Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

131–140 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#131
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

This is so true. My wife (US) just needs user+pwd to access her bank. Me (Italy), had physical tokens or at least SMS 2fa for years. Also EU is now going through a major security upgrade for banks with SCA (Strong Customer Authentication)

My US bank added "two-factor" authentication at some point, requiring both a password and the answer to my secret question :-D

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#132
post #33

I don't understand why there are still banks that do SMS verification. It has been proven so many times now that that it is vulnerable to both phishing (proven here), sim swapping attacks, etc. The banks here in the Netherland all have (well, except for one maybe) hardware authentication devices. They are portable smartcard readers, you insert your card, enter your PIN on the device itself (not your computer or phone…

IMO smart card readers are the worst solution for everything. They are invariable less capable and less secure than my phone. Why would I carry 2 devices (one of these quite primitive) if I could only carry one?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#133
post #123

Earlier quoted context omitted.

Oh it gets worse. My UK bank had a hardware token for years. They recently "upgraded" my security for online banking, and now use SMS 2FA codes for login and authorising new transfers. The hardware token is now unusable. I'd change banks, but I doubt the others are better.

I hate hardware tokens. Recently got one from my bank. I'm switching banks. I just don't see any advantage over a phone app (plus a phone app can offer better notifications).

Yes, but then it's not 2FA, it's notifications in the app you're probably using for banking, so now it's 1FA.

That's fine for sending £100 to an account already in your list of payees, but to set up a new account, where's the second factor in an app? That, to me, seems a large step backwards.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#134

Earlier quoted context omitted.

There seems to be broad consensus amongst the commenters that this is the most reliable defense against this kind of attack. Makes sense. If they are able to intercept my outbound calls, it's probably an entirely different level of sophistication and targeting.

I read about a landline attack that would keep the line open when you put the receiver down, play a dial tone, and then wait until you’d entered a number before putting you back on with the scammer

Learned about this too today. With the scammers playing the dial tone sound to trick the victim... Clever.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#135
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

In Sweden we have BankID - a two-factor, two-way authentication using public/private encrypted keys that's bound to a smartphone as a signature. The process is user-friendly while keeping security high: - The place where you want to login has to trigger the authentication from their server on every login - and have to be certified for BankID. - You then have to open the app, enter your fingerprint or 6-pin code befor…

That's the Mobile BankID, and it gets scammed a lot. The smart-card based BankID is the only acceptable choice IMO

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#136
Banks have such shitty security over the phone and they train us to do stupid stuff like giving out personal info when they call.

For example, your real bank in the U.K. ask for your date of birth and address for ‘data protection purposes’ when they call you, or they won’t even tell you what the call is about.

How are people supposed to understand what is OK to give out and what isn’t when these details, often used as security questions are somehow fine?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#137

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

[deleted]

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#138
Something quite similar happened to a relative of mine this summer in France. A scammer impersonating bank support. He called Friday 16h30 mid holidays. He proposed to help reduce fees by disabling not needed options, while in fact he was triggering a text verification code. The text doesn't specify the reason for the request.

He got in. Then did a few other useless operations during 15 minutes that required email confirmation which state what they are requiring it for. Those had mainly two purposes : help lower the guard and provide cover for the initial false requests. He kept smooth talking explaining that because of the various changes they should expect the bank app not be available and that everything was normal. Then he went for the option which allows to activate instantaneous bank transfers which required both email and phone verification code.

My relative was about to read it to them, when his wife smelling something fishy was happening put me with him on the phone. He was so convinced that everything was normal that I almost can't convinced him to hang up. What did the trick was telling him : "hang up and call back the bank before continuing".

My relative thought he was safe because he never gave the password of the bank app, nor the web password. But for our bank, this 4-digit pin password you put in the phone app is not a real password it is just a per-device off-line password you pick upon first device use to disallow someone stealing your phone to have access to your bank account too easily.

After he hang up, and I succeeded to talk some sense into him. I convinced him to call his bank. It was past 17h00, so it was closed. I told him to call emergency security which he did. But the number is typically used for lost credit card ; so they did the only thing that they usually do : revoke credit card and send a new one. Which is basically useless because the scammer wasn't about to use the credit card number to buy something online but he was initiating some wire transfer via the app.

So I had him call again a few times reexplaining the problem more precisely, or at least told them to block wire transfer for the account. Maybe it succeeded to raise some red flags, but they always told him that they couldn't do anything and that he needed to wait till Monday. From their point of view, you can be the impersonator so they didn't told us they did anything.

He also sent an email to the local bank manager during the night.

Stressful week-end lock-out of all bank accounts information goes by. The bank app is kind of deceitful because sometimes when it doesn't succeed in connecting shows you the last available data like it would in off-line mode and you think you are connected OK but you are not.

Monday they could reach the bank have the hack acknowledged and investigated ; access to accounts restored and password changed ; no harm done (except for the inconvenience of not having a credit card during the holiday, and info leaked) ; Luck.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#139

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

Just realizing that a phishing-attack like this is nowadays impossible in the EU: proper two-factor authentication is mandatory now (Revised Directive on Payment Services, PSD2), even just for login. TAN-codes generated for transactions need to incorporate the data of the transaction (recipient and amount), so that a phished TAN cannot be used to authorize a different transaction. I think even a simple SMS TAN may not be allowed any more (could be MITM-abused to authorize a different than the intended transaction).

Here is a summary of what customers and phishers have to face since september:

https://wso2.com/library/articles/2019/06/strong-customer-au...

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#140
post #123

Earlier quoted context omitted.

I hate hardware tokens. Recently got one from my bank. I'm switching banks. I just don't see any advantage over a phone app (plus a phone app can offer better notifications).

Yes, but then it's not 2FA, it's notifications in the app you're probably using for banking, so now it's 1FA. That's fine for sending £100 to an account already in your list of payees, but to set up a new account, where's the second factor in an app? That, to me, seems a large step backwards.

Well, you need (1) my phone and (2) my fingerprint, so technically it is 2FA. They could easily require (1) my password and (2) my phone, so still 2FA.

2FA is usually fake anyways, there's usually a way to reset stuff with only one factor (e.g. use phone number to reset password, or login with password and change phone number, ... same with PIN), so it's all a misnomer anyways.

Post reply on HN