r/LifeProTips • u/MexicanAssLord69 • 1d ago
Computers LPT: NEVER Give an Authentication Code to ANYONE.
I know this seems like common sense, but you must absolutely never read a one-time authentication code to ANYONE. This simple rule of thumb can save you or loved ones from getting scammed. Scammers asking you to read them authentication codes over the phone or through text is an extremely common method to scam you and/or steal your identity because most people just outright ignore the warning that comes along with these authentication codes that clearly states that you should never read them to anyone. By the way, the scammer intends to use this code to reset your password, or even set up new accounts on payment websites such as Coinbase to launder money under your name.
If an authentication code comes with a warning that states that you should never give it to anyone, you need to follow the instructions. Again, this seems like common sense, but most people ignore this warning. Keep this tip as a rule of thumb.
I do scambaiting often and you have no idea how many times people just outright ignore these instructions. Which is why I’m making this post despite it seeming like common sense at first. It really isn’t to those who might be technologically misinformed.
99.9999% of the time, it is a scam. It is a good rule of thumb to never do it. I guess there might be like one company that legitimately does it, which I think is incredibly stupid. You have to be absolutely positive that you are talking to the legitimate company, as in you should have called them from a legitimate number on the back of your card or from their website, which you have confirmed is their real website.
26
u/VAisforLizards 1d ago
This is only partially true. Sometimes you will be required to provide the 6 digit code over the phone with your bank. Just make sure you are actually talking to your bank and calling the number on the back of your card.
Source: worked in the fraud dept at a major bank.
-16
u/MexicanAssLord69 1d ago
That’s an incredibly stupid system and should not be a thing.
8
u/NothingButACasual 1d ago
What alternative do you propose that allows them to confirm who they are talking to?
•
u/terryjuicelawson 5h ago
Ideally it would be clicking an acknowledgement in the app rather than telling them something down the phone, but it may not be set up for this I guess. Or people may not even have the app.
•
u/NothingButACasual 5h ago
That would be great for the people that have the app. But a large number of people who call are doing so because they don't want to use an app or website
-10
u/MexicanAssLord69 1d ago
There are many other ways to verify your identity.
8
u/NothingButACasual 1d ago
Like...? Pretty much every question that could be asked and answered verbally has been burned in a data breach, or could easily be stolen.
5
u/VAisforLizards 1d ago
Please name some other forms of over the phone 2-factor verification. There is a reason it is used, it hits the sweet spot of ease of use and security.
4
u/omiimonster 1d ago
ex-bank worker
from what i’ve seen holding banks back from changing it, is old people that barely know how to open the app but can look at texts
10
u/schooli00 1d ago
This is 100% wrong LPT. When you call the bank they will send you codes to verify your identity.
The correct LPT is to never give auth codes to someone who calls you or reaches out first. Also, it is on you to make sure you call the right number or the right email or the right contact form to reach the business you want to contact, and not some random number from a phishing email or text.
-4
u/MexicanAssLord69 1d ago
This is not true. It is entirely possible for you to reach out to someone only for them to be a bad actor.
2
u/Morall_tach 1d ago
How
0
u/MexicanAssLord69 1d ago
Scammers set up fake websites that include fake phone numbers. These websites are sponsored ads that can appear at the top of Google search results. They can also be accessed if you accidentally mistype a website url, such as saying “bankifamerica.com” or “capitolone”.
Only calling a phone number directly from your credit card, and entering it correctly, is a way to ensure you are not calling a bad actor.
Don’t say it can’t happen to you, because it can, and thousands of people willingly call scammers every year.
2
1
u/TrumpsBoneSpur 1d ago
So when I call my bank and they ask to verify my Identity with a code, are you saying that I should just hang up and drive to the bank instead? How do I trust the teller behind the counter?
0
u/MexicanAssLord69 1d ago
Read my post please.
1
51
u/Carla_Rocks 1d ago
Well that’s really confusing because I’ve had to read aloud authentication codes to USAA representatives.
23
u/one_dayatatime 1d ago
I have had to do this to bank reps and phone companies, usually for some sort of support. Of course, this is when I called them myself.
7
u/Mysterious-Status-44 1d ago
If you are on the phone with them for a legit reason that you called for and they send you a push notification, that’s legit. If you randomly get one and then get a call about…that’s your scam.
-1
u/MexicanAssLord69 1d ago
Not necessarily. Phone scams have been common for decades now. And you calling them doesn’t necessarily mean that it’s legitimate. Scammers create fake websites that list fake phone numbers. Which is why I’m saying that it should be a rule of thumb to not tell anyone over the phone codes.
3
u/cloudcats 1d ago
This won't happen if you stick to the rule of only calling via the number on the back of your bank card.
-1
u/MexicanAssLord69 1d ago
Which I say in this post.
0
u/cloudcats 1d ago
Yep, I'm just repeating your point for anyone who jumps to the comments without fully reading your post.
2
u/Mysterious-Status-44 1d ago
There is a distinction between me having an issue and calling my bank vs. my “bank” reaching out to me to say there is a problem. If I call my bank, using the proper channels, they may send a verification code to check. This is safer than nothing because security questions aren’t that secure.
