Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

91–100 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#91

My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phish…

They always ask if I want to pay over the phone. I say nope, I'll mail you a check.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#92
post #68

Earlier quoted context omitted.

But, if I don't hang up the received and the counterparty hangs up, then the line tone is the one of the "busy", not the one of the "free", and I'm unable to dial anyone until I physically hang up to reset the line. Or at least that's how it works back home. Is it different in UK ? I suppose it's something that less attentive people might fall for anyways.

Wow, this really is something if done right. I don't use a landline now, but if I remember, the caller needs to disconnect for the line to actually be disconnected. So even if the callee tries to disconnect by hanging up, the caller is still actually connected. If the callee picks up the receiver again and hears a dial tone, they'd be none the wiser. But I guess the scammer would also need to detect a key-press tone…

Never heard of the systems with this flaw. It was always "if you hang up then it's completely cut".

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#93
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

> Last time I needed a new token issuer dongle, I had to actually visit the bank and sign stuff. I'm glad UK banks try to avoid physical dongles because having to go to the bank and sign stuff to get one is not always convenient, not to mention you need to carry around the dongle everywhere, and if you lose it while you're in vacation it's yet more troubles. Phone 2FA would be good but a bit pointless because the 2FA…

>Phone 2FA would be good but a bit pointless because the 2FA app is on the phone, and so is the banking app.

Can't you just lock the stolen phone?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#94
I can understand how people would fall for this one. With 20/20 hindsight, asking for the member number is fishy - it doesn't actually verify anything. And when my bank calls me, it is always automated - I only get a person talking to me if I ask for it through the automated systems. So in a way, any actual person calling would be a red flag. But in the moment, I can see why it sounded legit.

My parents have taken their precautions against phishing to extreme levels. They don't speak into the phone when unknown numbers call. At all. If they choose to answer, they wait for someone on the other end to talk and then decide whether to speak or hang up. They have heard horror stories of people getting their voices recorded and replayed into automated systems, so if someone calls and asks, "Hi, Is this ?", they avoid even saying "Yes", and instead ask who is calling. It may be paranoia, but as the saying goes... just because you are paranoid doesn't mean that they are not out to get you.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#95
post #72

In EU, there is the (recent) implementation of a (new) directive, PSD2: https://en.wikipedia.org/wiki/Payment_Services_Directive#Rev... That carries with it the requirement of SCA: https://en.wikipedia.org/wiki/Strong_customer_authentication In practice (here in Italy) you have a client number (secret) a password/PIN (also secret) AND either a SMS to your mobile with a one time code or a Smartphone app (yikes!), ther…

Also, when you're wiring money to someone, my bank is now requesting to input certain digits of the amount and destination account into the app. Those digits are then factored into the 2FA algorithm. I am not sure if this adds substantially to the security though.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#96

Earlier quoted context omitted.

There seems to be broad consensus amongst the commenters that this is the most reliable defense against this kind of attack. Makes sense. If they are able to intercept my outbound calls, it's probably an entirely different level of sophistication and targeting.

I read about a landline attack that would keep the line open when you put the receiver down, play a dial tone, and then wait until you’d entered a number before putting you back on with the scammer

Analogue telephones are creating (or at least in modern times simulating) a circuit, which doesn't close until the caller hangs up.

But almost everybody today has a digital phone, any kind of mobile telephone or desk VoIP phone is digital, "hanging up" ends the call because the telephone itself decided to do that, everything is just packets. So this trick won't be effective against most people today.

Likewise "dialling" today is an out-of-band digital step rather than a bunch of pulses or tones sent in-band that an attacker can just ignore.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#97
post #68

Earlier quoted context omitted.

But, if I don't hang up the received and the counterparty hangs up, then the line tone is the one of the "busy", not the one of the "free", and I'm unable to dial anyone until I physically hang up to reset the line. Or at least that's how it works back home. Is it different in UK ? I suppose it's something that less attentive people might fall for anyways.

Wow, this really is something if done right. I don't use a landline now, but if I remember, the caller needs to disconnect for the line to actually be disconnected. So even if the callee tries to disconnect by hanging up, the caller is still actually connected. If the callee picks up the receiver again and hears a dial tone, they'd be none the wiser. But I guess the scammer would also need to detect a key-press tone…

That's not how it works with digital lines. Disconnect on any side breaks the whole circuit presuming they conform to even ancient PDH, much less SONET or SDH. Oh and this includes even more ancient ISDN. The trunk will immediately tear down the DS0 slot and circuit.

GSM and VoIP also do not allow this behavior without engaging call waiting on subscriber side.

This only happens with old fully analog connections. Not sure which country or public operator still has this kind of PSTN.

For the difference, peruse ITU-T G.175 and Q.522 standards. SE (switching element) will disconnect the routing on your side. It took me a while to find the actual standard number.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#98

My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phish…

> My simple policy is I never give out any information if I'm cold-called. That's what I do. When someone calls me and then proceeds to ask me security question to allegedly assert my identity I reply "well, you called me so how do you prove to me who you are first?" I usually get a "err..." but on one occasion the guy was rather rude and hanged up. The worst thing is that most of the time these calls are genuine. Th…

My bank did this once - called me out of the blue and started asking for answers to security questions. I asked them how I could be sure it was definitely them and they said to call the number on my card and ask for a particular department, which I did, and it turned out it was indeed genuine.

The fact that they had an immediate answer to the question obviously means that they were asked this question all the time. I wonder how many people happily handed over the info?

It seems that they now just play a recorded message asking to call, and then automatically hang up.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#99

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

It should be noted that Caller ID spoofing is possible with pretty basic equipment. It's illegal in most countries but there's nothing technically preventing you from doing it. Which is crazy IMO.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#100
post #21
post #9

This is very scary for the average person. I've taken to simply not answering any questions (not even to confirm my name) if someone calls me. If my bank calls me then I call them back on a number that's on their web site.

If my bank calls me then I call them back on a number that's on their web site. I'm always amazed at how stupid the security situation is in these cases. Banks, telecoms services, etc. do actually call up and try to 'take me through security', and when I say "tell me something you know about me first so I know you're who you say you are", the best they can usually manage is "well, uh, you bank with [Bank]". It just p…

I've even had a bank rep get angry at me for refusing to answer their questions on the cold call. I presume it wasn't phishing because when I called back on the legit number they did want to talk to me. It was a long time ago so I forget but I think they were trying to upsell me so maybe thats why he got angry - i.e. no commission for him.
Post reply on HN