Live data from Hacker News

I'm a scam prevention expert and I got scammed

lupinia.net

131–140 of 562 posts

Re: I'm a scam prevention expert and I got scammed

#131

Earlier quoted context omitted.

Look, I certainly believe that as you get larger and larger groups of people, law of large numbers it becomes inevitable that someone becomes scammed. And I certainly don't doubt that I could be scammed at some time, especially by a phishing email or something of the sort. But I don't think I'll ever give out a 2FA code to anybody that's not me. It's a really simple rule of thumb. Just never do it, there is never any…

Yes, it's easy to convince yourself you're way too smart to make this mistake. At the same time, you now deliberately skipped over the fact twice that he just skimmed the mail and didn't fully realize it was specifically a 2FA code, just assumed it was some verification code. I mean, the wording explicitly talks about entering this code somewhere to enable stuff. That's already two dead giveaways. Otherwise you'd be…

It's pretty obvious what is a 2FA code and what is not. If I'm being sent a code on my email or phone, I know not to tell it to someone on the phone. Indeed, even that very email she was sent contained a reminder not to tell it to someone on the phone.

I read the entire article, I am just unimpressed by the justifications as to how this "could happen to anybody."

Re: I'm a scam prevention expert and I got scammed

#132
post #104

Earlier quoted context omitted.

Yep. Amazon gets a cut and they act like it.

This is quite a jump to conclusions. The alternative theory of the customer service rep googling a phone number and getting the wrong one is far more likely. Or, it's possible that the company's own seller login was compromised and a scammer changed their contact number. The idea that a wildly successful multi-billion dollar company would actually set up such an easily-noticed system where they "get a cut" of phishin…

> The alternative theory of the customer service rep googling a phone number and getting the wrong one is far more likely.

Their support staff is that reckless and Amazon has no training and other systems in place to prevent that? Your theory doesn’t paint them in any better light.

Re: I'm a scam prevention expert and I got scammed

#133
> my bank, Wells Fargo (I know, I know; trust me, they were not my first choice). > aren't phone numbers that Wells Fargo recognizes as valid mobile numbers (one of many things I despise about this bank). > Wells Fargo's system would be so janky and sloppily-built that this is the least awful way they could figure out how to do it. > consistent with similarly nonsensical policies I've encountered with Wells Fargo before (I hate this bank so much

I think it might be time to change banks...

Re: I'm a scam prevention expert and I got scammed

#134
A tip that may or may not travel well: some banks can set a "security passphrase" or passcode that must be provided before they will do anything for you. A few years back I had someone compromise my credit card and somehow answer enough questions to increase the credit limit on the card substantially. This was the bank's response to this.

No bank advertises this from what I can tell.

Re: I'm a scam prevention expert and I got scammed

#135
post #68
post #42

Earlier quoted context omitted.

Calling on the official number is a good rule. But my neighbour followed that and was still scammed for tens of thousands. The critical extra step that they missed was to check that the line was disconnected before calling out. They were using a landline. The scammers called them, but didn't hang up. Then, when my neighbour called out to their bank, they pretended to be answering that call - going through security, e…

For the people who are confused: this is a fairly common thing on landlines in some countries, where the telephone exchange doesn't drop the connection until both ends have hung up, or in some cases when the caller hangs up but not the callee. So it's possible to put your own phone down, but when you pick it up again your phone is still connected to the scammer's telephone. If they play a convincing dial tone, then c…

Even already knowing about this I'm still mystified that landlines work this way on every occasion that I'm reminded of it. Does anyone know if there is, or at least was, a justification for this mode of operation? Was it at least of any use to anyone back around the 1900s or whenever or is it just another "we do it because that's how we've been doing it" residue that hasn't been cleaned yet?

Re: I'm a scam prevention expert and I got scammed

#136
post #11

Earlier quoted context omitted.

