Why the FNB app needs your location data for payments

what are the 'certain payments' that need geo location. why those and not others or all.

also, you can just use internet banking where geo location is not required.

whats the actual point of this.

makes me think more of these calls from, "on behalf of", fnb are on their way
 
@system32

Why can't you control email?

Email is not easy to intercept.
How are you going to intercept my email?

I'm interested.

I control the mx records for my domain. Sender looks up mx records to know who to send to.
connects to the server listed directly. Depending on which of my mail servers it connects to it either stores, or forwards to the correct server.

Are you saying you have control of one of the mail servers involved? At least on the FNB side, I can see some issues which might tilt that your way (detailed below), as mail passes through what appears to be at least two 3rd parties. (Bidvest and enterprisedd)


Email is not secure - unless you use pgp
It's certainly far more secure than sms.
FNB's servers negotiate TLS over DKIM for communications between their server and mine, so its secured between A->B - i.e. you can't sniff the traffic usefully in the event you were in between their network and mine. Their Signatures verify for their messages.

They also publish SPF so I can verify the sender. Although they have in the past screwed that up. As I've let them know once or twice when thats failed.

Received-Spf: pass (([my server]: SPF record at fnbstatements.co.za designates 41.170.90.242 as permitted sender)

What I don't like is that they use a 3rd party for emails.

EnterpriseDD
"Join the EDD Generation. Document Delivery Transformed. With its remarkably accurate, efficient and secure document delivery system, EDD will radically transform your..."

Received: from unknown (HELO relay236.enterprisedd.com) (41.170.90.242) by ([my server] with SMTP; 8 Nov 2020 18:55:52 +0000

Received: from EDD-ZACheque-01.jhb.bidvestdata.co.za (Not Verified[10.0.0.211]) by relay236.enterprisedd.com id <B5fa83f1e0001>; Sun, 08 Nov 2020 20:55:26 +0200

Received-Spf: pass ([my server]: SPF record at fnbstatements.co.za designates 41.170.90.242 as permitted sender)

<[email protected]>

That email server also handles other mails for other clients in addition to FNB. - eg enterprisedd.com 's mail.

dig mx enterprisedd.com

; <<>> DiG 9.11.5-P4-5.1+deb10u2-Debian <<>> mx enterprisedd.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 51527
;; flags: qr rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;enterprisedd.com. IN MX


;; ANSWER SECTION:
enterprisedd.com. 14400 IN MX 15 relay236.enterprisedd.com.
enterprisedd.com. 14400 IN MX 15 relay246.enterprisedd.com.
enterprisedd.com. 14400 IN MX 5 za-smtp-inbound-1.mimecast.co.za.
enterprisedd.com. 14400 IN MX 5 za-smtp-inbound-2.mimecast.co.za.


To be honest I'm not quite sure why FNB doesn't handle their own mails. Would be safer.
I should ask them.


Email is not real time
So what?

Neither is sms, and nor is their app push.

Trust me on this, ... I was an email sysadmin.
Good for you. I also maintain my own email servers, and I disagree with you.





This ^^^^^^^
I'll just leave this here
1604919973131.png
EDIT: Removed name :-) - thanks
The aim is to show why email is not ideal for 2FA.
 
Last edited:
We give up additional aspects of our privacy daily in the name of safety. Yet safety keeps declining. Only the honest are left wasting their days with red tape and bureaucracy. Syndicates already have or will just switch to web browsers or any other means to circumvent measures.
this, especially with nonsense like COVID contact tracing and security registers and other such things that dont serve a purpose
 
Ive been with FNB since the Bob T card with Barclays days in early 80s
Now there's a distant memory! (and also gives away your age!)

I joined FNB since inception in the late '80s (was using United Building Society before then), but left them in 2016 due to their increasingly bad service (and service charges!)

What used to be the best/simplest banking experience online has systematically turned into possibly the worst! Methinks they are out of touch with their clients' needs/wants.
 
If the location data is genuinely helping prevent fraud etc, why does it bother you so much that FNB is using it?
Nothing is a problem until it is used by bad actors. Scammers in back streets? Nope. Bad actors like the state. Look at the SA government versus Paul O'Sullivan on trumped up charges which were in reality political persecution. Or Vodacom/MTN versus previously unmurdered people. The state can get any info they desire from FNB. The less FNB has the better. Maybe not today but maybe tomorrow. FICA and RICA were systems that were put in place to "genuinely protect" against criminals. Both only cause legit people a huge waste of time while the guptas of the world continue without problems. With the assistance of..? You guessed it the banks.


"Thousands of documents detailing $2 trillion (ÂŁ1.55tn) of potentially corrupt transactions that were washed through the US financial system have been leaked to an international group of investigative journalists."

Not obscure banks. Just the largest in the world and the largest in SA.

And when whistleblowers try expose banks?

"As FinCEN has stated previously, the unauthorised disclosure of SARs is a crime that can impact the national security of the United States, compromise law enforcement investigations, and threaten the safety and security of the institutions and individuals who file such reports.”

They are told their actions to expose bank crimes are a crime lol.
 
Last edited:
I signed up a few months ago for an FNB account.

When asked if I also wanted a Credit card I declined as the rep told me I had to agree that they can send my data to their "third parties and subsidiaries as they see fit", in order to get a CC.

What happened?
They sent me the credit card anyway, thus opting me in without my consent.
Their app also wants just about every permissions available on your phone.
No thanks. (And no, I don't have Whatsapp on my phone either).

Chucked the card in a drawer. Don't want to deal with a bank that refuses to listen to a very, very clear "NO, OPT ME OUT" and "No, I do NOT want your CC in that case". I discussed it with their consultant for a few minutes, so there was zero chance of a misunderstanding.
 
Ok... so we know that FNB can now track every move we make regarding where we spend money, and on what we spend it. The question not being asked is "why does the FNB app ask for Bluetooth access?" I cannot think of 1 practical reason why the FNB app needs Bluetooth access. We also know what else bluetooth can be used for... covid-19 spead/contact tracking right? The keywords here is "track" and "contact"... those two terms combined with "locations services"... Let's have the answer here FNB
 
They had to get my location for a completely different reason (of sorts) on Saturday. Imagine having the draw money for the cleaning lady (as the local Spar forgot to add the moneyback) only to find that both FNB ATM's closest to you (at sizeable malls) are gone. Toegemaak. Weg.

Finally located one off the beaten path (at least for me), but, what gives? I know we are moving towards cashless, but if they are so hell bent on it, then they ought to be working their bums off to give us cheap, easily accessible alternatives in the meanwhile. I mean, if I can't get to an ATM and still need cash, why the hell must I buy a product I do not want or need to have access to cash? Incentivize the shops by lowering or, better yet, waiving any charges for swiping, tapping or cashback.

Ek meen dit is nie asof julle fokkers nie al genoeg geld uit ons uit maak vir alles anderste nie.
 
I signed up a few months ago for an FNB account.

When asked if I also wanted a Credit card I declined as the rep told me I had to agree that they can send my data to their "third parties and subsidiaries as they see fit", in order to get a CC.

What happened?
They sent me the credit card anyway, thus opting me in without my consent.
Their app also wants just about every permissions available on your phone.
No thanks. (And no, I don't have Whatsapp on my phone either).

Chucked the card in a drawer. Don't want to deal with a bank that refuses to listen to a very, very clear "NO, OPT ME OUT" and "No, I do NOT want your CC in that case". I discussed it with their consultant for a few minutes, so there was zero chance of a misunderstanding.
Similar to you, I needed a back up credit card since virgin Money is leaving the country so that I can use for online purchases, but since I will only be using it occasionally wanted the cheapest credit card. decided to go for the FNB gold card. Was approved for a premier FNB credit card but told them I did not want it as the fees are higher and I only need a gold card. Got declined for the gold card. Went in again to find out WTF happened, was told it was due to some technicalities.......... long story short attempted three times to get the gold card, got declined every time.

Decided to rather go to Capitec. Walked in and 45 minutes walked out with the card in my pocket Fica'd and all.

FNB has lost the plot
 
How does using location data = a lack of security understanding?
Because many people disable it on a global level. Making it a requirement breaks that security. Besides people's habits aren't that rigid so it offers no benefit. FNB showed they have zero understanding when they forced people to use remembered and thus weaker passwords.
 
what contractors are these?
I know Entellect is one of them. I don't know the others but I do know they had to integrate with products built by other companies. I am assuming its a mess as they haven't made any real updates to it.
 
Well my recent messages now has a location button for some transfers and payments.
 
Top
Sign up to the MyBroadband newsletter
X