Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

11–20 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#15
One I almost fell for, was a tab that changed to a Gmail login screen in the background. When I switched to it, I thought I had gotten logged out and entered my password. Luckily 2fa saved me. Did not use a pwd-manager at the time, that also would probably have prompted some red flags when it didn't auto-fill.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#16
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

This is so true. My wife (US) just needs user+pwd to access her bank. Me (Italy), had physical tokens or at least SMS 2fa for years. Also EU is now going through a major security upgrade for banks with SCA (Strong Customer Authentication)

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#17
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

Oh it gets worse.

My UK bank had a hardware token for years. They recently "upgraded" my security for online banking, and now use SMS 2FA codes for login and authorising new transfers. The hardware token is now unusable.

I'd change banks, but I doubt the others are better.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#18
This is partly an issue with phone calls as a medium. If the bank only contacted you through the app, this couldn't happen unless the app itself was compromised somehow.

E.g., the Monzo app has a chat functionality built in. If, upon a fraud attempt, a notification appeared in the Monzo app, it would certainly be legitimate.

If the ease of conversation offered by chatting with voice is necessary, add a link in the chat that has the user call the bank, not the other way around.

You can't easily verify that someone is who they say they are over the phone.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#19
post #13

Who does "Phishing protection as a Service"? Like, a line you can call and ask "Is this legit?" .

Your bank. If someone rings you claiming to be from them, you hang up and call the phone number printed on the back of your card.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#20
When sending SMS or other notifications, always include the purpose. "You requested a password reset, the PIN to completel the reset is 112938181".

Ideally the pins are also in different formats, so your normal PIN to login is a 6 digit number, the password reset is a 12 digit alphanumeric.

Post reply on HN