Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

171–180 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#171
post #160
post #37

Earlier quoted context omitted.

Good idea - but here in the UK there was a scam where they called you and THEN suggested you call the number on the back of the card. They then don't hang up, but play a dialling tone down the line until you dial the number. At which time they 'answer'. This only works on home phones, not mobile, but is worth considering, and warning your family/friends about.

Have you any idea when this worked in the UK? It's such an old story that you'd have thought there would be an explanation online by now of exactly which telephone exchanges had this problem and when those telephone exchanges were in use. For what it's worth, it didn't work when I tried it, probably in the 1980s. Perhaps it worked in the 1970s in some places?

Pretty sure I tried it in the 70's with a TXE4. Didn't work.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#172

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

"The caller called me twice in rapid succession" this is to bypass the "Do not disturb" functionality on iOS if you have "Repeated calls" enabled. https://cdn.cultofmac.com/wp-content/uploads/2014/04/Do-Not-...

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#173
I think it's interesting to see how hard we've worked on making the web secure by adding all sorts of checks and protocols, but we've neglected to do the same with basic telecoms.

When I first started using web based communication platforms like Twitter and Nexmo I was really surprised to learn that I could put anything in the from field when sending a text message. All I could think was that it was a weakness that was ripe for abuse.

I believe there was a case in Germany a few years back where a group of phishers had online banking login details for several hundred users but couldn't initiate transfers without entering a PIN sent to the account holders phone via SMS. So the phishers set up a fake telephone company so that they could issue SS7 commands and have the account holders phone's temporarily redirected to another number where the PIN could be intercepted.

I think there is a false assumption amongst many people that the telephone system is inherently secure. Stuff like the above and all the robo calls coming from false numbers should warn otherwise.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#174

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

>When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-) Makes you wonder what this will look like when these scams evolve another couple of generations in terms of complexity ...

I think this is a social skills moment. For those that claim it's "easy" to spot: This is not the right time for people to brag about how they would have totally spotted it. This is mostly for protecting people who (as most people in this world) don't have time to build up a solid understanding of all aspects of internet security. If you don't care about these people, as some sort of Darwinian schadenfreude, stfu. If you do, focus on their perspective, not your brilliant detective skills.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#175
post #159

Earlier quoted context omitted.

society could fix all sorts of problems if we had a public key infrastructure...

Or maybe some sort of interconnected web of people who trust each other...

That would be pretty good privacy.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#176

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

While spoofing numbers on incoming calls is far easier, it is also possible for an attacker to redirect your outgoing calls from the right place in the phone network.

You just shouldn't consider any aspect of the phone network to provide authenticity or confidentiality.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#177

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

Just realizing that a phishing-attack like this is nowadays impossible in the EU: proper two-factor authentication is mandatory now (Revised Directive on Payment Services, PSD2), even just for login. TAN-codes generated for transactions need to incorporate the data of the transaction (recipient and amount), so that a phished TAN cannot be used to authorize a different transaction. I think even a simple SMS TAN may no…

The security part of PSD2 is starting to look like another cookie law. Banks of course didn't implement any proper 2FA like U2F but rather send you scrounging for the phone with their app every time you want to look up a transaction or an account number, something that didn't require second factor until the directive.

In fact, because it makes checking recent transactions that much less convenient, it probably made me less safe because I do it much less often.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#178

The easiest way to avoid this entire class of attack, is to never be willing to answer any kind of question from someone who calls you. Always hang up, Google the customer support line for the business, then call them .

How easy would it be for an attacker to (at least temporarily) outrank the bank in SEO so that when people google the bank's number they find the top result being the attacker's number?

There's quite a few articles about this happening in India through Google Maps:

https://www.forbes.com/sites/leemathews/2018/11/26/fraudster...

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#179
post #159

Earlier quoted context omitted.

society could fix all sorts of problems if we had a public key infrastructure...

Or maybe some sort of interconnected web of people who trust each other...

Like the web of trust from GPG?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#180
From the Twitter thread:

"Never answer your phone. Seriously. Only use it to make outbound calls. You cannot trust caller ID, and you should never answer unscheduled inbound calls."

Makes sense. Phone calls as they are can no longer be used for security verification. Just can't.

Post reply on HN