Live data from Hacker News

Voice Phishing Scams Are Getting More Clever

krebsonsecurity.com

101–110 of 226 posts

Re: Voice Phishing Scams Are Getting More Clever

#101
post #99
post #75

Earlier quoted context omitted.

I just want the major cellphone companies numbers to show up correctly and everything else can be ???. That does not require fixing all these other systems.

How exactly could they do that for calls originating outside their network? Most spammers are using VoIP, not cell phones on major US companies.

they can't, because as things currently exist they have to trust the caller ID data in the SS7 links coming from other wholesale carriers where the calls are coming from. possibly several hops away from the grey market voip sip trunking providers.

Re: Voice Phishing Scams Are Getting More Clever

#102
post #82

The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…

The problem here is the ability to spoof caller ID. This should not be possible. Think of incoming CLID in the same way that you do email From: addresses. Often and easily faked. Funnily enough both my office PBX and SMTP daemon check incoming CLID/HELO and drop attempts to spoof their own identity. Its not a particularly sophisticated protection these days but is one of many, many rules. Actually, now I come to thin…

A better analogy that I use (especially with nontechnical folks) is the return address on an envelope.

You can, technically, write anything in it and there’s no way to guarantee it’s authentic.

Re: Voice Phishing Scams Are Getting More Clever

#103
post #82

The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…

The problem here is the ability to spoof caller ID. This should not be possible. Think of incoming CLID in the same way that you do email From: addresses. Often and easily faked. Funnily enough both my office PBX and SMTP daemon check incoming CLID/HELO and drop attempts to spoof their own identity. Its not a particularly sophisticated protection these days but is one of many, many rules. Actually, now I come to thin…

The problem with SS7 is that you extend your SMTP analogy, there is no way to implement the equivalent of SPF, DKIM and DMARC for verification of incoming traffic without breaking SS7-to-SS7 links between the vast majority of installed phone switching gear out there on the PSTN. Which nobody wants to pay money to completely replace.

Re: Voice Phishing Scams Are Getting More Clever

#104
post #90
post #82

Earlier quoted context omitted.

The problem here is the ability to spoof caller ID. This should not be possible. Think of incoming CLID in the same way that you do email From: addresses. Often and easily faked. Funnily enough both my office PBX and SMTP daemon check incoming CLID/HELO and drop attempts to spoof their own identity. Its not a particularly sophisticated protection these days but is one of many, many rules. Actually, now I come to thin…

Curious: how does the PBX verify caller ID? Do you know how it works in practice?

It doesn't actually verify it, all it can do is read it. Just like email. When the PBX is told that the caller is say 01460223344 (I'm in the UK) then it would infer that the caller is from Crewkerne in Somerset due to the 01460 which is a designated area code. It may also be able to look up the whole number and infer a source.

However, just like email the CLID can be trivially faked and just like email, the lookup in your contacts is then wrong and potentially dangerous. In the case of telephony, if you subscribe to the BT service (I presume it still exists) that will return a name given a CLID (just like DNS for a price!) then you may end up with completely the wrong thing on your display.

Just to re-iterate the point: a PBX/phone/whatever cannot ... CANNOT ... verify CLID (Calling Line IDentification) it can only show what is presented to it.

Remember this, please: CLID is nominally under the control of the caller and could also be changed in transit. It should absolutely NOT be considered authoritative in any way.

Re: Voice Phishing Scams Are Getting More Clever

#105
post #7

I'll give you the flip side of the scammer's deterioration of trust in the phone... a few months back I got a phone call from what appeared to be my bank, and they were asking me about a fraudulent charge that I didn't recognize. Worried that this was the beginning of a scam, I delayed a bit on the phone while I logged in independently to my bank account... and lo, yes, indeed, there was a fraudulent charge to my acc…

For those worried about a situation like this, I set up automated purchase alerts on my credit cards and withdrawal alerts on my bank accounts. I see it all in close-enough-to-real-time, and it's helped me catch fraud before the banks did at least twice in the past few years.

People have a lot of reason to shit on wells fargo for its previousl unethical practices (loan scandals, etc), but they do have a good feature for email notifications of every individual transaction on a credit card or debit card. The emails are quick, too, if you take out cash from an ATM the email arrives at my mail server in less than 60 seconds.

