Live data from Hacker News

Voice Phishing Scams Are Getting More Clever

krebsonsecurity.com

51–60 of 226 posts

Re: Voice Phishing Scams Are Getting More Clever

#51
post #36

Earlier quoted context omitted.

For those worried about a situation like this, I set up automated purchase alerts on my credit cards and withdrawal alerts on my bank accounts. I see it all in close-enough-to-real-time, and it's helped me catch fraud before the banks did at least twice in the past few years.

Also, for anyone that doesn't know: you can request an old school ATM card (not a debit card, i.e. no MC/Visa logo) from your bank and use a credit card for purchases instead. This reduces the exposure of a critical account. And if you do become a victim of fraudulent charges, you don't have to worry about your bank account being drained immediately (possibly resulting in overdrafts, etc).

Card skimming has become so rampant where I live that I don't ever put a bank or credit card in a gas pump.

I got a gas company card (non-Visa/MC) with a super-low limit, and when I need to buy gas I make a payment online with my phone, then pump away knowing if it got skimmed, the perps would probably throw the info out because it's not usable anywhere else, and even if they used it at the gas station, they'd only get $10.

The local sheriff was on TV last year telling everyone to only pay cash for gas — never put a credit or debit card in a gas pump card reader.

Re: Voice Phishing Scams Are Getting More Clever

#52
post #46

This is 100% destroying the phone for younger generations ... my kids answer nothing, not even my own phone calls because they set their phones on do not disturb to curb the endless robo, scam, and cold calls. If it wasn't for https://hiya.com/ , I'd be at the end of my wits. Seems like the number of fake calls has ramped up exponentially in the last months. I finally just set it up completely block all telemarketing…

Hiya looks interesting. How do they make money if the app is free? How does it work? The site doesn't really say how it does what it does.

They have a premium subscription detailed here: https://hiyahelp.zendesk.com/hc/en-us/articles/360000872947-...

Re: Voice Phishing Scams Are Getting More Clever

#53

This is 100% destroying the phone for younger generations ... my kids answer nothing, not even my own phone calls because they set their phones on do not disturb to curb the endless robo, scam, and cold calls. If it wasn't for https://hiya.com/ , I'd be at the end of my wits. Seems like the number of fake calls has ramped up exponentially in the last months. I finally just set it up completely block all telemarketing…

I don't know the end game here. It's easy to say that phone calls as a medium just slides into oblivion and this all becomes academic. But I don't really believe that. There's a real and continuing place for voice conversations and that requires someone to initiate a call.

Eliminating spoofing is probably impossible without infrastructure revamps that aren't realistic even augmenting with spam filtering at the telco level. But the current situation is at the edge of the tolerable and people will just stop letting calls ring through.

Re: Voice Phishing Scams Are Getting More Clever

#54

What do I have to do to get my iPhone to only allow calls from my contact list, without using DND 24x7. Something has to happen for this setting to come out. Will it take enough spam calls to a CEO of a major company to come out with it?

Set your default ringtone to a minute of silence.

Set a custom ringtone for people you will accept calls from.

Re: Voice Phishing Scams Are Getting More Clever

#55
post #21

Earlier quoted context omitted.

It makes me laugh when my banks fraud department calls me and then asks me to verify myself to them by giving personal information before asking me questions. I usually laugh at them and tell them they they are the unverified party in this phone call, not me. I always pull up the website and confirm before telling them anything.

> I usually laugh at them and tell them they they are the unverified party in this phone call, not me. This is one of the related reasons why I finally got my ducks in a row and switched away from Chase three years ago. Their potential-fraud-has-happened outreach department was, in my experience, terrible about this. It didn't help that their potential-fraud-detection department was similarly bad. ("You used your deb…

> ... Chase ... It didn't help that their potential-fraud-detection department was similarly bad

I dropped Chase after about the 4th time they flagged my monthly payment to my ISP as potential fraud.

Re: Voice Phishing Scams Are Getting More Clever

#56
post #3

The sad thing is that I am old enough to remember when a call from the bank meant that the director of my local branch office or however someone I knew personally was on the phone, usually to ask to go to their offices because something needed my presence/signature.

I remember that, too. I was a huge deal if a bank called you.

Now, when I go into a Chase or Citibank or whatever branch with a question, all the "banker" guy does is call the same 800 number I would have called, and wait on the same 40 minute hold as I would have. They don't even have special in-house IVR anymore.

Meanwhile, I drink all their free coffee.

Re: Voice Phishing Scams Are Getting More Clever

#57
post #37

The issue, as I understand it, is that the SS7 telephone network is completely insecure assuming that you have the ability to connect to it. Shady gateway providers will allow you the privilege, and once you're in, you can do just about anything. There is precious little within SS7 to prevent or respond to spoofing. It's a major nightmare for telephone companies.

> Shady gateway providers will allow you the privilege,

Then those shady providers should be liable under proximate cause for when peoples' accounts get looted. If they weren't able to spoof valid-looking numbers, the frauds would be more difficult to perform.

Re: Voice Phishing Scams Are Getting More Clever

#58

What do I have to do to get my iPhone to only allow calls from my contact list, without using DND 24x7. Something has to happen for this setting to come out. Will it take enough spam calls to a CEO of a major company to come out with it?

I like this but it will only help a little and temporarily. I've received calls from my own number. Given the amount of data out there in social media and seeing friends of friends, the scammers will be able to call you from a number that is in your contact list. The phone system needs a new layer but one that is optional. If a call comes from via the old layer, your phone warns you that this call may be fraud.

Re: Voice Phishing Scams Are Getting More Clever

#59

This is 100% destroying the phone for younger generations ... my kids answer nothing, not even my own phone calls because they set their phones on do not disturb to curb the endless robo, scam, and cold calls. If it wasn't for https://hiya.com/ , I'd be at the end of my wits. Seems like the number of fake calls has ramped up exponentially in the last months. I finally just set it up completely block all telemarketing…

It's completely destroyed the phone for me... I get about 10 calls a day from scams. I don't answer my phone anymore unless it's from a number I already have programmed. Once the scammers get a hit on some of those numbers my phone is toast.

Re: Voice Phishing Scams Are Getting More Clever

#60

The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…

There is no way to fix the ability to spoof caller ID with the way SS7 is built. Not without breaking functionality to something like 85% of the installed base of PBX and phone switch equipment, most of which is anywhere from 10 to 45 years old. The legacy telco SS7 phone system needs to be burnt to the ground and rebuilt, but it never will be, because people have moved on to friend-opt-in based message platforms lik…

Yeah, it's hard not to think that basically rebuilding the entire phone system would be a massive case of fighting the last war. People won't stop needing the phone system entirely but it becomes a piece of quirky legacy technology.

And probably just have to live with the fact that there will be situations where people are harder to reach quickly than they are today.

Post reply on HN