Skip to main content

How UOB's Paper Trail Amplifies IT Greatest Security Threat

UOB required you to do everything on paper. If you want to change your mobile number for your banking account with them or for your credit card, you need to fill up a form.

Yet, this paper trail represented a potential security fail for the bank - Human Error.

So a bitcoin expert walked into UOB to open a bank account. The bank employee had to print a form from a online pdf document to fill in this bitcoin expert's particulars.

When it came to entering the bitcoin expert's email, that's when the forgotten art of handwriting was the most obvious of the digital generation.

Wrote Robert Capodieci,

My name is Roberto Capodieci, as most of you know. and my email address is very obvious to decode. It is not a p4l_l337_s0u1@gmail.com, but it is a more obvious roberto@capodieci.com, thing that, right after reading my name in the same form, should come out easy. Still, a data entry personnel of the UOB bank (or of a service provider the UOB bank uses) entered it as roberto@c2podieci.com.

So this meant Mr Capodieci needed to download a form to change his email address and post it to UOB. Simple?

Not exactly, by the time Mr Capodieci received his activation link, he was already in Bali, Indonesia. If he mailed the form out, it would take 3 weeks to reach UOB.

Unfortunately, that would have passed the statue of limitations for the form which was two weeks.

What could Mr Capodieci do?

Set up an email for roberto@c2podieci.com to get his activation link.

The first problem I think for UOB is that its computer does not have an Adobe PDF writer to allow its bank employees to fill in forms by typing out the particulars rather writing it out.

With a stroke of a pen, an activation code was send to the wrong and non-existing email.

However, the ease of Mr Capodieci setting up an email address online to get his activation code put the spotlight on how a human error might have lead to a hacked account.

It would be of great odds that the activation link be send to the wrong person and that wrong person knows how to clone an email.

But sending a letter to solve a email is quite ironic itself.

Comments

Popular posts from this blog

Singapore radio personality in "hot soup" for reporting train delays based on Tweets?

Update - Hossan Leong has commented on this post to say " I'm not in trouble pls don't blow this out of proportion. Let it rest. It's getting silly. Thank you for your love and concern and I apologize for any misunderstanding." ~  Hossan Leong. Hossan Leong, a Singapore radio personality for The Gold Breakfast Show on Gold 90.5, was censured today for reporting on train delays on the Circle Line because he based the information on Tweets, rather than waiting for the official reports from the Circle Line operator, SMRT.  It is, however, unknown if the "warning" came from Mediacorp producers or SMRT. Tweeted Hossan Leong ,  OK...I reported it on air and now I'm getting into trouble for it?? The CC line is DOWN rite? I did nothing wrong rite? The SMRT Circle Line was reported to be down this morning during peak hours and started as early as 7am. However, local news only received official statement was received by the mainstream media at about 9...

DBS Bank – One Tweet too little too late.

(Updated post - DBS apologise with the 3Rs – Will social media bite? ) It was the bluest Monday for DBS/POS Bank in its entire banking history when more than 1000 of their ATM and online banking services were taken offline due to a software upgrade an outage (PR announced that it was down due to software upgrade, but the outsourcer, IBM, later claimed it was an outage). So on that Monday, DBS decided to sign up onto Twitter and post a 140 characters one-liner onto Twitter to post a one liner to inform the Twitterverse of the down time. Everybody knows that if you just create a new account on Twitter, you would start off with 0 friends. How would you be able to inform the Twitterverse if you start with 0 friends? DBS Bank did something smart to insert the #dbs and #posb and that probably drew some attention to this account. However, the effectiveness of the tweet was lacking as it drew only 28 retweets. As of this posting, DBS Bank attracted 274 followers. A letter to T...

New field in SocialPR: Social Media Crisis Communications

I have been busy with family for the Lunar New Year week but it seem the Singapore blog-o-sphere was active, and is still is, about recently formed Association of Bloggers (Singapore), ABS for short. To cut a long story short, the announcement of ABS via mainstream media didn’t go down well with Singapore bloggers and in the end resulted in some speculation to why ABS was set-up in the first place. A post by the ABS president defending herself against a harsh criticism from a blogger added to the bad start and created even more speculation that ABS was set-up with an ulterior motive. A week later, some founding members of the pro-team started posting up notice of resignation on their blogs and this just added fuel to fire. Again, a story of ABS appeared in mainstream media and this lead to even more disgruntled bloggers asking why the president isn’t responding via her blog or the association’s blog. I also responded to a post about the ABS incident. You can catch a summary of...