TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Citibank India wants credit card, bank account numbers to stop marketing emails

168 pointsby manas2004over 11 years ago

18 comments

slowdownover 11 years ago
Citibank is one of the worst banks I&#x27;ve dealt with.<p>Once, one of their affiliate&#x27;s employees offered me a Credit Card for free and said &quot;it had no strings attached&quot; and I don&#x27;t need to do anything to keep it alive. Thought it sounded too good to be true, I bit the bullet and signed up, right on the spot, their affiliate clothing store. Before I was about to submit my documents, it was then I happened to meet a friend by chance and he told me that I would need to purchase a minimum X amount each year mandatorily through the &quot;free&quot; card, failing which I would be levied drastic charges.<p>Shocked, I asked the affiliate&#x27;s employee if it was true and he confirmed the same. I politely declined, got my papers from him, and scored the entire application paper off diagonally so that no sane company would accept it as a valid application.<p>However, the very next day, I get a call from one of Citibank&#x27;s employees asking me to submit a photograph so that he could forward the application. I was shocked and I asked him how it was even possible to submit a scored out application. Even though I scored off the application, I hadn&#x27;t scored off my other copies of proof (Driving license, etc). So the rep had cleverly filled out a fresh form just like I would have and even signed where I should have (!) and forwarded the application to the card processing department. I know this because the rep who called told me that the only thing he needed was a passport size photograph and everything else was pucca.<p>Shocked, I told him that I don&#x27;t need the card and asked him to stop bugging me. I got routine calls from the same rep for about 3 days and also continuous text messages asking me to submit just the photograph. Heck he would have come to even my house (the address was on the proof I submitted) , he was THAT desperate.<p>It was then I decided that I would never ever deal with a shady company like Citibank, ever again.<p>So, I&#x27;m not surprised that they are actually so intrusive to even have you unsubscribe from their site. This bank is full of shit.
评论 #6981591 未加载
评论 #6981810 未加载
评论 #6982651 未加载
davideousover 11 years ago
This is illegal in the United States under the CAN-SPAM law<p>From: <a href="http://www.business.ftc.gov/documents/bus61-can-spam-act-compliance-guide-business" rel="nofollow">http:&#x2F;&#x2F;www.business.ftc.gov&#x2F;documents&#x2F;bus61-can-spam-act-com...</a><p>&quot;You can’t charge a fee, require the recipient to give you any personally identifying information beyond an email address, or make the recipient take any step other than sending a reply email or visiting a single page on an Internet website as a condition for honoring an opt-out request&quot;<p>(My company provides email delivery software and consulting.)<p>[edit for typo]
评论 #6979737 未加载
columboover 11 years ago
This opens up an interesting phish attack. Spam users with seemingly innocent Citibank marketing emails several times a day until they get fed-up and try to unsubscribe using their credit card.
wrathover 11 years ago
This is a phishing attack waiting to happen! I never worked at a bank but I&#x27;m assuming (maybe I shouldn&#x27;t) that there are a few people working there that know a thing or two about security. I doubt that any person who claims to be a &quot;security expert&quot; would have let this go by, but I always seemed to be proven wrong. Take for example TDBank in Canada who has a 80&#x27;s password policy:<p>Passwords must:<p>- be 5 to 8 characters in length<p>- not contain spaces or special characters (e.g. #, &amp;, @)<p>Poor customers if TD ever gets their password database stolen.
评论 #6979791 未加载
评论 #6979776 未加载
评论 #6981868 未加载
评论 #6982200 未加载
raverbashingover 11 years ago
How about you mark their marketing emails as spam and let them deal with the consequences of that?
评论 #6979650 未加载
评论 #6979837 未加载
评论 #6979657 未加载
mtkdover 11 years ago
Getting increasingly harder to unsubscribe.<p>- Some big vendors (Dell, HP?) don&#x27;t seem to use unified opt-out lists or they use agencies that don&#x27;t share unsubscribes<p>- Unsub pages with complicated unsub process (double-negative questions, button size tricks e.g. &#x27;submit&#x27; is small and &#x27;continue&#x27; is large)<p>- Unsub pages requiring input of your email address on a form without the email address pre-populated (so you have to go back and lookup which address received the email)<p>- 2 stage unsub process, so you think you&#x27;ve submitted but it&#x27;s really a page saying &#x27;are you sure?&#x27; in small text with small submit<p>A single-click &#x2F; no interaction unsubscribe is the exception now.
