
February 2025
To say it up front, I haven't experienced much good. But let me start at the beginning and share my perception of the way the premium credit card provider (in short: the provider) implemented the mandatory validations of customer identities in Germany.
The initial situation: I have a credit card with partner cards from this provider. All of these cards have their own logins and e-mail addresses.
I received e-mails adressing the partner cardholders and asking me to validate the details of the partner cards. Each e-mail contained a link to a website, a so-called transaction number, and the last five digits of the partner credit card number (access data for short). I was asked to use the link and enter the access data.
The e-mail only offered publicly available data, but nothing to allow me to authenticate it. We all know how easy it is to use a false e-mail address, and everything in me screamed fraud. Instead of following the link, I tried to find a way to validate customer data behind the provider's firewall, but was unable to do so.
I contacted the provider's call center. The employee was friendly, but only told me that
When I explained that I couldn't find this option, she promised to check and call me back - guess what never happened?
While I was still waiting, I received another request to validate the data soon. There were probably two perceptions of urgency: while it was fine for the provider's call center not to reply at all, I received a reminder. Driven by my curiosity, however, I found a way to continue without the risk of jeopardizing my PC: I set up a Raspberry PI on a separate subnet of my network (please don’t call me paranoid) and followed the link. I saw a completely blank web form that was supposed to capture all the data the provider should already have. Since this looked like a phishing approach, I became very interested in the situation.

The provider's German language web form for data capture
I used the provider's website and sent a secure message to explain the situation and in particular my concerns. To be honest, I wasn't overly optimistic, but I thought it was worth a try.

A few days later, I noticed that I had received a reply and checked my inbox on the provider's website. However, I was unable to access the inbox. Instead, I received an error message. Probably an evil spirit was preventing me from receiving a reply.

Despite this great experience, I wanted to keep the provider's credit cards. We all like them - but no cards without ID validation.
Thus, I wrote a letter to the German CEO of the provider describing the situation, explaining the technical issues I was facing (including screenshots), and asking her team for help. I had to wait about two weeks. In the meantime, I received the third reminder.
The head of customer service for Germany and Austria and a member of the Office of the CEO replied with a letter on beautiful stationery. I received explanations of money laundering law (nothing new), a reminder to submit the information quickly (which I would have liked to do), an explanation of how to use the credentials - whatever. They also offered me to use Post-Ident - a German identification and authentication service normally used for customer onboarding (kind of time consuming).
But no one explained to me where I could find the validation option behind the firewall. Given the state of the provider's German website, nasty people might assume that the provider didn't find it either, but I personally would never say that.
In the meantime, the reply to my earlier secure message became accessible, but it did not contain substantially new information. But - the letter mentioned an e-mail address for further questions.
Guess what? I sent an e-mail with four questions. Of course, the responses arrived again as a letter on beautiful stationery, and here is a summary:
Did these answers help? Not too much, but it increased the likelihood that this (in my opinion amateurish) combination of e-mail and website was the provider's approach to validating customer data. Threatening to block the credit cards, the provider eventually forced us to resubmit unchanged data inspite of a perception of insecurity. Needless to say, the confirmations of the data transfers arrived in my inbox.
In my humble opinion, there are some odd approaches here (I'm not sure which one to call “bad” or “ugly”), including:
But the worst part was something else: when I asked why the form was not pre-filled, the provider replied that data protection law does not allow this. Given that various financial service providers do pre-fill these fields, I find it hard to believe that this is the real obstacle: perhaps it was the cost, perhaps the need for a speedy implementation, perhaps the inability of legacy systems to provide the data when and as required.
Dear provider, those customers who write letters to the CEO typically want to remain customers - and you should try to understand their issues and concerns. The others simply cancel their contract.
Germany's Commerzbank, the bank I use as a retail customer, handled its customer validation in a way that is in line with best practice - or at least very, very close to it. I received a printed letter offering two options:
I didn't have to spend much time, felt the process was trustworthy, and was happy with it.
The provider could have taken a similarly customer-friendly approach. Why it didn't do this will probably remain its secret. Suffice it to say that my bank account is free, while the provider receives a substantial monthly fee. Does it matter whether this is bad or ugly? At least in the classic western movie, only the good survives the day.

Source: reddit.com