Live data from Hacker News

The short tale of an online scam

duarteocarmo.com

21–30 of 98 posts

Re: The short tale of an online scam

#21
"always look at the url bar"

I remember reading about a scam where the URL seemed legit, and the suspicious part was pushed after so much white space that it was no longer visible in the URL bar. I don't remember the details and I'd be curious to know if anyone remembers it. I remember even sophisticated users saying they might have fallen for it.

Re: The short tale of an online scam

#22
> "Also, (2) if you want to protect other people from falling victims to scams like these: tell them to always look at the url bar. Always."

This is good advice, as things stand right now, it is in fact the best advice we can give.

In absolute terms it is borderline useless advice. Many companies still communicate from and operate from domains other than their well-known main domain.

How is anybody supposed to know that windowsupdate.com is a legit Microsoft domain? What about windowsazure.com? How do you know that fbcdn.net belongs to Facebook, but fbabc.com does not. Why isn't gdynamic.com a Google asset like gstatic.com. lufthansa.com, lufthansa.de, lufthansa.at, lufthansa.ch are all legit, why are lufthansa.li and lufthansa.lu not?

Sure, you can check WHOIS, but that just shifts the issue one level lower.

"[..] always look at the url bar." - Please do, but don't expect it to be enough to be 100% safe. In the world we live in anyone can be phished.

Re: The short tale of an online scam

#23

> "Also, (2) if you want to protect other people from falling victims to scams like these: tell them to always look at the url bar. Always." This is good advice, as things stand right now, it is in fact the best advice we can give. In absolute terms it is borderline useless advice. Many companies still communicate from and operate from domains other than their well-known main domain. How is anybody supposed to know t…

[deleted]

Re: The short tale of an online scam

#24
It's a fun story.

For myself, I tend to avoid pissing off scammers. I just let the relationship wither on the vine.

I had a friend that attacked a forum hacker, and the hacker responded by completely destroying a years-old online community. They probably used a bot to register a scammer login, but the attack got their attention.

My friend would have been far better served by deleting the login, and fixing the holes in his forum.

Re: The short tale of an online scam

#25
post #21

"always look at the url bar" I remember reading about a scam where the URL seemed legit, and the suspicious part was pushed after so much white space that it was no longer visible in the URL bar. I don't remember the details and I'd be curious to know if anyone remembers it. I remember even sophisticated users saying they might have fallen for it.

[deleted]

Re: The short tale of an online scam

#26

> "Also, (2) if you want to protect other people from falling victims to scams like these: tell them to always look at the url bar. Always." This is good advice, as things stand right now, it is in fact the best advice we can give. In absolute terms it is borderline useless advice. Many companies still communicate from and operate from domains other than their well-known main domain. How is anybody supposed to know t…

There has also been a push by Google and others lately to "dumb down" the url bar to hide the full address from users. Not sure why but I assume the justification would be some misguided attempt at making it look nicer while the real reason is somehow ad related.

Re: The short tale of an online scam

#27

> "Also, (2) if you want to protect other people from falling victims to scams like these: tell them to always look at the url bar. Always." This is good advice, as things stand right now, it is in fact the best advice we can give. In absolute terms it is borderline useless advice. Many companies still communicate from and operate from domains other than their well-known main domain. How is anybody supposed to know t…

There has also been a push by Google and others lately to "dumb down" the url bar to hide the full address from users. Not sure why but I assume the justification would be some misguided attempt at making it look nicer while the real reason is somehow ad related.

> There has also been a push by Google and others lately to "dumb down" the url bar to hide the full address from users. Not sure why but I assume the justification would be some misguided attempt at making it look nicer while the real reason is somehow ad related.

Suggesting Google might do anything without ad-related motives is probably too generous, but I've always thought that this was an optimisation in the sense that it's built on optimism: when everything's working well, most of what's in the URL bar is irrelevant. So the bar is built towards working well in the best case, at the expense of becoming much less useful in the worse (and probably more common) case.

Re: The short tale of an online scam

#29

> "Also, (2) if you want to protect other people from falling victims to scams like these: tell them to always look at the url bar. Always." This is good advice, as things stand right now, it is in fact the best advice we can give. In absolute terms it is borderline useless advice. Many companies still communicate from and operate from domains other than their well-known main domain. How is anybody supposed to know t…

There has also been a push by Google and others lately to "dumb down" the url bar to hide the full address from users. Not sure why but I assume the justification would be some misguided attempt at making it look nicer while the real reason is somehow ad related.

One of the justifications is that showing only the hostname will make it easier to recognize malicious hostnames; as it is, the typical non-technical user just sees a bunch of stuff, doesn't really know how to distinguish hostname from path.

I buy it honestly.

Re: The short tale of an online scam

#30
post #2

Scammers really have stepped up their game in recent years. I keep getting spam emails that say "we have your data, click here to see the list..." Of course, the link wants to authorize against my (nonexistent) gmail. Nice try. The people I feel bad for are the elderly: I know two that have been taken in by these things. They really aren't mentally equipped for the complexities of the modern Internet.

Lots of scams want your bank details. Unlike with SMS 2FA where the phone company never offered their service as a magic universal authenticator, the scammers want your bank account because it's a bank account. To the extent such scams work, we should be pretty unequivocal that it is your bank's fault. Banks are always reluctant to put their hands in their pockets when it comes to meaningful security. Whereas merchan…

> My good bank actually has security.

Would you be willing to make a recommendation?

Post reply on HN