Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

81–90 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#81
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

In Sweden we have BankID - a two-factor, two-way authentication using public/private encrypted keys that's bound to a smartphone as a signature. The process is user-friendly while keeping security high: - The place where you want to login has to trigger the authentication from their server on every login - and have to be certified for BankID. - You then have to open the app, enter your fingerprint or 6-pin code befor…

>that's bound to a smartphone as a signature.

Big yikes, that's a no for me.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#82
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

The EU has made 2FA mandatory for online banking as of September.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#83

Earlier quoted context omitted.

In Sweden we have BankID - a two-factor, two-way authentication using public/private encrypted keys that's bound to a smartphone as a signature. The process is user-friendly while keeping security high: - The place where you want to login has to trigger the authentication from their server on every login - and have to be certified for BankID. - You then have to open the app, enter your fingerprint or 6-pin code befor…

>that's bound to a smartphone as a signature. Big yikes, that's a no for me.

This is the same system I'm talking about. You can use your smartphone and a PIN, or you can get a hardware dongle. Same authentication API from the banks POV.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#85
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

I had one of those from a major UK bank nearly 15 years ago.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#86
post #77
post #37

Earlier quoted context omitted.

Good idea - but here in the UK there was a scam where they called you and THEN suggested you call the number on the back of the card. They then don't hang up, but play a dialling tone down the line until you dial the number. At which time they 'answer'. This only works on home phones, not mobile, but is worth considering, and warning your family/friends about.

I don't think this works any more. My parents always did this when kids did prank calls. Kept the phone open for hours blocking their line. Did not work last time I tested. Uncertain how long you have to wait before next call though.

Generally with digital phone lines (almost every line out there) this does not work, and teardown on your side is at most few seconds.

This is also impossible to pull off on cellphone lines. (There are other attacks but these require access to your BTS.)

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#87
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

> Last time I needed a new token issuer dongle, I had to actually visit the bank and sign stuff. I'm glad UK banks try to avoid physical dongles because having to go to the bank and sign stuff to get one is not always convenient, not to mention you need to carry around the dongle everywhere, and if you lose it while you're in vacation it's yet more troubles. Phone 2FA would be good but a bit pointless because the 2FA…

I don't think having 2FA in phone app is pointless. It's still second factor, if someone got to your bank account. They need to get access to that 2FA app as well. And of course you protect that app with password/ping. Do you know of cases when 2FA app was defeated when someone stole money from bank account?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#88

Earlier quoted context omitted.

Oh it gets worse. My UK bank had a hardware token for years. They recently "upgraded" my security for online banking, and now use SMS 2FA codes for login and authorising new transfers. The hardware token is now unusable. I'd change banks, but I doubt the others are better.

To send money over £250, RBS still use hardware card readers for their MFA flow. You put your debit/credit card in the device, entry your normal pin and then a code that is displayed on the website. It's a little inconvenient of you don't have the device with you when you need to send large amounts of money but in general it's great to have rather than SMS. Of course, I expect that eventually they'll move to SMS too…

Under the new EU rules 2FA over SMS is not allowed because it is possible to transfer phone numbers to other devices (through social engineering or simply because providers reuse old numbers) and thereby intercept the code. Instead most banks use an authentication app so that 2FA is bound to a single device.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#89

My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phish…

> My simple policy is I never give out any information if I'm cold-called.

That's what I do. When someone calls me and then proceeds to ask me security question to allegedly assert my identity I reply "well, you called me so how do you prove to me who you are first?"

I usually get a "err..." but on one occasion the guy was rather rude and hanged up.

The worst thing is that most of the time these calls are genuine. This means that my bank does think it's fine to do that.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#90

Earlier quoted context omitted.

Interesting thanks for the write-up. One thing that I've frequently heard is that in any type of fraud call you should always hang up right at the beginning and call the bank back. Seems like no matter how sophisticated the attackers, this defense will always foil anything along the same lines of what happened to you. The only way I can see this countermeasure failing is if the scammers can somehow manage to intercep…

There seems to be broad consensus amongst the commenters that this is the most reliable defense against this kind of attack. Makes sense. If they are able to intercept my outbound calls, it's probably an entirely different level of sophistication and targeting.

I read about a landline attack that would keep the line open when you put the receiver down, play a dial tone, and then wait until you’d entered a number before putting you back on with the scammer
Post reply on HN