Skip to main content

How UOB's Paper Trail Amplifies IT Greatest Security Threat

UOB required you to do everything on paper. If you want to change your mobile number for your banking account with them or for your credit card, you need to fill up a form.

Yet, this paper trail represented a potential security fail for the bank - Human Error.

So a bitcoin expert walked into UOB to open a bank account. The bank employee had to print a form from a online pdf document to fill in this bitcoin expert's particulars.

When it came to entering the bitcoin expert's email, that's when the forgotten art of handwriting was the most obvious of the digital generation.

Wrote Robert Capodieci,

My name is Roberto Capodieci, as most of you know. and my email address is very obvious to decode. It is not a p4l_l337_s0u1@gmail.com, but it is a more obvious roberto@capodieci.com, thing that, right after reading my name in the same form, should come out easy. Still, a data entry personnel of the UOB bank (or of a service provider the UOB bank uses) entered it as roberto@c2podieci.com.

So this meant Mr Capodieci needed to download a form to change his email address and post it to UOB. Simple?

Not exactly, by the time Mr Capodieci received his activation link, he was already in Bali, Indonesia. If he mailed the form out, it would take 3 weeks to reach UOB.

Unfortunately, that would have passed the statue of limitations for the form which was two weeks.

What could Mr Capodieci do?

Set up an email for roberto@c2podieci.com to get his activation link.

The first problem I think for UOB is that its computer does not have an Adobe PDF writer to allow its bank employees to fill in forms by typing out the particulars rather writing it out.

With a stroke of a pen, an activation code was send to the wrong and non-existing email.

However, the ease of Mr Capodieci setting up an email address online to get his activation code put the spotlight on how a human error might have lead to a hacked account.

It would be of great odds that the activation link be send to the wrong person and that wrong person knows how to clone an email.

But sending a letter to solve a email is quite ironic itself.

Comments

Popular posts from this blog

Will mrbrown's post on Mr Tan Kin Lian's thermometer app "misadventure" promote technology ageism?

I am not ashamed to say I support Mr Tan Kin Lian as a presidential candidate because I believed in what he stood for. And when Mr Tan posted his "misadventure" with a thermometer app, I did shake my head in disbelief that he did that. Source:   http://www.mrbrown.com/blog/2013/07/we-could-have-had-him-for-president.html Thinking twice, there could be a possibility that Mr Tan misunderstood how this app work. Most  thermometer app take data from various weather stations to display the temperature on it. Yes, the technology savvy will do a #facepalm when they read the post and mrbrown's post demonstrated it perfectly. Wrote mrbrown , "Maybe the former Presidential-hopeful didn't realize he needed to upgrade to the Pro version of the app. Then his iPhone would not only measure temperature, it would also measure current PSI (PM2.5 included), tell you if you are having your period, and cook instant noodles. Good thing he didn't try to measure boil

Singapore radio personality in "hot soup" for reporting train delays based on Tweets?

Update - Hossan Leong has commented on this post to say " I'm not in trouble pls don't blow this out of proportion. Let it rest. It's getting silly. Thank you for your love and concern and I apologize for any misunderstanding." ~  Hossan Leong. Hossan Leong, a Singapore radio personality for The Gold Breakfast Show on Gold 90.5, was censured today for reporting on train delays on the Circle Line because he based the information on Tweets, rather than waiting for the official reports from the Circle Line operator, SMRT.  It is, however, unknown if the "warning" came from Mediacorp producers or SMRT. Tweeted Hossan Leong ,  OK...I reported it on air and now I'm getting into trouble for it?? The CC line is DOWN rite? I did nothing wrong rite? The SMRT Circle Line was reported to be down this morning during peak hours and started as early as 7am. However, local news only received official statement was received by the mainstream media at about 9