Santander To Track Customer Location Via Mobiles and Tablets
New submitter raburton writes: Santander (one of the biggest banks in Europe) slipped a little note on the corner of my latest statement saying they intend to start collecting "location or other data" from mobiles and tablets that their customers own, from 1st July 2015. There is no link to further information about the policy, or any suggestion you can opt out of it. The stated aim is of course to "prevent and detect fraud", but once they have the data (and they'll probably keep it for a long time) they, or anyone who can gain access to it, can do whatever they like with it. In this day and age I find it hard to take any assurances to the contrary very seriously. Is this kind of policy common practice with banks elsewhere?
Bank of America implemented this several months ago. No additional features, of course, to even justify more invasive use.
Many, possibly most, ecommerce sites do at least basic location checks for fraud protection and have for many years. The 20,000 or so sites which use our software have done so for at least ten years. If you're on the site from Comcast San Francisco at 10:00, then an hour later someone claiming to be you tries to initiate a transaction while in Russia, that's suspicious.
That red flag is then combined with other available information to choose from one of four possible outcomes:
The transaction is approved.
The transaction is declined.
The customer gets a call / text asking them to confirm the transaction.
Verified by Visa (tm) or the cashier calls in for manual approval.
The system works pretty well.
Note "tracking" is slightly overstating it for two reasons. First, the bank or processor checks only the location of the transaction- we don't know or care where you are if you're not attempting a transaction against an account holder's funds at the moment. Secondly, the "location" is strictly numerical longitude and latitude to see how far you are from the last location. Is it physically possible that you traveled that fast? We don't know or care if you're in a grocery store or a strip club. We only care if "you" are 4,000 miles from where you were two hours ago.
As this is a European company it is subject to European data protection and privacy legislation. Many countries have given their enforcement agencies quite significant enforcement powers to punish abuse and there is pressure for the penalties to be increased to the point that non-compliance is not going to be viable business model:
http://www.computerweekly.com/...
Namgge
Well damn! Start with the the bank president and work your way down. You'll find 90% of it before you hit four layers down the hierarchy.
“He’s not deformed, he’s just drunk!”
I'm in the payment industry and it pretty well works. There's more to it (metrics and whatnot that score up or down your transactions) but location is incredibly useful. Give it 10, 15 years and these sorts of metrics + big data parsing will pretty much eliminate point of sale fraud. Right now the only thing holding it back is processor cycles are still kinda pricy per watt in a data center, but that's changing more and more. Sure, Moore's law is done but we're nowhere's near done with reducing the energy footprint. Plus before long cell phones will replace your credit card, and when your "credit card" is a no longer a dumb piece of plastic but basically a super computer with tons advanced sensors in your pocket it opens up a whole new world.
I know it's popular to say the hackers and crackers will always come out ahead, but really they won't. In 10-15 years the only fraud left will be the large scale investor kind and the "legal" kind where you buy up a company Bain Capital style and suck the life out of it. Small scale credit card fraud is a dying breed.
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/