Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

321–330 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#321

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

I've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiat…

> "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are"

Correct. If someone calls me, the onus is on them to prove to me that they are who they say they are.

However, I usually just block ALL unscheduled phone calls, period. Not only do I not have time for unscheduled interruptions, but banks have secure websites and if they can't make proper use of them, too bad, they aren't going to reach me by trying to call me. They should know that phones are easy to phish with, and stop using phone calls to initiate communication.

Ideally what I want is an e-mail saying "we saw some suspicious transactions, please /log in/ to check that there is no fraudulent activity" or even a more general "please log in for an urgent message" with a suspend button in the online interface.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#323
post #251
post #222

Earlier quoted context omitted.

Can you elaborate why you believe smartcards are less secure than your mobile phone?

All the ones I've seen have no security, either it's just a changing password (e.g. RSA key), or you input your card (optionally entering your PIN which you share with every POS terminal / shop) and get a password. My phone requires a password (which I can set to be arbitrarily secure, not 4-digit PIN (LOL)) or a fingerprint (which is something noone can steal, unlike a credit card... or at least I'd notice it's miss…

As I expected: you don't appear have a clue on what a smartcard actually is.

> My phone requires a password (which I can set to be arbitrarily secure, not 4-digit PIN (LOL)) or a fingerprint (which is something noone can steal, unlike a credit card... or at least I'd notice it's missing much sooner!)

Anyone can steal your fingerprint, and you can't reset your fingerprint like you can with a password or PIN.

A smartcard will self-destruct (wipe the key material) after a number of unsuccessful PIN entries, so the chance of someone successfully guessing the PIN is ~1:3333 for a 4 digit PIN with 3 attempts. This is good enough for banks to offer fraud insurance, in the off-chance that your card gets cracked your bank will reimburse the damage.

> optionally entering your PIN which you share with every POS terminal / shop) and get a password.

Yes, but that would still require physical access to your card. So they'll need to have both your card and your PIN. At that point you'll need to have your card/account blocked ASAP anyway. Your bank will supply you with a new card and PIN, which is a way better solution compared to cutting off your fingers and attaching new ones ;-)

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#324
post #154

Earlier quoted context omitted.

Thinking of this I would have continued like: Me: are you confirming that if I start a scam you will not investigate it? Police:...? Me: Ok , then thanks a lot, I know now. Police: umm, wait maybe..

Of course the local police department isn't likely to investigate it. That doesn't mean no one is.

But, formally speaking, it actually really is within their responsibility to serve as the first point of contact for the individual citizen (think "retail customer") and put it through to the proper channels within law enforcement.

The Bavarian police (this was in Bavaria) even has a "center for cybercrime" which, according to press releases and stuff, sounds like precisely the office that should take note of things like that. But they don't have any public-facing communication channels of any kind[1], and I'm unclear whether they actually do stuff or whether they exist purely on paper as a public relations and politics stunt.

Maybe if I was politically connected or willing to spend a pile of dough to put a lawyer on it, things would be different, but this was just one man trying to do his civic duty and there's only so much trouble that I'm willing to go to for that.

[1] EDIT: After doing some more research, it looks like, meanwhile they do. This was just announced two months ago, so seems to be a new development.

https://www.polizei.bayern.de/kriminalitaet/internet/index.h...

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#325

Earlier quoted context omitted.

My bank always says "There is an issue with your credit card/account, please call the number on the back of the card/your branch as soon as possible." and has for years. The only time they do otherwise is on very specific instances where they provide the info, "did you just buy something at store XXX for approximately $YYY" All banks and credit institutions should be required by law to do this.

Capital One has an app, every time my card is used I get a push notification. This is the best solution in my mind. I can actively monitor my card usage and call if I see something suspicious.

chase does this too.

applepay, for all my cards, gives me an immediate push notification, despite some cards not doing so for regular chip/swipe transactions. really like that feature & also wish all cards did it for all transactions.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#326

Earlier quoted context omitted.

Interesting thanks for the write-up. One thing that I've frequently heard is that in any type of fraud call you should always hang up right at the beginning and call the bank back. Seems like no matter how sophisticated the attackers, this defense will always foil anything along the same lines of what happened to you. The only way I can see this countermeasure failing is if the scammers can somehow manage to intercep…

I agree. The same goes for email obviously. But some financial institutions are actively luring customers into doing the wrong thing. Paypal really stands out on this one. They are regularly sending me emails with a link to their login page to view my recent transactions (regardless of whether or not there are any transactions). This is clearly negligent.

Okay, so it's not just me. I've never clicked on what are apparently real paypal emails, because I have legitimately always assumed they were phishing e-mails that made it past my spam filter.

They're real. They're really real paypal e-mails. Wow.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#327

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

>It is better if banks include a security warning / specific reason the code is sent with the password reset pins and similar credentials. My bank did not. Another twitter user noted being subject to the scam, and just glancing over the warning copy. So it helps, but it is not perfect. Especially pre-coffee. I'm seriously surprised there are banks that send SMS codes without a reason for the code. All banks I deal wi…

I have seriously reconsidered giving my business to a bank that does do that: I'm not a fan of sending transaction amounts or account info via text. My bank does this (and over email!); their security posture is fairly decent otherwise, but why oh why send transaction amounts out into the world where they can be intercepted by anyone between here and there?

Think about the useful information for an attacker in messages like that: Recent transaction details can help an attacker auth on a call, account numbers can do the same. And large transactions are catnip, alerting attackers to worthwhile victims.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#328

I can understand how people would fall for this one. With 20/20 hindsight, asking for the member number is fishy - it doesn't actually verify anything. And when my bank calls me, it is always automated - I only get a person talking to me if I ask for it through the automated systems. So in a way, any actual person calling would be a red flag. But in the moment, I can see why it sounded legit. My parents have taken th…

I wonder if the criminals start to use automated voice systems, especially if those systems prompt and allow you to input numbers/password from the dialpad, how many more people would fall to the scam.

If done well, it likely would be highly effective. Maybe we should not give them any ideas.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#329
post #21

Earlier quoted context omitted.

If my bank calls me then I call them back on a number that's on their web site. I'm always amazed at how stupid the security situation is in these cases. Banks, telecoms services, etc. do actually call up and try to 'take me through security', and when I say "tell me something you know about me first so I know you're who you say you are", the best they can usually manage is "well, uh, you bank with [Bank]". It just p…

I’ve tried getting them to give me a checksum to verify validity. For example, tell me the sum of the last four digits of my card number. They always refuse, so I always hang up and call back. Too bad they don’t understand that giving out a checksum is not insecure.

Well, yeah, if it's not standard operating procedure I'd hope they'd refuse.

Now, it should be supported, but I don't want the folks on the front lines guessing (or figuring out on their own) what sorts of mathematical games are safe. Erring on the side of caution is the right approach for CSRs.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#330

Earlier quoted context omitted.

Never heard of the systems with this flaw. It was always "if you hang up then it's completely cut".

Perhaps it worked on Strowger exchanges when the call is local? I definitely remember this being "a thing" back in the 1970s but I don't remember ever succeeding in reproducing it. Obviously there must have been some time out because otherwise you could DoS anyone's phone by just calling them then not hanging up.

In the UK, when exchanges moved to digital, they deliberately kept the old behaviour because some people relied on it (eg, hanging up their main phone, then walking to another room and picking up the call on an extension phone), with a timeout of a few minutes.

In 2014 they reduced the timeout to 10 seconds to make this fraud harder to pull off.

https://www.openreach.co.uk/orpg/home/updates/briefings/down...

Post reply on HN