Live data from Hacker News

Voice Phishing Scams Are Getting More Clever

krebsonsecurity.com

131–140 of 226 posts

Re: Voice Phishing Scams Are Getting More Clever

#131

The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…

> Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a number they provide over the phone or in caller ID. I did this to a student loan company. The caller ID was that of my parent's house, and the woman on the other end was incredulous that anyone would demand that she prove who she was. And it turned out to be legitimate, incredibly, t…

If you can actually identify the company or individual on the other end of a spoofed call, please report them to the FCC.

Re: Voice Phishing Scams Are Getting More Clever

#132

Earlier quoted context omitted.

It's not quite "Just like email" because email has systems in place to authenticate this, while phone systems do not. https://en.wikipedia.org/wiki/DMARC

Have you ever tried to implement DMARC? DKIM and SPF are OK but DMARC breaks mail lists. Yes there are ways to mitigate but it might not be worth it unless you also do DNSSEC as well. Well actually I believe that every little helps and use every weapon available. I do think that the analogy works really well. PBXs can have quite a few weapons of their own to attempt to authenticate callers. For example you can pass "…

I haven't set it up, but how does it break mail lists? Do you mean like using third party providers to send emails with your own domain in the From address?

Re: Voice Phishing Scams Are Getting More Clever

#133
I am interested to understand how does these attacks work. The article states, after the victim disclosed the CC number there were ATM transactions performed using it.

How are scammers able to generate a physical card in first place to perform ATM transaction? Is it something similar to card skimming with cards having magnetic stripe? Can this attack be performed with cards using chips?

Also I often come across a fraudulent transaction being performed even if only credit card number is disclosed, while cvv and expiry date are not. As per my understanding all 3 info is needed to perform a transaction.

Do anyone have some resource where these attacks are discussed in detail and how they are carried out.

Re: Voice Phishing Scams Are Getting More Clever

#134

What do I have to do to get my iPhone to only allow calls from my contact list, without using DND 24x7. Something has to happen for this setting to come out. Will it take enough spam calls to a CEO of a major company to come out with it?

NumberShield lets you block wildcards while letting your contacts through.

It won’t let you specify a ‘global’ wildcard, but I find blocking my own area code is generally sufficient. Most scammers and spammers spoof your local area code these days, and Nomorobo is pretty good at filtering out those that don’t.

Between those two apps, I go months without unwanted calls. I used to get them daily.

Re: Voice Phishing Scams Are Getting More Clever

#135
One of the issues is that the scams adapt themselves to current "best practices" (use known information to reassure you, tell you not to divulge other pieces of information) - whereas the legitimate institutions use poor practices.

When I call my bank, they ask for verification by giving an account number, credit card and expiry details (!)

Re: Voice Phishing Scams Are Getting More Clever

#136

The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…

> don't call a number they provide over the phone

It's OK to ask for their extension. A lot of times you can't call the fraud department directly, but if you have their extension you can ask to be transferred to it. But yeah, always call the number printed on the card, not what they tell you.

Re: Voice Phishing Scams Are Getting More Clever

#137
Good news, everyone, the industry is moving towards SIP! Bad news is that it's just as bad. There's no improvements in security because that would break backwards compatibility.

Also, there's no one who wants to pay extra for security, and the telecoms industry have the virtue of laser-like focus on money.

Re: Voice Phishing Scams Are Getting More Clever

#138

Earlier quoted context omitted.

their potential-fraud-detection department was similarly bad. ("You used your debit card at an AM/PM in Washington State!!!!" Yes, I know, it is about 900 feet from my house; I go there regularly.) A year ago I had an awful experience with this. We were on vacation at Big Bend National Park, which is hours away from everything in southwest Texas. When trying to pay for breakfast, our card was denied. I tried to call…

As someone who travels in remote corners of deserts very frequently, I can say that you can never have too much water, fuel, or cash. And when you're in a scrape, you can often barter with all three.

If you're visiting remote parts of Texas, always have a hat with a brim (there's a reason that cowboy hats are shaped the way they are), bottled water, and a few hundred dollars in cash.

Re: Voice Phishing Scams Are Getting More Clever

#139
post #99
post #75

Earlier quoted context omitted.

I just want the major cellphone companies numbers to show up correctly and everything else can be ???. That does not require fixing all these other systems.

How exactly could they do that for calls originating outside their network? Most spammers are using VoIP, not cell phones on major US companies.

They could not fix it. However, it would be a big value-add to me if, say, the big 4 US carriers could add an out-of-band security check and block calls to their networks from numbers they control but which are spoofed.

I get way too many calls from area codes and prefixes I recognize. This would help me get some of that back.

Re: Voice Phishing Scams Are Getting More Clever

#140
post #138

Earlier quoted context omitted.

As someone who travels in remote corners of deserts very frequently, I can say that you can never have too much water, fuel, or cash. And when you're in a scrape, you can often barter with all three.

If you're visiting remote parts of Texas, always have a hat with a brim (there's a reason that cowboy hats are shaped the way they are), bottled water, and a few hundred dollars in cash.

I would add Imodium AD, analgesics, some power bars and jerky, condoms, tampons if you’re female or traveling with women, a compass, weatherproof matches, a small mirror, and a good knife.
Post reply on HN