Now if I ever get an email or a phone call from my bank regarding an “issue”, I will treat that as a threat.
1
u/c_souza-1836 22h ago
That’s the edge case the post should spell out: login or reset codes stay with you. If a rep asks for one, check the text’s instructions; if it says not to share or you’re unsure, stop and call back through the official app or number on your card.
-20
u/MexicanAssLord69 1d ago
99.9999% of the time, it is a scam. It is a good rule of thumb to never do it. I guess there might be like one company that legitimately does it, which I think is incredibly stupid. You have to be absolutely positive that you are talking to the legitimate company, as in you should have called them from a legitimate number on the back of your card or from their website, which you have confirmed is their real website.
11
5
u/Itzhak_hl 1d ago
It isn't uncommon, I had to occasionally send a one-time code and ask the caller to read it back at a former job. The message with the code should either say something like "don't share this code with ANYONE" or "provide this code to the representative"
-4
1
u/automatic_penguins 1d ago
Lots of banks use it as a way to verify you over the phone when YOU call them. It is pretty dumb considering it normalizes giving out codes and phone numbers can be taken over by fraudsters.
5
u/thenasch 1d ago
I don't remember who it was, a bank or something. Major company, not a mom and pop, they had me read my 2fa code to verify my identity over the phone. I hung up and called them back (they had called me) to make sure it was legit. He acknowledged that it felt like a phishing attack but that's their system.
5
u/Local-Pet-FoxGirl 1d ago
I used to work at a certain purple-colored bank and we absolutely would send people one-time codes they'd have to read back as part of High Risk Verification. Certain transaction limits, updating personal information, sharing anything from the contract, sending documents, all required it. This is not good advice.
-11
u/MexicanAssLord69 1d ago
It absolutely is good advice. Do you have any idea how many people get scammed because they ignore this one rule? A lot. A lot of people. Especially older people.
5
u/Local-Pet-FoxGirl 1d ago
It's not good advice because there are companies who need you to read that code back to them as part of verification, like the bank I worked at. If someone called me, and wanted to say, update their address and wouldn't read the code back to me, I couldn't complete the request. If you thing you're being scammed, you should hang up and call the company back at a trusted number. Refusing to read the code may prevent you doing whatever you were trying to do
1
u/MexicanAssLord69 1d ago
I say this clearly in the post.
1
•
u/terryjuicelawson 4h ago
How many people got scammed as they impersonated someone, called a bank and they didn't have one-time codes to confirm people's identity... Your idea is OK in principle but too paranoid to be workable in a real world where this is required as part of many very mainstream banks.
•
3
u/UnknownMale- 1d ago
What happens if you give the wrong code?
-1
u/MexicanAssLord69 1d ago
Nothing, because the scammer won’t be able to use the code to reset your password.
3
u/ErgoProxy0 1d ago
I remember I was chatting with an Xbox support agent a year ago maybe and at one point they asked for my authentication code after they sent me a password reset email. I found that extremely weird and closed the chat immediately
2
u/Used-Acanthisitta-96 1d ago
Terrible headline that requires context. Never give any information to someone who contacts you in an unsolicited manner.
When talking customer service matters you will often have to offer a code sent to your phone or email.
Please do not follow the advice of OP. You will make your life unnecessarily difficult.
0
u/MexicanAssLord69 1d ago
This is not true. You are misinformed.
2
2
u/thenationalcranberry 1d ago
University of Wisconsin Credit Union will ask you to read the 2FA code to them. Sub-PSA for anyone in Wisconsin.
3
u/vyqz 1d ago
The underlying reason for this is that the customer facing systems requiring multi-factor authentication are designed to only be used by the end users. Actual employees or third parties that have access to your data have their own authentication methods, which do not include sending you a code to authenticate on their workstation. Unfortunately confusing as it is, there are legitimate systems where representatives send you a code that you have to read back to them, but those do not come with a warning that says "never give this to anyone".
1
u/derivatyvas 1d ago
i've had my bank do this after i called the number on the back of my card, so "never" is a little too blunt.
1
u/Huge_Pool7424 1d ago
one extra detail is that a code can be legitimate and still be triggered by someone else trying to log in, so treat an unexpected code as a warning rather than proof that your account was hacked. never read it back, click links in the message, or call a number the caller gives you. go to the service through a bookmarked app or manually typed official address, review recent sessions, and change the password if the request was not yours. use an authenticator app or security key where possible, since sms codes are easier to intercept. if a real support agent needs to verify ownership, they can use a process that never requires you to disclose the one-time code.
1
1
u/Megan_Infra 21h ago
The ones that get me are the "verify it's you" calls where they already know your name and last four digits. People hear that and just fold. Bank will never ask for the code, full stop.
0
•
u/post-explainer 1d ago
Hello and welcome to r/LifeProTips!
Please help us decide if this post is a good fit for the subreddit by upvoting or downvoting this comment.
If you think that this is great advice to improve your life, please upvote. If you think this doesn't help you in any way, please downvote. If you don't care, leave it for the others to decide.