Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

51–60 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#51
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

> Last time I needed a new token issuer dongle, I had to actually visit the bank and sign stuff. I'm glad UK banks try to avoid physical dongles because having to go to the bank and sign stuff to get one is not always convenient, not to mention you need to carry around the dongle everywhere, and if you lose it while you're in vacation it's yet more troubles. Phone 2FA would be good but a bit pointless because the 2FA…

> Phone 2FA would be good but a bit pointless because the 2FA app is on the phone, and so is the banking app.

This is exactly like having a physical token with you. If it gets stolen, they have the tokens. But, at least, having token on the phone app is waymore convenient for customers and also has another layer of protection (think of the fingerprint/passcode ecc you need to access your phone)

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#52

My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phish…

This is probably the best security technique in terms of simplicity vs effectiveness, one that everyone and their grandma can use. I wish there was more effort in educating people to use it.

I even remember a thread here in HN were one three-letter agency authenticated themselves to a user with this method, calling his numbers and saying, this is the FBI/NSA/etc but for you to be sure, please hang, look the website for the public number, call, and ask to be put through with $Agent from $Department.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#53

The easiest way to avoid this entire class of attack, is to never be willing to answer any kind of question from someone who calls you. Always hang up, Google the customer support line for the business, then call them .

How easy would it be for an attacker to (at least temporarily) outrank the bank in SEO so that when people google the bank's number they find the top result being the attacker's number?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#55

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

> It is better if [...anyone...] include a security warning / specific reason the code is sent with the password reset pins and similar credentials.

I think anyone building such systems (either via e-mail or SMS or whatever) should at least remember THIS.

Send something like this via SMS:

> The password reset code you requested via our website is 12345. We will never ask you for this code except when you requested a password reset.

1. What is requested 2. How was it requested 3. Is it safe to pass this to some other human being

Okay, 4. in better English ;) As opposed to:

> Your caller verification code is 12345, please read this code to your banking agent to verify your identity.

Also, ChipTAN is great: https://en.wikipedia.org/wiki/Transaction_authentication_num... If your bank would use this, it would be require extraordinary smart social engineering (or a really naive user).

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#56
post #37

My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phish…

Good idea - but here in the UK there was a scam where they called you and THEN suggested you call the number on the back of the card. They then don't hang up, but play a dialling tone down the line until you dial the number. At which time they 'answer'. This only works on home phones, not mobile, but is worth considering, and warning your family/friends about.

[deleted]

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#57
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

Oh it gets worse. My UK bank had a hardware token for years. They recently "upgraded" my security for online banking, and now use SMS 2FA codes for login and authorising new transfers. The hardware token is now unusable. I'd change banks, but I doubt the others are better.

To send money over £250, RBS still use hardware card readers for their MFA flow. You put your debit/credit card in the device, entry your normal pin and then a code that is displayed on the website. It's a little inconvenient of you don't have the device with you when you need to send large amounts of money but in general it's great to have rather than SMS.

Of course, I expect that eventually they'll move to SMS too since it's easier for them and more on line with the rest of the industry.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#58

The easiest way to avoid this entire class of attack, is to never be willing to answer any kind of question from someone who calls you. Always hang up, Google the customer support line for the business, then call them .

There was a widespread phishing attack in the UK that used this approach. On UK landlines the call is not terminated until the person who made the call hangs up. That is to say if I call you, you answered and then hung up, then waited a minute and picked up the phone again, I'd still be there and the connection still made. Scammers phoned people, told them there is an account issue and to phone the number on the reve…

This BBC article from 2014 suggests that the call clearing time was reduced to a few seconds by most carriers: https://www.bbc.co.uk/news/technology-26559554

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#59
In France at least you need to keep the member number a secret from everybody. Since banks here are lazy bums with security they only ever implement the minimum recommended security. According to French data protection services this is 5 digits!!! when the 'username' is secret.

Never disclose your member number.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#60

The easiest way to avoid this entire class of attack, is to never be willing to answer any kind of question from someone who calls you. Always hang up, Google the customer support line for the business, then call them .

How easy would it be for an attacker to (at least temporarily) outrank the bank in SEO so that when people google the bank's number they find the top result being the attacker's number?

Extremely hard. Maybe you could buy an ad space and "outrank" them that way. Have to pass Google's ad approval process though.
Post reply on HN