Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

181–190 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#181

Go to the police? Let us know how that works out for you. I did that once, after a highly credible phishing attempt (that, ultimately, I did not fall for). This was in Germany. Me: Here is what happened to me, I'd like to file a police report. Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it. Me: They used perfect German, used informati…

The good old self-reinforcing loop...

It's not a prevalent issue -> We won't do anything -> You filing a report will be just a waste of time -> Statistics show it's not a prevalent issue

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#182
post #159

Earlier quoted context omitted.

society could fix all sorts of problems if we had a public key infrastructure...

Banks have this in place already - EMV cards have powerful cryptoprocessors. In Germany we can use chipTAN, it's a small cheap reader for your card where you scan a six-binary-blinking screen that transmits the transaction data, then the card signs it and you get a six-digit TAN back. You can also manually enter the hash to be signed ("start code" is the technical term) and you get the TAN. Customer support could ask…

Would you happen to know what kind of signature scheme they use?

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#183

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

> My bank no longer allows me to reset my password without calling them (thanks bank). So how are they going to verify it’s you who is calling them?

Ask for things like postcode, birthdate, etc.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#184

I'm sorry, I'm missing something between > Me: (that number, by itself, is useless). and > Once I gave my member number, the attacker used the password reset flow to trigger a text message from the bank. > They used this to gain access to the account. What happened here? How does an exposed useless member number trigger a password reset? Would the reset request not have come to an email account, presumably a well-pro…

> Would the reset request not have come to an email account, presumably a well-protected one?

Not in this case (and not in many); verifying access to a phone number is also common and apparently was an option for this bank.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#185
post #172

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

"The caller called me twice in rapid succession" this is to bypass the "Do not disturb" functionality on iOS if you have "Repeated calls" enabled. https://cdn.cultofmac.com/wp-content/uploads/2014/04/Do-Not-...

I noticed a political robocall taking advantage of this just yesterday, and there went any possibility that I would vote for this person. Your robocall did not constitute an emergency _you asshole_.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#186

Earlier quoted context omitted.

Banks have this in place already - EMV cards have powerful cryptoprocessors. In Germany we can use chipTAN, it's a small cheap reader for your card where you scan a six-binary-blinking screen that transmits the transaction data, then the card signs it and you get a six-digit TAN back. You can also manually enter the hash to be signed ("start code" is the technical term) and you get the TAN. Customer support could ask…

Would you happen to know what kind of signature scheme they use?

IIRC the German system is proprietary, the specs are available only after payment of a couple hundred euros.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#187
post #55

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

> It is better if [...anyone...] include a security warning / specific reason the code is sent with the password reset pins and similar credentials. I think anyone building such systems (either via e-mail or SMS or whatever) should at least remember THIS. Send something like this via SMS: > The password reset code you requested via our website is 12345. We will never ask you for this code except when you requested a…

The only text messages I get from my bank are descriptive confirmations of actions I did. At the end of every message it says to contact them by phone if you don't recognise the action.

My bank uses a scanner to authorize pretty much all actions. It scans some sort of RGB QR code [0]. When scanned you'll see the IBAN you're sending the money to and the amount you're sending. I think that when the IBAN is in your contacts it shows the name instead of the IBAN.

But most importantly it shows a descriptive message of what action you're verifying. I think the only actions that don't require the scanner are small transactions through their app and marking your card as broken/stolen in the app.

[0] https://www.rabobank.nl/images/how_does_the_rabo_scanner_wor...

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#188

Go to the police? Let us know how that works out for you. I did that once, after a highly credible phishing attempt (that, ultimately, I did not fall for). This was in Germany. Me: Here is what happened to me, I'd like to file a police report. Police: Well, with these internet scams, the fraudster is usually in another country, meaning we can't really do anything about it. Me: They used perfect German, used informati…

Unfortunately with spoofed numbers it is, from what I've heard, incredibly difficult to track. The carrier that terminated the call to your carrier is likely not the originating carrier (the one that initiated the call) so it could involve subpoenas to many carriers to find the originator, which you then have to subpoena for the customer information.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#189
post #177

Earlier quoted context omitted.

Just realizing that a phishing-attack like this is nowadays impossible in the EU: proper two-factor authentication is mandatory now (Revised Directive on Payment Services, PSD2), even just for login. TAN-codes generated for transactions need to incorporate the data of the transaction (recipient and amount), so that a phished TAN cannot be used to authorize a different transaction. I think even a simple SMS TAN may no…

The security part of PSD2 is starting to look like another cookie law. Banks of course didn't implement any proper 2FA like U2F but rather send you scrounging for the phone with their app every time you want to look up a transaction or an account number, something that didn't require second factor until the directive. In fact, because it makes checking recent transactions that much less convenient, it probably made m…

TOTP is in terms of usability not very different from PhotoTAN or ChipTAN, so I don't see how these methods aren't "proper 2FA".

U2F is a useful method, but it's not common at all (even in IT most companies don't provide it, not even the website we're on right now, nor PayPal), and it's not understandable how this isn't "proper 2FA".

In addition, the directive requiring the purpose of the code to be fixed and shown aside it, either in the app generating it, or in the push notification, is a very useful security aspect which most other 2FA solutions miss — even U2F can't differentiate between a login and a transaction authorization.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#190
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

In the Netherlands we used to have dongles or card-readers for all online banking but we are now downgrading to apps, 5-digit number codes and 2FA without an external device. This is all for ease of use but I think from a security standpoint it's not the right direction to go. For instance, in an app you can't view the certificate and wether or not the connection is secure. If you are in a foreign country with dubious leadership it could be hijacked using a rogue SIM-card or some dictator driven root CA (looking at you Kazakhstan).

The worst offender is ING, you can set a payment limit in the app but then you can also change the payment limit in the app itself. If I take a nap on the train, you can drain my bank account my pressing my thumb on the reader.

Post reply on HN