Yup, that's a huge security flaw!... 🤦♂️

      In conversation Sunday, 07-Jan-2024 02:37:40 JST permalink
    • Embed this notice
      Aral Balkan (aral@mastodon.ar.al)'s status on Sunday, 07-Jan-2024 02:37:40 JST Aral Balkan Aral Balkan
      in reply to
      • SkyNebula

      @skynebula I mean thank fuck we have a good relationship but bloody hell… It definitely shouldn’t be that easy.

      In conversation Sunday, 07-Jan-2024 02:37:40 JST permalink
    • Embed this notice
      Ahmet Alphan Sabancı (ahmetasabanci@mastodon.social)'s status on Sunday, 07-Jan-2024 02:54:46 JST Ahmet Alphan Sabancı Ahmet Alphan Sabancı
      in reply to

      @aral on my bank app in Turkey, if I don’t have the IBAN saved it always makes me write the full name of the account holder and shows me the first letters to control before sending any money. I don’t know if it allows the transfer if the name is wrong but I always assumed that’s the case because my bank even personally called me one time because someone sent money to my wrong currency account to verify.

      In conversation Sunday, 07-Jan-2024 02:54:46 JST permalink
    • Embed this notice
      Aral Balkan (aral@mastodon.ar.al)'s status on Sunday, 07-Jan-2024 02:54:46 JST Aral Balkan Aral Balkan
      in reply to
      • Ahmet Alphan Sabancı

      @ahmetasabanci Well, sending money is one thing but with a direct debit you’re authorising a third party to *withdraw* money from that account so it’s even worse.

      In conversation Sunday, 07-Jan-2024 02:54:46 JST permalink
    • Embed this notice
      Aral Balkan (aral@mastodon.ar.al)'s status on Sunday, 07-Jan-2024 02:56:13 JST Aral Balkan Aral Balkan
      in reply to
      • Darryl Wright

      @punkscience_ns And that’s the problem: a direct debit is authorisation for a third-party to withdraw from someone’s bank account.

      In conversation Sunday, 07-Jan-2024 02:56:13 JST permalink
    • Embed this notice
      Darryl Wright (punkscience_ns@me.dm)'s status on Sunday, 07-Jan-2024 02:56:14 JST Darryl Wright Darryl Wright
      in reply to

      @aral I'm actually not sure it's a security flaw. Here in Canada you can walk into a bank and -- given the account holders information -- deposit money into anyone else's account freely. It would be a security flaw if you were trying to withdraw, of course.
      But giving/gifting/depositing money kind of should be an open thing if you think about it.

      In conversation Sunday, 07-Jan-2024 02:56:14 JST permalink
    • Embed this notice
      Aral Balkan (aral@mastodon.ar.al)'s status on Sunday, 07-Jan-2024 02:57:02 JST Aral Balkan Aral Balkan
      in reply to
      • Display Name

      @alper Yep, they took payment from that account which is what alerted my ex-landlord, which is what alerted me.

      In conversation Sunday, 07-Jan-2024 02:57:02 JST permalink
    • Embed this notice
      Display Name (alper@sfba.social)'s status on Sunday, 07-Jan-2024 02:57:03 JST Display Name Display Name
      in reply to

      @aral but did the transfer happen? I think that's when the system should flag it for human check, not when you enter as a setting up step.

      In conversation Sunday, 07-Jan-2024 02:57:03 JST permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.