Live data from Hacker News

Voice Phishing Scams Are Getting More Clever

krebsonsecurity.com

41–50 of 226 posts

Re: Voice Phishing Scams Are Getting More Clever

#41

>That made Sasser pause. Wouldn’t an actual representative from Wells Fargo’s fraud division already have access to his current PIN? No, nobody has access to your PIN, if you forget it you need a new card.

> if you forget it you need a new card

That's not true- you can reset you PIN if you go to a physical Wells Fargo location, I've done it.

Re: Voice Phishing Scams Are Getting More Clever

#42
post #21

Earlier quoted context omitted.

It makes me laugh when my banks fraud department calls me and then asks me to verify myself to them by giving personal information before asking me questions. I usually laugh at them and tell them they they are the unverified party in this phone call, not me. I always pull up the website and confirm before telling them anything.

> I usually laugh at them and tell them they they are the unverified party in this phone call, not me. This is one of the related reasons why I finally got my ducks in a row and switched away from Chase three years ago. Their potential-fraud-has-happened outreach department was, in my experience, terrible about this. It didn't help that their potential-fraud-detection department was similarly bad. ("You used your deb…

("You used your debit card at an AM/PM in Washington State!!!!" Yes, I know, it is about 900 feet from my house; I go there regularly.)

Bank of America has an interesting optional feature where they geolocate the transaction, and if it's a certain distance away from your cell phone, it triggers the fraud process.

I think if more banks did this, it could cut down on a certain percentage of these problems.

The downside is that you have to trust your bank enough to let it track your phone 24/7. And having recently gone through the privacy notices of several of my bank apps and web sites, I'm not entirely sure that's a good idea, either.

Re: Voice Phishing Scams Are Getting More Clever

#43
post #16

How come in 2018 we can't get a reliable CallerID. Surely this is something that could be simply regulated. Perhaps there should be a few types of CallerID - verified, physical and nominated. Eg a company calls you with a verified ID (like TLS), a local number from a single line is physically authenticated and anything else is just a best guess. That way we can filter more reliably.

Most likely because majority of senate and congress-people want to always have option to hire cold calling companies to send their emergency message, be it some senator accused of using gov founds to sponsor his mistress or simply to get advantage in upcoming political race.

Re: Voice Phishing Scams Are Getting More Clever

#44

Who are the people manning the phones for the scam? Does it really pay better than a real job? I mean if you have the skills to scam like this you have skills that are valuable to legit business as well, no? I knew a few criminally-minded people back in high school and my early 20's (I don't associate with them anymore.) The thing that always stuck me about the "criminal mind" is that they were ready and willing to w…

Reply All decided to try to get to the bottom of a specific "tech support" scam, which might shed some light.

https://www.gimletmedia.com/reply-all/102-long-distance-part...

Re: Voice Phishing Scams Are Getting More Clever

#45

Earlier quoted context omitted.

> I usually laugh at them and tell them they they are the unverified party in this phone call, not me. This is one of the related reasons why I finally got my ducks in a row and switched away from Chase three years ago. Their potential-fraud-has-happened outreach department was, in my experience, terrible about this. It didn't help that their potential-fraud-detection department was similarly bad. ("You used your deb…

their potential-fraud-detection department was similarly bad. ("You used your debit card at an AM/PM in Washington State!!!!" Yes, I know, it is about 900 feet from my house; I go there regularly.) A year ago I had an awful experience with this. We were on vacation at Big Bend National Park, which is hours away from everything in southwest Texas. When trying to pay for breakfast, our card was denied. I tried to call…

As someone who travels in remote corners of deserts very frequently, I can say that you can never have too much water, fuel, or cash.

And when you're in a scrape, you can often barter with all three.

Re: Voice Phishing Scams Are Getting More Clever

#46

This is 100% destroying the phone for younger generations ... my kids answer nothing, not even my own phone calls because they set their phones on do not disturb to curb the endless robo, scam, and cold calls. If it wasn't for https://hiya.com/ , I'd be at the end of my wits. Seems like the number of fake calls has ramped up exponentially in the last months. I finally just set it up completely block all telemarketing…

Hiya looks interesting. How do they make money if the app is free? How does it work? The site doesn't really say how it does what it does.

Re: Voice Phishing Scams Are Getting More Clever

#47
post #37

The issue, as I understand it, is that the SS7 telephone network is completely insecure assuming that you have the ability to connect to it. Shady gateway providers will allow you the privilege, and once you're in, you can do just about anything. There is precious little within SS7 to prevent or respond to spoofing. It's a major nightmare for telephone companies.

How did spoofing work vis-a-vis those with 1-800 inbound lines? I was under the (mis?)impression that those users were protected against spoofing because they were (are?) billed by inbound call duration.

> It's a major nightmare for telephone companies.

Disagree. It's a bug for the telcos, and a major nightmare for the rest of us.

Re: Voice Phishing Scams Are Getting More Clever

#48
post #37

The issue, as I understand it, is that the SS7 telephone network is completely insecure assuming that you have the ability to connect to it. Shady gateway providers will allow you the privilege, and once you're in, you can do just about anything. There is precious little within SS7 to prevent or respond to spoofing. It's a major nightmare for telephone companies.

If it's "completely insecure," then why aren't there reports of people correctly dialing their banks phone number and being connected to a scammer?

Re: Voice Phishing Scams Are Getting More Clever

#49
post #7

I'll give you the flip side of the scammer's deterioration of trust in the phone... a few months back I got a phone call from what appeared to be my bank, and they were asking me about a fraudulent charge that I didn't recognize. Worried that this was the beginning of a scam, I delayed a bit on the phone while I logged in independently to my bank account... and lo, yes, indeed, there was a fraudulent charge to my acc…

Always remember that any legit financial institution will (should) have no problem giving you a case or reference number and letting you call back in to their public customer service number.

Re: Voice Phishing Scams Are Getting More Clever

#50

The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…

There is no way to fix the ability to spoof caller ID with the way SS7 is built. Not without breaking functionality to something like 85% of the installed base of PBX and phone switch equipment, most of which is anywhere from 10 to 45 years old. The legacy telco SS7 phone system needs to be burnt to the ground and rebuilt, but it never will be, because people have moved on to friend-opt-in based message platforms like whatsapp, signal, telegram, facebook messenger, and the domestic chinese equivalents (wechat etc).
Post reply on HN