Voice Phishing Scams Are Getting More Clever
81–90 of 226 posts
Re: Voice Phishing Scams Are Getting More Clever
#82The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…
Think of incoming CLID in the same way that you do email From: addresses. Often and easily faked. Funnily enough both my office PBX and SMTP daemon check incoming CLID/HELO and drop attempts to spoof their own identity. Its not a particularly sophisticated protection these days but is one of many, many rules. Actually, now I come to think of it, my firewalls also check for inbound IP spoofing on their own IPs.
As the OP stories highlight, your mental firewall must make you bail out when asked for your PIN, regardless of how legitimate things sound. The only thing that should ever request your PIN is a machine that you have stuffed your card in first. I'm pretty certain that CVV requests should also only ever come from vendors that you are buying from, not your bank.
Re: Voice Phishing Scams Are Getting More Clever
#83How come in 2018 we can't get a reliable CallerID. Surely this is something that could be simply regulated. Perhaps there should be a few types of CallerID - verified, physical and nominated. Eg a company calls you with a verified ID (like TLS), a local number from a single line is physically authenticated and anything else is just a best guess. That way we can filter more reliably.
Re: Voice Phishing Scams Are Getting More Clever
#84The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…
Re: Voice Phishing Scams Are Getting More Clever
#85The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…
Re: Voice Phishing Scams Are Getting More Clever
#86Earlier quoted context omitted.
How did spoofing work vis-a-vis those with 1-800 inbound lines? I was under the (mis?)impression that those users were protected against spoofing because they were (are?) billed by inbound call duration. > It's a major nightmare for telephone companies. Disagree. It's a bug for the telcos, and a major nightmare for the rest of us.
Having spent a bit of time working on projects that touch the phone network, I think it is a 'major nightmare' in the Lovecraftian sense--I for one am forever changed by what I saw. As for billing, it is usually based on the destination number, and your originating telco, unless I am misunderstanding your question.
Re: Voice Phishing Scams Are Getting More Clever
#87Earlier quoted context omitted.
If it's "completely insecure," then why aren't there reports of people correctly dialing their banks phone number and being connected to a scammer?
The insecurity comes from the fact that once a call is in the network, it is mostly passed off without validation or verification. You only need to find someone willing to carry your call in to the network, and the rest takes care of itself. To change the routing of a call other than yours would require you to access a carrier's systems and change where the call is routed to--which is substantially more difficult.
Re: Voice Phishing Scams Are Getting More Clever
#88Number one advice I give my family: never give out any information (no matter how inconsequential it seems) to a person purporting to be from a company calling you. Hang up and call the company yourself using a trusted number (e.g., the number on the back of a credit card).
Re: Voice Phishing Scams Are Getting More Clever
#89Earlier quoted context omitted.
There is no way to fix the ability to spoof caller ID with the way SS7 is built. Not without breaking functionality to something like 85% of the installed base of PBX and phone switch equipment, most of which is anywhere from 10 to 45 years old. The legacy telco SS7 phone system needs to be burnt to the ground and rebuilt, but it never will be, because people have moved on to friend-opt-in based message platforms lik…
I just want the major cellphone companies numbers to show up correctly and everything else can be ???. That does not require fixing all these other systems.
Find another in/out of band way of providing caller-ID services.
Re: Voice Phishing Scams Are Getting More Clever
#90The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…
The problem here is the ability to spoof caller ID. This should not be possible. Think of incoming CLID in the same way that you do email From: addresses. Often and easily faked. Funnily enough both my office PBX and SMTP daemon check incoming CLID/HELO and drop attempts to spoof their own identity. Its not a particularly sophisticated protection these days but is one of many, many rules. Actually, now I come to thin…