Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

231–240 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#232
This seems like a big problem, since my bank's SMS codes don't specify why they are sending it:

"This is a verification code from [bank]. Enter online at prompt or in password field w/in 30 minutes."

Nowhere does it mention the purpose, or to NOT read the code over the phone under any circumstances.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#233

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

To me, the biggest red flag is asking for any identifying info in a conversation they initiated, especially without them initially providing some sort of privledged information to you first.

Unfortunately, some banks do this. (I'm looking at you, U.S. Bank.)

It's like someone calling me and then asking me who they're speaking to. Really? You called me! (Assuming they're not returning a missed call, of course.)

If (someone claiming to be) a bank calls/texts you, (and it's not immediately after a declined transaction) you always hang up and call the number you already have for the bank.

Even if it is after a declined transaction, you still don't provide any info. If they ask if you attempted a $101.89 purchase at "big box store," you should simply respond yes/no, and provide no other info.

If you didn't attempt that transaction, they especially don't need to confirm any other info.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#234
post #31

The bank I'm currently at has this "obnoxious" text around verification numbers: Don't EVER communicate the following verification number to anyone, including collaborators: 123456 SMS OTP should always have that or similar text.

Also maybe a less predictable otp

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#236

Earlier quoted context omitted.

My bank always says "There is an issue with your credit card/account, please call the number on the back of the card/your branch as soon as possible." and has for years. The only time they do otherwise is on very specific instances where they provide the info, "did you just buy something at store XXX for approximately $YYY" All banks and credit institutions should be required by law to do this.

Capital One has an app, every time my card is used I get a push notification. This is the best solution in my mind. I can actively monitor my card usage and call if I see something suspicious.

I wish all banks and CCs offered this feature.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#237
post #177

Earlier quoted context omitted.

The security part of PSD2 is starting to look like another cookie law. Banks of course didn't implement any proper 2FA like U2F but rather send you scrounging for the phone with their app every time you want to look up a transaction or an account number, something that didn't require second factor until the directive. In fact, because it makes checking recent transactions that much less convenient, it probably made m…

TOTP is in terms of usability not very different from PhotoTAN or ChipTAN, so I don't see how these methods aren't "proper 2FA". U2F is a useful method, but it's not common at all (even in IT most companies don't provide it, not even the website we're on right now, nor PayPal), and it's not understandable how this isn't "proper 2FA". In addition, the directive requiring the purpose of the code to be fixed and shown a…

I don't like TOTP. U2F, however, is both convenient and secure. You touch a dongle, you're in, and at the same time there is no way to get access to your account without physically stealing the dongle. It's a proper second factor to a password.

Other solutions are either or. There is a benefit to confirming particular actions (with the info about the action) in the app but it's unnecessarily inconvenient for mere login.

U2F isn't widely supported but I managed to secure virtually my entire high-value Internet presence with it. Google, OVH, Coinbase, and Stripe all support it. Let's be honest, for HN I wouldn't bother with any second factor. I have the password saved in the browser and that's more than enough.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#238
post #174

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

>When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-) Makes you wonder what this will look like when these scams evolve another couple of generations in terms of complexity ... I think this…

Most people claiming they would have spotted it are probably wrong anyway. They're reading the messages with the knowledge that they were sent by a scammer. Any idiot can identify these things in hindsight knowing what they're looking at. Without that context, with other things on their mind, it's much more likely they'd have been duped too.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#239
post #224

Earlier quoted context omitted.

> it’s only illegal to spoof your number for fraudulent purposes Seems like you’re gettig bogged down in semantics sir

How is that semantics? Fraud is already illegal literally everywhere, so spoofing your number for fraudulent purposes will obviously be a part of that crime. If this is intended to defend your original claim, you’re being utterly ridiculous. You made a specific claim about caller id spoofing, not fraud. For example, If you’re spoofing a random number for telemarketing calls that’s just not fraud.

> If you’re spoofing a random number for telemarketing calls that’s just not fraud.

It absolutely is, and in most civilised countries is illegal.

Like, I can totally believe that in the USA where any old lunatic can own an automatic weapon amd nobody gets concerned until he shoots up a school thats the case ye

There’s probably some constitutional argument that you can spoof your number based on something ridiculous like free speech

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#240
post #174

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

>When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-) Makes you wonder what this will look like when these scams evolve another couple of generations in terms of complexity ... I think this…

I'd wager >50% of those that claim "Ah ha! I'd spot it here!" would fail in real life. Arm-chair quarterbacking is easy. Spotting the scam in real life, when you're walking down the street or otherwise distracted with life? Much harder.
Post reply on HN