I think the movie was Phone Booth that begins with the line "A ringing phone demands to be answered" Technology projects a form of authority (disconnected from any real power) in the same way that written words were synonymous to truth for illiterate 13th century peasants. To follow your logic, which I am not criticising as it's a valid approach given how dysfunctional cellphones are as trustable systems, I would say…

The rule in our family for a number of years now has been, "If the number is not in your address book, let it go to voicemail." We have the landline ringer off and always let it go to voicemail. As an 80/20 solution, it's been remarkably effective so far.

The scammer spoofed the wells fargo customer service line in caller ID though.

Re: I'm a scam prevention expert and I got scammed

#137
post #113
post #93

Earlier quoted context omitted.

Brute forced by a human voice on a phone call? You must talk quickly.

He almost certainly meant that sha256(card number) can be bruteforced to figure out what card number was hashed. 10^12*256 bits is only 29 TiB. So providing a hashed card number to a potential scammer is just as bad as providing the card number.

So just ask the other party to give you a salt they generate on the spot? And/or you do so on your end?

You can still get targeted for a direct attack but much less likely to end up caught in a dragnet approach.

Re: I'm a scam prevention expert and I got scammed

#138

I wish the title hadn't given away that it was a scam call. Perhaps it could have implied it was a gripe about Wells Fargo at first. Reading it while already knowing it was a scam, it seemed blindingly obvious to me, and it was hard to imagine how I could have made the same mistakes. But that could be overconfidence.

Yes it is overconfidence. You just have to be tired or distracted and it will be incredibly easy to fall victim to one of these scams.

Re: I'm a scam prevention expert and I got scammed

#139
post #6

I nearly got taken by a scammer because Amazon transferred me to one. I purchased a set of Reolink cameras on Amazon, (they've been great) one of them failed a couple months in. I contacted Amazon customer support (via my Amazon login and in their interface) and they wanted to troubleshoot with their technical team. Eventually the (very helpful) Amazon technician suggested contacting Reolink for support and started a…

It's really hard recognizing the image Amazon have in the US compared to my personal experience with amazon.de . The service is stellar, shipping both ways is free as long as you buy products covered by prime. Refunds are with no questions asked (as long as you don't start abusing it i guess). As soon as you go into 3rd party sellers the experience gets muddled, though I've had plenty of good experiences with those as well. There's simply nothing here in Europe that gets even close to what Amazon offers. I really really hope it will never be like the horror stories i see here on HN.

Re: I'm a scam prevention expert and I got scammed

#140

> So, I faithfully relayed the Apple Pay verification code, as requested. I cannot fathom how a tech professional would do this. I mean, I read their justification, but it still doesn't make an ounce of sense to me, other than their brain was shut off for the entire call.

I think I can kind of get it. This guy has made his own life so complicated that he no longer knows what a normal guy operates like.

A normal person knows that scam calls come in all the time, so they're on the alert for them. A normal person has their MFA device or has MFA on text and they know these two mechanisms have codes they should never relay. If they got an MFA via email they'd immediately have their suspicions up.

A normal person, through the normalcy of their system, assumes that if this bank is having trouble dealing with them they'd have trouble dealing with everyone and that's just absurd.

But if you're the _abnormal_ person, then you assume your custom setup is the problem. That's because 99% of the time it is the problem. He's fucked himself into being a social engineering target.

Back in the day, this was a thing with Linux. You'd encounter a bug in a Windows app hosted through the WINE runtime and you'd think "Well, it's WINE, it can't be perfect. I'll just report it on WineHQ and go about my life". Well, sometimes it wouldn't be WINE. It would just be the app itself. But you assumed that because you're the weird one using WINE. Everyone else is using Windows. So you blame your own setup and your bug doesn't get fixed because it's in the wrong place.

So this is my attitude to a lot of security stuff. I want to be the normal user. Huge advantages:

- If something is broken for you, it's broken for everyone. So no one will blame you for consequences.

- If something is weird about it, it's weird; you should be suspicious

- If things go badly for you because of it, no one will blame you because they can relate; you will get help easier

Post reply on HN