Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

- When I worked in a bank's call center, it would be impossible for such an attacker to gain any information without the (receiving) agent screwing up unless the attacker had already successfully phished a different employee.

- The situation you describe in particular, where one employee might cold transfer to another employee without the receiver verifying whether the customer had identified already...if that is even possible, it's gross negligence.

- Call centers typically record all calls regardless of origin; it's not like a human being manually hits a record button on a case-by-case basis.



When I worked at a call center, I eventually was promoted to call monitor, where I was actually the person listening to the recordings and grading reps on how they did. Our system did not record every call. It was a random sampling, and I had to hope a given MSR got recorded enough times in a month for me to hit my minimums.


Different use-case but we've implemented recording on all call-center calls; this isn't for employee monitoring, it's so we have a recording for legal purposes because some of those calls involve instructions for financial trades.

If I was in PayPal's situation I'd want to record every call, because dealing with money is a lot more critical than dealing with call quality.


I suppose I could have hedged a bit with the usual "may depend on the institution" disclaimer, heh. Anyway, I was responding to the apparent belief that someone might look at the inbound number and think "no need to record this one," which I'm pretty confident saying does not happen.


I've implemented this is a call center. We recorded every call. It's actually harder to do "random sampling" than just have the button auto-click every call. It sounded like Paypal reviewed the call transcript before making a statement.


Re: recording...

Why does the message when you call say something like '...may be recorded...' where "may" sounds like it's synonymous with "might"?

I know why they have to have the message but I was just curious if there was a reason for the apparently odd wording.


They reserve the right not to record the call, in case the stuff hits the fan and a customer insists on getting a recording of the call where everything went wrong.


The wording is specifically because they want to pretend that only a small share of calls are recorded for quality review and that it is very unlikely that your particular call will be recorded.


Why commit yourself to a stronger statement than necessary? As you probably already know, it's just to satisfy laws against recording a phone call without the consent of both parties. It's just a nicer way to say "we will proceed assuming we have your consent to record this call," without promising or revealing anything further.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: