We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

First Direct wants email keyed in for extra protection

Options
I'm curious as to know how the present system of using OTP codes is being amended to now include having to type in one's email address.  No problem with that.  However I am left scratching my head re the following info on the FD site

"Why do I need to enter my email address as well as my one-time passcode?

We use a third party, Callsign, who help us protect your payments from fraud by recording how you enter your email address (including key strokes). This data is collected from your browser and stored by Callsign for 3 months. We use this biometric data with other information like your location and how you use your device to help us check it’s you making the card payment and not someone else."

It is the bit in bold that I cannot fathom.  BTW I use a PC to logon (+ a physical secure key) rather than a mobile (because I am a luddite and don't possess a smart one just a cruddy old embarrasing phone with no smart capability).  What if you are using a VPN to logon?  Thoughts?

«13

Comments

  • [Deleted User]
    [Deleted User] Posts: 35,242 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    A VPN wouldn't change your keystrokes, so the same system applies.
  • A VPN wouldn't change your keystrokes, so the same system applies.
    But it would change your location wouldn't it?
  • Zanderman said:
    Thanks for that link.  Seems like absolute rubbish to me.  My typing is not great and the older I get the more inclined I am to hit the wrong key so have to go back and delete an erroneous keystroke etc
  • Migster
    Migster Posts: 150 Forumite
    Part of the Furniture 100 Posts
    edited 21 December 2023 at 3:18PM
    [Deleted User] said:

    Thanks for that link.  Seems like absolute rubbish to me.  My typing is not great and the older I get the more inclined I am to hit the wrong key so have to go back and delete an erroneous keystroke etc
    But that's the whole point. If you often make a mistake and (for example) take around 10 seconds to type your email, the system will be suspicious if suddenly it gets a mistake-free email typed in 5 seconds, as this could indicate that it's not you doing the typing. 
  • cx6
    cx6 Posts: 1,176 Forumite
    1,000 Posts Name Dropper
    I have my browser set to 'clear cookies on exit' so unless they have found another way to store you keystroke patterns this will not work with me
  • PRAISETHESUN
    PRAISETHESUN Posts: 4,859 Forumite
    Sixth Anniversary 1,000 Posts Photogenic Name Dropper
    cx6 said:
    I have my browser set to 'clear cookies on exit' so unless they have found another way to store you keystroke patterns this will not work with me
    Odds are they'll gather the data and store it on their end as a part of your online profile somehow - it wouldn't make sense to use this kinda of thing as a security tool if all it takes to defeat it is to clear your cookies!
  • cx6
    cx6 Posts: 1,176 Forumite
    1,000 Posts Name Dropper
    edited 24 March 2022 at 10:53AM
    Yes I think you are right. Weird system though.

    Wonder what happens if you try and log on and they say the keystroke pattern doesn't match?!
  • [Deleted User]
    [Deleted User] Posts: 35,242 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    They won't say that.  They'll go through further verification.
  • PRAISETHESUN
    PRAISETHESUN Posts: 4,859 Forumite
    Sixth Anniversary 1,000 Posts Photogenic Name Dropper
    cx6 said:
    Yes I think you are right. Weird system though.

    Wonder what happens if you try and log on and they say the keystroke pattern doesn't match?!
    I would imagine that it'll be one of many factors they use to determine if it is you logging in - it might just prompt for extra security (eg. a OTP even if you've already authorised the device in the past) or at worst just lock you out. I doubt they'll ever really explain how it works because that will then give fraudsters the knowledge to be able to try and circumvent the system.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.8K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.8K Work, Benefits & Business
  • 598.7K Mortgages, Homes & Bills
  • 176.8K Life & Family
  • 257.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.