HJ
Hennie J

1 reviews | Active since Oct 2011

10 Sept 2020, 22:36

The INSECURE “so-called security” features on STD Bank products.

I have been previously using the Standard Bank Shyft Application to make payments in foreign currencies with relatively few issues.

However, when I tried to log onto the App today, it sends me an email with a link requesting me to register my mobile device by linking it to my Shyft profile and the most interesting part of this specific URL link is that this link takes a person to an obscure website, and then it states “set-password” at the end of the URL link.

Herewith an example: https://getshyft.co.za/link-device//set-password/ (random numbers) /set-password/

I tried to locate Shyft’s telephonic contact details in order to verify the authenticity of the process, but they do not have a direct contact number, the only manner in which a Standard Bank Customer can communicate is thus via insecure methods such as a chat system which I was able to activate on the very same unverified website URL.

Here are my SECURITY concerns, the link opens to a webpage that requests my personal details, the link provided has a “set password” at the end of the URL link. That in itself is suspicious. (Please see NOTE “A” below regarding Standard Bank’s terms for personal information requests.)

I am not able to link my mobile device on the App itself, only via this suspicious link. When a customer care consultant phones me, (at my insistence) she also states that there is no other way to have access to my Shyft funds except via this website link. A veiled threat that I do not respond well to! (See NOTE “B” below). I can clearly hear that the person conversing with me is not in an office. When asked if there is any way that she can verify that she is indeed speaking on behalf of Standard Bank/Shyft before I proceed, she says there is none, but she can get her superior to contact me, she will even get the owner to answer my questions. The owner? Really? The owner of Shyft?

I was under the impression that Shyft was a product piloted by Standard Bank, which is an entity and not a person.

Firstly, no team-leader, superior or “owner” contacted me. I was sent information on the previous web chat to read the favourite FAQ for linking a device, on which it clearly states that when you click on the link, you will be asked TWO SECURITY questions. There was a space to insert an ID and cell number which is personal information (again please refer to NOTE “A”) where Standard Bank clearly indicates it will never ask for your personal information. Secondly, any service provider within South Africa from clothing stores to mobile phone companies will have access to both a person’s ID number and cell number. Furthermore, one of the three main Credit Bureaus within South Africa recently experienced a high-level risk security breach where much more information than simply ID numbers and mobile numbers were made public.

In the chat (via unverified website), I was also informed that if I do not want to follow the verification process, I must contact Standard Bank directly and lodge a complaint. (See NOTE “C”)

Seeing that I would be prompted with TWO SECURITY questions, I went ahead and provided the ID and cell number and pressed “enter” expecting to be asked the TWO SECURITY questions prior to linkage of the mobile device, but alas, there was no such security questions & the process was completed successfully. Now please inform me where is this “so-called added SECURITY”. Due to the fact that this information (ID & mobile number) is so readily available, one simply cannot expect that these are the only questions required to activate and verify a customer account.

In fact, this process has not added any extra layers of security whatsoever to my Standard Bank Shyft account, on the contrary there is now less security. Firstly, by having to add my email profile to my phone (in order to re-activate the Standard Bank Shyft App), I now run the risk that if my phone is ******, the perpetrator will have access to both my emails AND my Standard Bank Shyft App. In other words, the perpetrator will have all my details at their finger tips. How very convenient for *********. Furthermore, the perpetrator can now request to reset the password (see example of URL link provided above), which one will presume will send an automated email which a perpetrator can easily access via the recently added email profile on the potentially ****** mobile device. Let’s not forget there are NO security questions, all that is required is an ID number and mobile number.

To add insult to injury, phoning Standard Bank in itself was a total waste of time. I was cut off numerous times before been able to finally speak to a living person. Then when I got hold of a Standard bank Consultant, he informed me he would put me through to the correct department. Instead all I heard was “click” phone call ended.

After many unsuccessful attempts to phone the help desk, I then proceeded to phone private banking directly seeing that I have that facility available to me. The call was answered and transferred to the complaints department. I never got through to the complaint department, even after holding on for many minutes, the phone call dropped again. Each time I got through, the phone call either gets cut or I am actually cut off whilst in the process of getting transferred to another department. This is both tiresome and exceptionally frustrating.

The level of security and service that I experienced today is far below the standard level I’ve come to expect from Standard Bank. In fact, I find that this entire experience today was cumbersome, insecure and counterproductive, not to mention extremely uncomfortable for me as a Standard Bank Customer. Standard Bank needs to urgently re-evaluate all their processes, from lack of security questions for confirmation of an existing active Standard Bank facility, to the lack of an emergency contact telephone number for a Standard Bank endorsed APP product as well as an alternative method for verification, preferably a method using the same App itself. If the mobile device is ******, how can I as a Standard Bank customer deactivate the account or contact the Standard Bank Shyft if no telephonic contact details are provided. I cannot even freeze the available funds. Are my only options to send an email or initiate a chat? Furthermore, the veiled threat of not been able to have access to one’s own finances unless the customer complies with this INSECURE linking method needs to be re-addressed. Such tactics such as ************ are completely uncalled for and totally unwarranted considering the obvious security risks and concerns.

NOTE A: (Copied directly from a verifiable email from the Shyft Team with attached Standard Bank terms of confidentiality. Please not the wording.) “The group will never send you any email or other communication asking you to update or provide confidential information about you or your account. If you have any doubts about the legitimacy of this email or other emails you receive claiming to be from Standard Bank please forward them to ***”

NOTE B: (Via Phone call asking questions about the web link. ) If you don't want to do the security features, and you don't want to insert the information, then your device will not be linked. If you don't want to open the link there is no ways I can help you. (Thus one is forced to insert personal information into an obscure unverifiable website, ie not on the actual app and as previously stated NO security questions were asked whatsoever.)

NOTE C: (Later after the phone call, I received the following on the chat which was still open on PC.) If you are not willing to complete the device linking security verification process please log your concern or your complaint with Standard bank directly in order for them to intervene and assist.

0
Replies (0)