Re: Voice Phishing Scams Are Getting More Clever

#106
post #37

The issue, as I understand it, is that the SS7 telephone network is completely insecure assuming that you have the ability to connect to it. Shady gateway providers will allow you the privilege, and once you're in, you can do just about anything. There is precious little within SS7 to prevent or respond to spoofing. It's a major nightmare for telephone companies.

It seems that what changed is that sometime in recent years it became much easier for shady gateway providers to remain in business. In earlier times, it would appear that originators of fraudlent caller ID data where shut down rapidly.

Re: Voice Phishing Scams Are Getting More Clever

#107
post #90

Earlier quoted context omitted.

Curious: how does the PBX verify caller ID? Do you know how it works in practice?

It doesn't actually verify it, all it can do is read it. Just like email. When the PBX is told that the caller is say 01460223344 (I'm in the UK) then it would infer that the caller is from Crewkerne in Somerset due to the 01460 which is a designated area code. It may also be able to look up the whole number and infer a source. However, just like email the CLID can be trivially faked and just like email, the lookup i…

It's not quite "Just like email" because email has systems in place to authenticate this, while phone systems do not.

https://en.wikipedia.org/wiki/DMARC

Re: Voice Phishing Scams Are Getting More Clever

#108
I've had an Asterisk box for about 10 years now, mostly to deal with the tide of junk calls, and it has worked nicely. I first just blacklisted numbers (and sometimes whole prefixes), but now I use a CAPTCHA that handles the robocallers beautifully. Calls from known numbers get to ring through without the CAPTCHA.

Still, I've been paying too much for that crusty old landline, and finally got motivated to do something about it. I just ported it out last month, and the new VoIP service I'm using costs less per month than what AT&T was charging just for Caller ID. Even funnier, they offer telemarketer blocking like I've set up, at no extra charge.

Farewell and f*ck you very much, AT&T. You didn't even lift a finger to insure that the Caller ID I paid for was accurate.

Re: Voice Phishing Scams Are Getting More Clever

#109
post #102
post #82

Earlier quoted context omitted.

The problem here is the ability to spoof caller ID. This should not be possible. Think of incoming CLID in the same way that you do email From: addresses. Often and easily faked. Funnily enough both my office PBX and SMTP daemon check incoming CLID/HELO and drop attempts to spoof their own identity. Its not a particularly sophisticated protection these days but is one of many, many rules. Actually, now I come to thin…

A better analogy that I use (especially with nontechnical folks) is the return address on an envelope. You can, technically, write anything in it and there’s no way to guarantee it’s authentic.

In email the From: address rarely delivers the mail. From: and To: are the ones that you see in your mail client and correspond to the addresses on the letter within.

For example here are some headers from some spam I received:

  From: "Jeremy Adamson" 
  Reply-To: "Jeremy Adamson" 
From: is what I see in my client and Reply-To: is where a reply would go to.

This one is much better, note how I'm BCCd and To: is complete bollocks:

  Reply-To: dr.ahmed.faruk@outlook.com
  From: Dr Faruk Ahmed 
  Subject: MANAGER AUDIT AND ACCOUNT DEPT
  To: undisclosed-recipients:;
  BCC: 
  Return-Path: dr.faruk.ahmed1@gmail.com
Given that Reply-To and Return-Path are in different domains, where would a reply go to?

Re: Voice Phishing Scams Are Getting More Clever

#110
I'm personally somewhat nervous about what voice phishers will be able to accomplish with call ID once voice sample synthesis gets good enough and cheap enough, which is well on the way from what I can tell. Shades of that old Uplink game, call up a family member or friend and just get them to talk into the phone at all, not even give up personal information but literally just speak enough. Then the phisher can call up the target, spoof that number, and directly have the voice sound just like someone the target knows. The voice and the Call ID will both check out, and this should actually be a lower target then the kind of voice synthesis work currently being done because phone calls are highly compressed and tend to be not great quality anyway.

Once that hits general usage along with the kind of ML and social network graphs being done up couldn't that just plain be it for phone usage if companies can't come up with a proper cryptographically verified call scheme (which would require new phones, for everyone)? I mean, if a call coming in directly from a "trusted contact's number" that is literally in their voice becomes generally a scam too I think that'd have to be a real tipping point for the general population. I can't see any choice at that point but to disable all incoming calls period, and move my family over to something else as well. And that tech train is coming down the tracks pretty fast, there have to be at least some phone providers who can see that right? Heavily automatically run personalized ML powered social media and ad network profile fed phishing calls in a relative's voice, yeah that'll be really fun.

Post reply on HN