SEPA privacy - fantasy recipient name / initials only

Repeating myself:

This thread is only about the SEPA RECIPIENT! As a seller you don’t even see the name the SEPA transaction was sent to.

Yes for me as well, but seems there are people falling into such stuff. probably mostly older people or from rural areas where life is less corrupt :slight_smile:

I dont know what you mean.
You see the popup when the buyer has sent the Fiat where it states all the info and data and in the screen you see the bank details of he btc buyer.
The btc buyer need to know anyway the sepa details. There might be some banks who don’t check if the name is correct, but I assume most would make problems if it is not.
So simple rule: All the bank details need to be correct and match with the account used for the actual transfer.
That helps to avoid 2 Problems:
Problem 1: Bank rejects sending of Fiat if any details are not correct
Problem 2: Social engineering scams (MITM attack) are easier to do if we allow that you receive Fiat from someone else as stated in the Bitsquare payment account.

If you want more privacy in the Fiat side use OKPay or PerfectMoney.
We cannot fix the banks, sorry :wink:

I know it’s hard to believe but since a couple of years ago SEPA transactions are not required to have the name field checked any more. So banks just don’t do it because it costs a lot of money. There really is no problem 1 for this issue.

Say I were to send money to Alice’s IBAN via a SEPA transaction. In the recipient name field I put “Bob is an old fart”. Alice would never know as she has no way to tell. So this case does not help problem 2 either
(of course the seller still needs to check the SEPA sender name which he can see against the credentials from Bitsqure because it helps a bit against MITM but this is something completely different).

Please rethink this as it helps privacy at no cost as far as I can see.

Thanks for the info. I did not know that the name is not mandatory and I am surprised about that.
Still most bank interfaces require it (in my experience), some even require an address of the receiver or the banks address.
We will take it in consideration.

Please update this thread if anything changes. It would definitely help with privacy of btc sellers not to give out the account holder name at their bank. Selling via bank SEPA on Bitsquare is a big advertisement to people, saying “This person has bitcoin, resides in country X and does business with bank Y”.
It is not hard to imagine in today’s world that hackers will catch on and be willing to lose a security deposit in order to carry out spearfishing attacks on bitsquare users. Heck, they don’t even have to lose the deposit if they are willing to buy some coin.

This security concern, however, greatly depends on the bank’s willingness to identify recipient names to IBAN numbers. If it is trivial to socially engineer the name from the banks, it would just be one more hoop to jump through. If anyone knows the details on that, it would be great to hear.

Just now I did two SEPA transactions with UBS Switzerland electronic banking. The address of the recipient of the money is not required, but the field for town and pincode of the recipient is compulsory. Since this data are not given by bisq, I did one transaction with the same town and pin the bank has, the other transaction I did with a fantasy town and pin which really exist, because I know that in this case the town and pin of the bank are with very little chance the same like town and pin of the recipient. A little later the same evening I contacted the 24h support of UBS. I just said, that I have all required data, but not town and pin. The answer was, that in the field at least a * or a . must be typed and if the town and pin are not correct, the payment could be rejected. Probably on the 16th of March or on the 17th I will see whether the SEPA got accepted or not, but Saturday and Sunday UBS does not process SEPA. I hope I will not run out of time, if it does not work.

1 Like

Don’t worry about the time too much, I am sure the arbitrator will understand.

Both SEPA transactions went through. So everything fine.