Live data from Hacker News

Voice Phishing Scams Are Getting More Clever

krebsonsecurity.com

201–210 of 226 posts

Re: Voice Phishing Scams Are Getting More Clever

#201
post #197

This is 100% destroying the phone for younger generations ... my kids answer nothing, not even my own phone calls because they set their phones on do not disturb to curb the endless robo, scam, and cold calls. If it wasn't for https://hiya.com/ , I'd be at the end of my wits. Seems like the number of fake calls has ramped up exponentially in the last months. I finally just set it up completely block all telemarketing…

Another typical problem with the American system of deregulating everything and anything. In Europe (at least the parts I know) this is never an issue.

This is regulated in the US. You're not allowed to spam calls nor fraudulently impersonate someone's bank, the IRS, a healthcare provider, a collections agency, etc. There are dedicated lines for reporting these types of calls to the FTC, a nation Do Not Call registry.

I can't speak to the manpower dedicated to nor the pursuit of these reports by the FTC, but this is definitely a regulated issue.

Re: Voice Phishing Scams Are Getting More Clever

#202
post #160

Earlier quoted context omitted.

> The problem with SS7 is that you extend your SMTP analogy, there is no way to implement the equivalent of SPF, DKIM and DMARC for verification of incoming traffic without breaking SS7-to-SS7 links between the vast majority of installed phone switching gear out there on the PSTN. Why not? That's how it was done for email. SPF doesn't prevent interoperability for sending domains that don't use it or recipients that d…

Because it's a huge installed base of non-upgradeable equipment that is 15, 20, 25 years old. People doing oldschool SS7 telco stuff are just not going to upgrade. They'll sue their upstream carriers if they suddenly cut them off because their new re-implementation of SS7 is incompatible with their old gear. I'm a senior network engineer for a mid sized regional ISP, and encounter this shit on a fairly regular basis.…

When you get a scam call, you know that somewhere there is a company that got paid for that call, because telcos -- even and really especially scummy shady scam-enabling telcos -- don't offer access to their network for free out of the goodness of their hearts.

Turning those companies into smoking holes in the ground doesn't require anyone to upgrade their equipment. All it takes is willingness on the part of lawmakers and regulators to track them down and make them regret their business practices.

Re: Voice Phishing Scams Are Getting More Clever

#203

Earlier quoted context omitted.

Could you please point to guides / docs / references for setting this up? Might make some good HN submissions ;-)

Here's a good starting point: http://nerdvittles.com/?p=75 Of course, with Asterisk, you can get downright crazy if you wish.

Yeah, I'd like to start simple, basic, and effective.

Re: Voice Phishing Scams Are Getting More Clever

#204

Can anyone offer any insight into the latest series of odd phone calls I've been noticing, where you get either a private number or an out-of-state number call you, and then sit in silence until you utter a word in which it hangs up at that moment? I've experienced a few so far over the previous months. I've even experimented by not saying anything for an extended time - up to about 30 seconds of silence (and then it…

One reason for calls that get instantly disconnected is that when these systems will call up, say, 10 people at a time, 8 won't answer, so there's no reason to tie up 10 operators waiting for someone to answer. So they don't connect you to an operator until you actually pick up the phone/interact. But if they miscalculated and 4 people answered, they don't have enough operators and they just hang up.

Re: Voice Phishing Scams Are Getting More Clever

#205

The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…

I did this to my bank. They called me, I told them that I'll not talk to them as I can't identify them and that I'll call them back in standard number. Bank was really not prepared for this. They blocked my card (call was about suspicious transaction that was ok) and the transaction. I called to unblock transaction, but card remained blocked. So I had to call again.

It all took precious time, they really should anticipate this more.

Re: Voice Phishing Scams Are Getting More Clever

#206

Can anyone offer any insight into the latest series of odd phone calls I've been noticing, where you get either a private number or an out-of-state number call you, and then sit in silence until you utter a word in which it hangs up at that moment? I've experienced a few so far over the previous months. I've even experimented by not saying anything for an extended time - up to about 30 seconds of silence (and then it…

One reason for calls that get instantly disconnected is that when these systems will call up, say, 10 people at a time, 8 won't answer, so there's no reason to tie up 10 operators waiting for someone to answer. So they don't connect you to an operator until you actually pick up the phone/interact. But if they miscalculated and 4 people answered, they don't have enough operators and they just hang up.

Interesting, I wasn't aware this could be the case.

Re: Voice Phishing Scams Are Getting More Clever

#207

The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…

Yeah I get spam phone calls almost daily, and it's always from a local area code and ANI which I recognize as being from a nearby city. So, it _seems_ legit. But I no longer answer phone calls from numbers I don't already have in my Contacts... :P

In my case I have a bit of an outlier combination so it never seems legit when I get a call from a number like that. Makes it easier to spot the spammers, however!

Re: Voice Phishing Scams Are Getting More Clever

#208

Earlier quoted context omitted.

their potential-fraud-detection department was similarly bad. ("You used your debit card at an AM/PM in Washington State!!!!" Yes, I know, it is about 900 feet from my house; I go there regularly.) A year ago I had an awful experience with this. We were on vacation at Big Bend National Park, which is hours away from everything in southwest Texas. When trying to pay for breakfast, our card was denied. I tried to call…

As someone who travels in remote corners of deserts very frequently, I can say that you can never have too much water, fuel, or cash. And when you're in a scrape, you can often barter with all three.

My wife and I (we are both Brits) were driving in the middle of nowhere in Washington state. We stopped at a garage to get petrol/gas and discovered that the credit card machines in the unmanned gas station only seemed to accepted credit cards issued in the US - IIRC the PIN equivalent was a US zip code. Our personal credit cards (UK cards) and cash (no teller) were thus useless. Luckily my wife had a corporate credit card issued in the US that we were able to use, on the principle that she could ask for forgiveness from her company when we got back.

Re: Voice Phishing Scams Are Getting More Clever

#209
Well, I think these scammers will always try to steal our money by using hundreds of methods and tricks. Almost everyday I could read dozens of complaints and reports filed at social media and also sites like http://whycall.me about phone scams. We need to keep informing our family about these scams. They are never getting tired of trying.

Re: Voice Phishing Scams Are Getting More Clever

#210

The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…

Yeah I get spam phone calls almost daily, and it's always from a local area code and ANI which I recognize as being from a nearby city. So, it _seems_ legit. But I no longer answer phone calls from numbers I don't already have in my Contacts... :P

One thing I hadn’t thought of until a friend who is a parent mentioned it, is that if you have a young child and that child is currently out of your sight you basically have to pick up a call from any possibly local number, it’s just too risky not to. I would imagine that accounts for a lot of the success of this strategy.
Post reply on HN