评论 #6979845 未加载
评论 #6980571 未加载
评论 #6980758 未加载
coofluenceover 11 years ago
There is a massive love in India for documents. To get any service in private or public sector, you need ID proofs and address proofs. Even to browse internet at a &quot;net cafe&quot;, you need to produce ID proof! That&#x27;s so because authorities can catch (and some side cash) you if you were browsing anything against what they think the law is.<p>The problem is that there is massive trust deficit. Public too is keen to cheat whenever a loophole exists due to simplified procedures. That invites even harsher regulation and the cycle of submitting 10 documents where 1 would be suffice continues. There are endless certificates and NOCs (no-objection certifcates) required to operate in India: Aadhar citizen number, PAN number, TAN number, Service Tax number, Excise registration, LBT registration, Domicile, 7&#x2F;12 extracts, 20 year old vouchers for LPG gas cylinders, nationality...and so it goes. Also, there is very little belief about who you are and where you live. So for everything an address proof is required apart from an ID.<p>Any wonder that there are no ground-level start-up stories from India. All that we can do is morph into HSFC (Human Services for Cheap) model to serve the rich western countries who want to off-load their guilt of wanting modern &#x27;e-slaves&#x27; in the post-industrial world but not being able to fund their liabilities.
arnabcover 11 years ago
I liked this JS function one of the JS files in that page, specially the name of the cookie &quot;Gabbar&quot;:<p><pre><code> function fun() { var new_dte= new Date(2005,1,1); setCookie(&quot;Gabbar&quot;,&quot;#!#0&quot;,new_dte); setCookie(&quot;hitsscore&quot;,hitsscore+&quot;~&quot;,new_dte); }</code></pre>
评论 #6982326 未加载
jlawerover 11 years ago
A few people have mentioned this but if your using a web based email service, then simple mark the email as spam. This will cause an Abuse Feedback Report to be sent to citibank, which should cause their server to automatically unsubscribe you from the email stream.<p>If your sending bulk email, your not going to be getting delivery unless your process these messages from the large web mail providers.<p>I am actually surprised that they aren&#x27;t required by law to have either a 1 click unsubscribe or at the very worst, require you to enter your email address into the form and click a button. This is the way that the us CANSPAM act and the australian spam act work.
anilshanbhagover 11 years ago
In India, if you want to use your credit&#x2F;debit card online you need to enter a pin&#x2F;password. Hence it is highly unlikely you can do anything with that info. This however is still scary !
chazover 11 years ago
To be ever so slightly more fair to Citibank, this is the page after you&#x27;ve already said you have a relationship with them. This is where you choose: <a href="http://www.online.citibank.co.in/customerservice/DND.htm" rel="nofollow">http:&#x2F;&#x2F;www.online.citibank.co.in&#x2F;customerservice&#x2F;DND.htm</a>. The other option asks for your email and phone number. Still, poorly designed and surprised it&#x27;s considered to be in compliance. Phone and email inputs should be enough.
评论 #6979869 未加载
coloncapitaldover 11 years ago
This is surprising given that the bank IVR and reps keep saying that the bank will never ask you for your personal information.
paragaroraover 11 years ago
This forms opens up when you select existing customers. Upon clicking not existing customers, it asks only email and phone.
donniezazenover 11 years ago
I am not surprised most of the banking websites in India, seems like, designed for IE in 90s. There are pop-ups, options after options, acronyms and more acronyms, and did I mention Verified by Visa thing.
chinmay-ravalover 11 years ago
Looks like a UI bug, credit card number is mandatory only if you want relationship dropdown value as credit card.
aruncover 11 years ago
Anything is possible in Indian market.
FlyingCocoonover 11 years ago
What did RBI said?
dec0dedab0deover 11 years ago
I don&#x27;t understand the issue, from the banks perspective those are basically your username. It&#x27;s not like they need to trick you into giving them a number they issued you.<p>EDIT: The only problem I can think of is that it may encourage users to be loose with their info, and therefore be more susceptible to phishing attacks.
评论 #6979658 未加载
评论 #6979710 未加载
评论 #6979992 未加载