Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> In a case like this, how support personel can tell a legitimate customer from someone trying to gain access through social engineering?

Pretty simple: opt-in KYC. Give people the option to email/fax you their passport or birth certificate or whatever, at any time after they set up their account but before the account is compromised. Extract the relevant ID numbers from the images; then store those numbers, encrypted, the same way you'd store "password recovery" info.

If the account is later compromised on their end, just ask the person attempting to do the recovery to send through the same stuff again, and compare with your recovery fields.

It's essentially the pseudo-biometric, pseudo-"something you have" equivalent of a Secret Question.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: