Bank Statements Emailed

SethGecko

Active Member
Joined
Feb 3, 2007
Messages
43
Reaction score
0
Location
Cape Town
Hi All

With the last 12 months being a busy one for internet fraudsters and identity theft, I was wondering what your feeling was about
banks emailing statements in an unsecured manner, in this case FNB for example.

I receive my credit card statement, needless to say with all my personal information, credit card account number, itemised expenditure, from which very easily "patterns" can be picked up...........and all this in an unencrypted PDF document.

Standard bank, dstv etc for example require you to install a "decoder" on your pc before you can view the statement.........then again, anyone getting hold of that email can install the same free decoder and see it.

But how do you feel about a pdf statement. We all know email does not go from FNB straight to your mailbox....it makes a few stops along the way :-)
 
Serious?
Sheesh - poor form on FNB's part.

I have an issue with posted statements even.
 
Here at standard bank we encrypt your emailed statements.

When you log onto Internet Banking and select to have your statements emailed we ask you to set up a password. The client does have to download a small plugin. When the email arrives, the user double clicks the attachment and the plugin asks the user for the password. If the password is correct the plugin decrypts the email and the user can view it. As soon as the file is closed the plugin deleted the decrypted file.
 
I had a telephonic interview. Unfortunantly, the job was for a monitoring position, so I had to make sure that the servers were up, that the databases were not under heavy load, ect ect.

Its not a job I want to do, its what I call IT suicide. Also, I do not have the skill set required. They needed someone with strong Linux, Linux Scripting, Python, TCPIP, ORACLE, ect.

The interview was fun though.
1st question: whats 2^12.
2nd questions: Whats the response time for Quick Sort
3rd Question: whats the worst response time for Quick Sort
4th question: Given a system with infinate memory and an array of 10000 16 bit intigers, please describe the method your would use to calculate the sum of the bits.
 
Thats easy enough:

1. According to my calculator ....
2. Quick
3. Not so quick
4. Google is your friend :D
 
Thats easy enough:

1. According to my calculator ....
2. Quick
3. Not so quick
4. Google is your friend :D
LOL
1: EZ Mental Arithmetic.
2x2x2x2x2x2x2x2x2x2x2x2=4096

or for the very doff, just 'chunk' it. [baby steps]
2
x2=4
x2=8
x2=16
x2=32
x2=64
x2=128
x2=256
x2=512
x2=1024
x2=2048
x2=4096
 
LOL
1: EZ Mental Arithmetic.
2x2x2x2x2x2x2x2x2x2x2x2=4096

or for the very doff, just 'chunk' it. [baby steps]
2
x2=4
x2=8
x2=16
x2=32
x2=64
x2=128
x2=256
x2=512
x2=1024
x2=2048
x2=4096

At least I answered all 4 questions :D
 
There's a greater chance that my post will be stolen from outside my house than my email account getting hacked.
 
Agreed bwana.

I do see a trend building where companies preffer to email you statements rather than post them.

The nice thing with email:
1) Near instant devliery
2) Cant get stolen or lost
3) You get informed when it cannot be delivered
4) Much cheaper.

I know that MTN, for example, gave me the option to go email and I took it.
 
Company I'm at started distributing a product for most of Africa called PGP encryption (www.pgp.com) about a year back. Since then, we've got many large SA companies - Nedbank, ABSA, Cell C, Denel, NIA etc) so they're definately going that way.

Also - from what I've heard and read, South Africa may get a privacy bill implemented in a few years which says certain information must be protected (customer info). Not sure how accurate I am with this though :/
 
I've sent off a few emails to FNB about the so called 'encrypted' statements.

From the FNB email:

Attached to this e-mail is your encrypted FNB Card account statement. Your statement is encrypted in order to comply with SARS requirements that invoices and statements sent electronically should be tamperproof.

I think they don't quite understand the 'encryption' concept. Sure the PDF is 'digitally signed' which means changes to it cannot be made (easily)

But the document is not encrypted. They do not have a copy of my public key so how can they encrypt it. Anyone intercepting the email can open and read my statement. :eek:
 
I've sent off a few emails to FNB about the so called 'encrypted' statements.

From the FNB email:



I think they don't quite understand the 'encryption' concept. Sure the PDF is 'digitally signed' which means changes to it cannot be made (easily)

But the document is not encrypted. They do not have a copy of my public key so how can they encrypt it. Anyone intercepting the email can open and read my statement. :eek:

Yeah, I had the same problem with Nashua Mobile. I emailed them asking about it, and basically they said they use Adobe 128 bit encryption, which only Acrobat 5.0 and higher can decrypt; and that is sufficient for SARS. That was a few years ago; sad to see that companies don't know any more about crypto by now :(

With regards to them not having your public key - what happens is that there's a key embedded in Acrobat, which is used to decrypt it (so techinically it is encrypted). But anyone with Acrobat can read it, which is, of course, pointless.
 
Top
Sign up to the MyBroadband newsletter
X