Thank you!

Dear Readers,

Thank you, indeed. The number of page views crossed 15K on Nov. 1, 2016.

A compilation of the blog posts up to first quarter of 2016 has been published and is available on Smashwords, Amazon (Kindle store), and Google Books.
Showing posts with label bank. Show all posts
Showing posts with label bank. Show all posts

Saturday, May 7, 2016

Internet Banking and Travelling Overseas

With steady increase in the NRI numbers, many parents make yearly trips abroad to spend some time with sons, daughters and their "grand" versions.  One issue that inconveniences them is the use of internet banking while abroad. They have to use it for payment of bills as also checking their accounts.

All banks impose use of use-once-only OTP (One Time Password) under certain conditions though the usage is not uniform.  The use is for ensuring that the action is being performed by the genuine account holder who is in possession of his registered mobile number.  The OTP is sent as an SMS on this registered mobile number.  Some banks initiate OTP at the time of login itself if they find that it is being done from an unfamiliar device and location.  While some banks may just have a second password for transactions, others insist on use of OTP for all transactions irrespective of device or location.

The point is that unless international roaming is activated on your Indian mobile number,  you may not be able to make use of Internet banking.  International roaming is not only expensive but also not as easily available as national roaming.  BSNL does not provide international roaming to its prepaid customers.  Airtel does, but not to customers in East UP circle: This gets my goat as I reside in this circle.  And then this roaming can prove to be very expensive if you were to respond to an incoming call by mistake.

I had found a solution for this.  I put an app 'Relay ME' on my phone.  Then I would leave my phone in India with someone who could ensure that it is kept charged and connected to the network.  The app relays all received SMS to an email address configured in it.  This did the job without having to go for international roaming.

Now many banks have introduced 'active token' for generating the OTP instead of receiving it from the bank.  It is done through an app on customer's smartphone.  The OTP can be generated whether or not you are in the coverage area of your GSM operator.  However your SIM which has the mobile number registered with the Bank, must be present in the phone. Presto! carry your SIM with you and forget about international roaming.  As long as you have a wi-fi connection you can carry out Internet banking unhindered.

Activating the "Token" app is just a little bit tricky.  For this purpose you have to log into your Internet banking account, preferably on another device while activating the app on your smartphone.  Also you must install the app on the phone which has the SIM for the registered mobile number.  You will receive an SMS which will have an URL for activation and you have to click on this URL on the phone having the app and the SIM.  However all the hassle is worth it.

Finally, having your Bank's mobile banking app on your phone also helps.  It allows you to login and transfer funds without OTP.  However when you are being redirected to bank's Internet banking site by an online merchant, you may have to resort to the "Active Token."

Do share your experience if you have been using an active token for banking transactions.

Saturday, November 17, 2012

Beware of Credit Card Frauds

As I was taking my car out on the second day after Dipawali, i.e., 15-Nov-2012, I was distracted by my phone which announced arrival of 15 messages.  I thought these must be delayed Dipawali greetings and that I could defer viewing them.  But then I opened the message box on impulse.  Out came the Jack-in-the-box and hit me with full force.  All the 15 messages were for successful transactions on my credit card!  All the transactions appeared to be carried out on the Internet and they were all done within the span of one hour with the midnight hour of 14th and 15th November in the middle.  The last transaction was for Rs.200/= for draining out the credit limit to the hilt.

So I parked the car right outside my house and went back in.  A lot of telephone calls were made to Bobcards and umpteen mails exchanged.  I also visited two websites where several of the transactions were made and left complaint notes using a form available on them.  One of them promptly acknowledged the message and also charged back the amount saying that investigations showed that it was a fraudulent transaction.  The other asked me to request my card company to talk to them.  All these messages were passed on to Bobcards.

It seems that my password for internet card transactions was reset by the miscreants and then used for the fraudulent transactions.  Now the Verified-by-Visa (VBV) implementation by Bobcards definitely lacks security.  So if you have forgotten your password or are a miscreant who has got the card number, CVV and expiry date but doesn't has the password, the only additional piece of data required for resetting the password is cardholder's date of birth!  All these data are available with the card company and its service providers and if a staff is so inclined he can easily carry out the password reset operation.  I inquired with some other banks' customers.  They have given me to understand that they have to use an OTP (One Time Password) for password reset.  The OTP is sent to them on their registered mobile number.  This security check is missing in the Bobcards implementation, and this weakness is sure to attract cyber criminals in hordes.

So be careful with your Bobcard.  I am relying on the following (picked up from the Visa website):


Zero Liability

Zero Liability


Shop anywhere with absolutely no risk

Your peace of mind and protection are paramount to Visa. Visa's Zero Liability policy is our guarantee that you won’t be held responsible for fraudulent charges made with your card or account information
In fact Visa goes on to say:

Count on quick resolution and provisional credit if your card is lost or stolen. 1


If your account is compromised, Visa is committed to setting things right without further aggravation or inconvenience to you. Visa’s cardholder protection policy requires all financial institutions issuing Visa products to extend provisional credit for losses from unauthorized card use within 5 business days of notification of the loss.