Your Bank's Back Door Is a Selfie and a Sticky Note
Your Bank's Back Door Is a Selfie and a Sticky Note
This episode is based on our article:
Read the full article →Your Bank's Back Door Is a Selfie and a Sticky Note
Full Episode Transcript
Picture this. You've built a bank vault with steel walls, biometric scanners, and a retina check at the door. Then, around the back, there's a screen door held shut with a sticky note. That's not a metaphor for bad security. That's roughly how some digital banks handle it when their system glitches.
If you've ever changed the email address on your
If you've ever changed the email address on your bank account, this story is about you. Here's what set it off. A financial platform called Qonto uses a serious identity check when you sign up — biometrics, a liveness scan, the works. But according to reporting from Fincrime Central, when that automated check fails during something routine, the backup plan gets primitive fast. Customer support asks you to take a selfie, hold up your I.D., and write a handwritten note. So the question that runs through everything today — why does the strong door only guard the front, while the back stays wide open?
Let's start with what actually happens when the machine says no. The vendor behind the scan is a company called Fourthline. When its biometric and liveness detection can't confirm you, the fallback kicks in. A selfie. A document. A note scrawled on paper. That looks official. It feels like proof. But a photo of a face next to a handwritten sticky note gives no cryptographic proof of anything. For the rest of us, that means the thing standing between your money and a stranger might be a picture a determined attacker can fake.
And attackers have noticed. Security researchers describe a simple truth. An intruder doesn't attack your strongest lock. They go looking for your weakest one. Once they realize recovery is easier than the front-door login, they aim straight for recovery. Password resets and account-recovery flows are becoming a favorite way in.
Now the scale. In the U.S. alone, losses from account takeover — where someone hijacks an account that isn't theirs — reached over fifteen billion dollars last year. That's up nearly a quarter from the year before. That's not a rounding error. That's people locked out of their own money.
The Bottom Line
There's a deeper design flaw underneath all this. Most systems treat your identity check as disposable. You prove who you are once, at signup, and then that rigor gets thrown away. When something breaks later, the company tries to rebuild trust using weaker signals than the ones it used the first time. A selfie with a note isn't a weaker signal. It's a weaker defense — against deepfakes and synthetic identities good enough to fool a human reviewer squinting at a screen.
Here's the part that flips the whole thing. The security gap was never in the front door. It's in the fallback. Companies spend a fortune making onboarding fortress-grade — then, the moment something goes wrong, they quietly reset the defense back to about two thousand five.
So let's bring it home. Banks build an incredible lock for the day you join. But when you get locked out and need help, they often hand you a much weaker one. And a weaker recovery path helps the thief more than it helps you. Most people only discover this the hard way — locked out, desperate, and finding out the back door was open the whole time. The full story's in the description if you want the deep dive.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Episodes
That "Prove You're 18" Pop-Up Is About to Be Everywhere — And Fakes Are Coming for Your Kid's ID
A major identity verification company left its login credentials sitting exposed online for over a year. In that time, anyone who found them could reach names, birthdates, national ID numbers — and photos of people's actu
PodcastThat Annoying "Verify Again" Text? It's Catching Fraudsters Using Real ID Numbers
Researchers at deepidv looked at four million fake identities. Nearly a quarter of them used a real government I.D. number — a legitimate number, pulled from a real record — paired with completely invented personal details. <break time="0.5s"
PodcastYour Face Is Forever. A Judge Just Ruled Companies Can't Hide What They Did With It.
A judge just ordered a company to hand over its deletion logs. Not its marketing. Not its emails. The quiet, boring records that show exactly when it erased people's faces from its systems. And that o
