Umm, did you miss the part where the email said to call the number printed on the back of my credit card? I did so, and that’s who I was speaking with.
I closed the account for that credit card. Do not need.
Yes, I did miss that. And reading the OP again, I still don’t see it. But sorry if I misunderstood.
It might technically be okay, but you are better protected if you don’t reply at all. For example, some messaging apps won’t allow a sender whom you have never replied to (or is not in your contacts) to text you tappable links, so the scammer tries to trick you into responding first with an innocuous Y/N, then sends the malicious tappable link. And since they have now primed you to engage with the Y/N reply, you’re now more likely to tap a link. So the best thing to do is just not reply at all.
At the very least, replying to an unsolicited text confirms to the scammer they have a live number of someone who will engage with unsolicited texts.
There are rare edge cases, but basically just don’t respond at all to unsolicited texts.
You make a very good point :smack self in face:
Yeah, when I clicked “No, I didn’t authorize this transaction”, I was taken to a web page that instructed me to call the number printed on the back of my credit card.
You don’t need to smack yourself in the face
heh!!
That is good advice, but I don’t think there is much risk in responding to yes/no texts that come from a number that you have previously received texts from your credit card issuer. I do get those occasionally.
While it’s not 100% risk-free because a text number can be spoofed, so long as you don’t click on any links or pick up a follow-up incoming phone call, you should be ok.
But I do totally agree if you get a text from a number you have never received texts from before.
None? Srsly?
I recently hit a medical test scheduling site that would only let ONE account use a given cellphone. Which was inconvenient, since my wife doesn’t use her phone for anything like this–we use mine. Once I got ahold of their support folks, however, it turned out that we could add her as a “family member” on MY account so I could schedule for both of us. I also discovered that it would do 2FA to a landline via synthesized voice, though it wasn’t smart enough to tell me that–I discovered it by accident when I changed her account to NOT use my cellphone# and it called to verify that change.
I’m getting pretty tired of 2FA+site timeouts: I start doing something, go through 2FA, get logged in, she needs something, and by the time I get back to the screen I get to start over.
Not to mention the one I hit last week with a THREE MINUTE timeout on the 2FA code. Which wasn’t enough for the email to arrive; took me several tries before I JUST made it under the wire.
2FA is great, as long as it’s done right. And in appropriate circumstances–Dunkin, I’m looking at you: you act like logging into your app is accessing the nuclear codes!
I’ve had donuts and I’ve had nuclear codes. All things considered, I prefer donuts.
The Wendy’s app doesn’t even do two-factor. It won’t ask me for a password. It sends an email with a link. No code, just a link, and you must be on that phone to log in to their app.
It’s extremely common for these groups to come up with their own ways of doing things and having no other way. I just want to have my app logged in on my phone. You know, something my bank will let me do, as long as I use my fingerprint sign in again before actually doing any transactions.
Yes, I’ve seen more and more of this. It’s irritating when it’s something like Wendy’s, where you’re trying to get it done fast, and having to wait for the email is dumb!
My bank does fingerprint sign-in but then also sends a 2FA. To the phone. On which I just did the fingerprint sign-in. I’m not sure that makes sense: in a SIM-swap scenario, it’s not going to help. If I lose the phone and someone finds it, they’re not going [well, not that likely] to get past fingerprint login. But belt-and-suspenders is at worst harmless in the case of something like bank access, at least. Dunkin, not so much!
I’ve noticed that some fast food doesn’t even trigger the most basic login requirement to use Google Pay, which I assume means they’ve chosen to assume the fraud risk over the increased friction of having to do logins. Which (if my reasoning is correct) is a business decision that presumably makes sense for them.
Thanks to this thread I checked out how apps that have fingerprint authentication react when I make a change to the fingerprints stored on my phone. My concern is if someone other than me has access to my phone, could they add their own fingerprint and then sign in to my apps? And it turns out that it depends.
