Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

31–40 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#32

If someone is asking you the PIN so they can confirm it is you, you can ask them to give you the PIN so that you can tell if it matches or not.

That PIN should not even be readable information. It's a password. It should be salted and hashed. It should be useless for any kind of over-the-phone confirmation of your identity.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#33
I don't understand why there are still banks that do SMS verification. It has been proven so many times now that that it is vulnerable to both phishing (proven here), sim swapping attacks, etc.

The banks here in the Netherland all have (well, except for one maybe) hardware authentication devices. They are portable smartcard readers, you insert your card, enter your PIN on the device itself (not your computer or phone) and transfer a digest from your PC to the reader by typing or scanning a QR code (some readers have a little camera). You then type the signature into your computer or phone.

The readers for my bank even have a screen, that tells you what you are signing, like a login, or transfer of which amount to which bank account. Photo here [0].

The banks are very clear that they will never ask you to use the device over the phone. And that double confirmation by showing the sign action on the screen of the reader makes any form of phishing really hard.

IMO these smart card readers are the best compromise between convenience and security for banking.

[0] https://4.bp.blogspot.com/-6c1NGHew1P8/VBqvTeqDQdI/AAAAAAAAf...

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#34

It sounded sketchy from the moment they asked for a pin code that they sent to your phone. It's easier to talk from the outside, but that should always be a red flag. What exactly would they be confirming by sending a PIN to the same number they were already contacting? But that's a great heads up. Phishing is not just about obviously fake e-mails to hotmail accounts.

There's so many outside circumstances that might even make a technically adept person like the original poster fall for this: bad day at work, fight with the girlfiend, getting called in traffic, having loud kids playing at home, not feeling well, etc.

Like you said, spam and phising used to be obviously bad but I'm afraid I'm going to fall for it some day now.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#35
post #19
post #13

Who does "Phishing protection as a Service"? Like, a line you can call and ask "Is this legit?" .

Your bank. If someone rings you claiming to be from them, you hang up and call the phone number printed on the back of your card.

My bank has terrible call waiting lines and they even overcharge for it! And it's not just banks that are being phished

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#36
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

As a child in Sweden in the late 90s and early 2000s I recall that my dad had a hardware token to access his bank account. Though nowadays people in Sweden use BankID for the most part which is 2FA in the form of a mobile app. BankID is also used to login to most government websites in Sweden which is nice.

Meanwhile, banking security in the US is stuck in the Stone Age. Last I checked Wells Fargo, one of the largest US banks, still does not allow passwords greater than 14 characters in length and passwords are not case sensitive.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#37

My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phish…

Good idea - but here in the UK there was a scam where they called you and THEN suggested you call the number on the back of the card.

They then don't hang up, but play a dialling tone down the line until you dial the number. At which time they 'answer'. This only works on home phones, not mobile, but is worth considering, and warning your family/friends about.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#38

The easiest way to avoid this entire class of attack, is to never be willing to answer any kind of question from someone who calls you. Always hang up, Google the customer support line for the business, then call them .

Yeah but people expect when calling a business to be put on hold for 20 minutes and be dicked around on a phone tree. They don't want to deal with that.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#39
post #23

It's even worse in Russia - fake caller ID makes you think you are talking with the bank, mobile phone operators don't seem to be doing much, or at least didn't a couple of months ago. That said, all the banks I used send you along with the confirmation code a description of what you are actually confirming.

>> mobile phone operators don't seem to be doing much

It is in the protocol. Operators are not the only problem here.

https://en.wikipedia.org/wiki/Caller_ID_spoofing

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#40

The easiest way to avoid this entire class of attack, is to never be willing to answer any kind of question from someone who calls you. Always hang up, Google the customer support line for the business, then call them .

There was a widespread phishing attack in the UK that used this approach.

On UK landlines the call is not terminated until the person who made the call hangs up. That is to say if I call you, you answered and then hung up, then waited a minute and picked up the phone again, I'd still be there and the connection still made.

Scammers phoned people, told them there is an account issue and to phone the number on the reverse of their credit or debit card. The scammers keep the line open and play a recording of a dial tone to the target phoning back and then go through garnering all the details needed to rinse the accounts.

I believe in response UK phone networks are implementing time limits on one sided terminations

Post reply on HN