Live data from Hacker News

Voice Phishing Scams Are Getting More Clever

krebsonsecurity.com

211–220 of 226 posts

Re: Voice Phishing Scams Are Getting More Clever

#211
post #210

Earlier quoted context omitted.

Yeah I get spam phone calls almost daily, and it's always from a local area code and ANI which I recognize as being from a nearby city. So, it _seems_ legit. But I no longer answer phone calls from numbers I don't already have in my Contacts... :P

One thing I hadn’t thought of until a friend who is a parent mentioned it, is that if you have a young child and that child is currently out of your sight you basically have to pick up a call from any possibly local number, it’s just too risky not to. I would imagine that accounts for a lot of the success of this strategy.

I inadvertently solved this by keeping my old, out of state number. I can pretty much block all numbers that match my prefix if they aren't in my contacts.

Any actual local number is always legit since spammers have no way of knowing where I actually live.

Re: Voice Phishing Scams Are Getting More Clever

#212
post #196

Earlier quoted context omitted.

On my particular Android phone (Pixel) this is not a great solution because setting Do Not Disturb alters the behavior of other things like Calendar reminders or email alerts. You could make DND not do that, but sometimes I do want to mute other things. If you're using DND all the time, you essentially lose that feature on your phone. The best solution I've found is to just go into the Google Dialer app and set the o…

A great improvement to that would be an option to silently reject all suspected spam calls and send them to the voicemail. This has been suggested many times on Google's product feedback and suggestion boards but for some reason they have not gotten around to doing it. The hard part of detecting spam calls is already there; all it should take is adding a couple of new check boxes.

There are apps like youmail and nomorerobo. I use youmail and it has the option to give a disconnected message when a scammer calls.

Re: Voice Phishing Scams Are Getting More Clever

#213
post #64

Earlier quoted context omitted.

> I usually laugh at them and tell them they they are the unverified party in this phone call, not me. This is one of the related reasons why I finally got my ducks in a row and switched away from Chase three years ago. Their potential-fraud-has-happened outreach department was, in my experience, terrible about this. It didn't help that their potential-fraud-detection department was similarly bad. ("You used your deb…

I pointed out, each time, that they were the ones who called me so I should be verifying them. "But, sir, WE are the bank and you could be anyone who just answered your phone." There has got to be a word for this and similar behavior. Banks, credit card agencies, mobile phone companies are getting really aggressive with how they handle these sort of transaction based interactions and I'm leaning towards wanting to se…

The reason they are asking you why you missed a payment is because creditors have hardship payment plans for people in certain hardships. They were trying to see if you were eligible.

Re: Voice Phishing Scams Are Getting More Clever

#214

Earlier quoted context omitted.

> I usually laugh at them and tell them they they are the unverified party in this phone call, not me. This is one of the related reasons why I finally got my ducks in a row and switched away from Chase three years ago. Their potential-fraud-has-happened outreach department was, in my experience, terrible about this. It didn't help that their potential-fraud-detection department was similarly bad. ("You used your deb…

their potential-fraud-detection department was similarly bad. ("You used your debit card at an AM/PM in Washington State!!!!" Yes, I know, it is about 900 feet from my house; I go there regularly.) A year ago I had an awful experience with this. We were on vacation at Big Bend National Park, which is hours away from everything in southwest Texas. When trying to pay for breakfast, our card was denied. I tried to call…

This is the reason I always travel with >1 debit cards (different banks) and >1 credit cards (different banks)

Re: Voice Phishing Scams Are Getting More Clever

#215

Earlier quoted context omitted.

As someone who travels in remote corners of deserts very frequently, I can say that you can never have too much water, fuel, or cash. And when you're in a scrape, you can often barter with all three.

My wife and I (we are both Brits) were driving in the middle of nowhere in Washington state. We stopped at a garage to get petrol/gas and discovered that the credit card machines in the unmanned gas station only seemed to accepted credit cards issued in the US - IIRC the PIN equivalent was a US zip code. Our personal credit cards (UK cards) and cash (no teller) were thus useless. Luckily my wife had a corporate credi…

For foreign credit cards oftentimes entering 00000 or 99999 for zip code works.

The other thing that sometimes works is entering the digit part of your postal code and padding it out with zeros. Ex: if your postal code was 1A2B3C you'd enter 12300.

Re: Voice Phishing Scams Are Getting More Clever

#216
post #91

If I were able, I would disable incoming telephone calls entirely (consider that a feature request, Apple). The phone system today is fundamentally untrustworthy because of caller ID spoofing, and the phone companies involved are culpable for not addressing this problem. A new ID system using PKI could eliminate the spoofing problem completely. Yes, I'm sure it would require a huge coordinated effort. Given spam call…

Public-key identity verification wouldn't even require substantial upgrades to anything except the phone hardware itself - when making the call, just convey the signature upon connection via a dialup-modem-like encoding, and the receiver may at their discretion neglect to connect their audio hardware to the line until after verifying that data.

(Could even use some kind of PoW as another option, for calls where the receiver is unlikely to have received your public key yet.)

Re: Voice Phishing Scams Are Getting More Clever

#217

Earlier quoted context omitted.

If it's "completely insecure," then why aren't there reports of people correctly dialing their banks phone number and being connected to a scammer?

It's completely insecure because someone could call you, spoof your bank's number, and claim to be your bank.

http - ISP injects sales/billing garbage in the response. Completely insecure!

phone - I dial the number my bank gave me and no man in the middle ever answers or interrupts. But still completely insecure!

Now imagine you see me trying to enter my credentials over an http connection to AwfulBank.com. "Stop! That's completely insecure!" you say. "Sure, but so is calling a bank using the phone number they gave me."

If both cases are already completely insecure, why am I wrong?

Re: Voice Phishing Scams Are Getting More Clever

#218
post #78

Earlier quoted context omitted.

Card fuckup is the only reason I have even a little cash on hand. Even the second hand store near me takes cards now. It is my policy if I am any distance from home to carry a spare car key, and enough cash to fill the tank and get home. Considering that we could eliminate fraud with a private key chip card, this is really, really sad.

Another reason to have some cash is so if you're mugged, the mugger won't be so disappointed they take it out on you.

Oh I don't carry the cash on me.

I probably should worry more about muggers, but I just can't get myself to be afraid, so.

Re: Voice Phishing Scams Are Getting More Clever

#219

Earlier quoted context omitted.

Could you please point to guides / docs / references for setting this up? Might make some good HN submissions ;-)

Here's a good starting point: http://nerdvittles.com/?p=75 Of course, with Asterisk, you can get downright crazy if you wish.

A bit more a "getting started" guide than this, actually.

Hardware, configuration, concepts.

Re: Voice Phishing Scams Are Getting More Clever

#220

Earlier quoted context omitted.

Another reason to have some cash is so if you're mugged, the mugger won't be so disappointed they take it out on you.

Oh I don't carry the cash on me. I probably should worry more about muggers, but I just can't get myself to be afraid, so.

It's fairly common to read a story about how some carjackers abandoned a car because it unexpectedly had a manual transmission, but I think I also read about a case where they shot the driver out of pique.
Post reply on HN