Both my password manager and a brokerage account app disabled fingerprint sign on when any change was made to the phone’s fingerprint profile, requiring a password login before enabling fingerprint sign on again. That’s good.
However, two other apps didn’t care. One was the Verizon app, which sucks because the bad actor could then unlock my SIM. The other app was the Microsoft Authenticator app, which I suppose sucks even more, seeing how that app should be as secure as possible. I think that I may be looking into another source for TOTPs.
Of course, to actually add a fingerprint requires the phone PIN, so perhaps I am overreacting. Still a bit surprised at what I learned though.
Android 15, btw.
For sure. My husband has lost thousands of dollars in Apple music because he lost his phone and so changed his number. Mistake, as now they can’t text that number. They will entertain no other ways of authenticating his account.
Android should force you to authenticate again with your current fingerprint (or equivalent unlock method) just before letting you add a new one. Does it not?
Assuming that you are talking about the Verizon and Microsoft Authenticator apps: yes, I was able to use my fingerprint to sign in, it didn’t care that there was a new fingerprint added. The other two apps basically said “No, we won’t recognize a fingerprint because there has been a change in the fingerprint profile, please log in with a password”. Which seems to me to be better from a security standpoint. But as I said (and to answer your question) adding a fingerprint requires the PIN, so maybe it’s not a big deal overall.
It does tell me that an app can detect a change in the fingerprint profile, and some apps lock out fingerprints after a change and some don’t.
After I logged into the more restrictive apps with a password I was able to re-enable fingerprint log in.
I had to deal with something similar with Comcast last month, although I did eventually get the issue sorted out. I’m supposed to get Peacock for free as a reward for being a customer with them for so long, but when I logged into my Comcast account to activate it I got an error saying something like “This feature is only available to the primary account holder”. Which was odd, because I’m the only person on that account.
Long story short, apparently when I first signed up for Comcast internet way back in 2008, an account was created for me, which I promptly lost the login information for. At some later point I created another account, through which I could go online and pay my bill and do all the other stuff I needed to at the time. But that apparently was considered a “secondary” account, and that old account from 2008 that was just sitting dormant was the “primary” one. And certain features can only be accessed through the primary account, like the rewards I was trying to access (and apparently if I ever wanted to move my service to a new address, that can only be done online through the primary account). Except the contact information associated with that primary account was the comcast.net email address I was given when I signed up, but never used (and Comcast actually closed because I didn’t use it), and my old landline phone number that I haven’t used since like 2008 but I guess must have been the number I gave them when I first signed up. And their tech support needed to authenticate me by contacting me via one of those, neither of which I had access to. But they did let me authenticate myself by going in person to a Comcast store with a photo ID, and they were able to eventually sort it out there. (I’m somewhat surprised Apple didn’t even let your husband do something like that in person at an Apple Store).
Well, it’s not quite entirely sorted out to my liking, because for some reason the primary and secondary accounts can’t use the same email address or phone number. I did at least have another email address I could use, but I couldn’t use my cell number because it’s already tied to the other account. So I put my work number, because it’s literally the only other phone number I have, except they want to verify it by sending a text, and that number can’t receive texts. I’d like to just delete that other secondary account since I don’t really have a need for it now that I’ve gotten access to the primary one, and theoretically I can do that from the primary account, except it won’t let me until I provide a cell number for the primary account, but as we’ve already discussed it won’t let me use my actually cell number because it’s already associated with the other account. Oh well, at least I can log in to the primary account now and do the things I want to do.
Therein lies the problem. If you’re speaking of a one time or temporary authentication password, their (the banks) app that spits this out this pass code doesn’t work and has never worked, unless it’s recently been fixed.
Well, that is the bank’s fault. This is the well-known temporary-password scheme supported by Google Authenticator and any number of free apps, and is perfectly okay as one of the “factors” for authentication.
I bought this thing from Radio Shack that you could hold against the mouthpiece and press buttons to generate the tones. It was kind of a PITA.