Live data from Hacker News

I'm a scam prevention expert and I got scammed

lupinia.net

371–380 of 562 posts

Re: I'm a scam prevention expert and I got scammed

#372

No offence but as an "expert" there is no excuse to run a webpage/blog etc. with no https. With Vercel, Netlify and many others offering free stating hosting and let's encrypt https certificate there is no excuse to run a site without an SSL certificate. To me the moral of the story and that you should never ever follow instructions by an alleged bank calling you asking to confirm informations and, even worse, give t…

HTTPS is when you ask 200 companies if either of them know the key for your bank. And they are all run by charlatan boomers who think buying more firewalls and cool security products is equivalent to securing their private cert signing keys. Why on earth would I ever want this? Like hello, have you ever seen ultracorporate tech company culture? They really don't know what they're doing. Why would you trust them let alone trust 200 of them in a way such that even if one of them messes up, all your sites are compromised?

Imagine that domain names contained the public key in them. I Google up "mybank", and it gives me https://8c789ad256afa4ca93f1af6436e7adff51cdd1c380de7d7cc78b... This takes https://a4244aa43ddd6e3ef9e64bb80f4ee952f68232aa008d3da9c78e..., which you somehow obtained before the MITM happened.

Re: I'm a scam prevention expert and I got scammed

#373
post #21

There's one easy rule that could have avoided all of this - never give out any info on incoming calls. If I get a call or text about fraudulent transactions, I'll keep them on hold while I log into the bank website. If I get a call about a late payment, I'll thank them for the info and ask them to stay on while I pay online. If I get an inbound call with a more complex request, I'll ask them for their employee info a…

I don't know, I maintain that policy fairly strictly, but I can imagine falling for this.

I won't as a policy give out information to an incoming call, and I do call back if they want any info from me. But my working memory is not endless. The topic of discussion had changed three times before he was asked for any information, and the information still wasn't PII, it was a confirmation code. The scammer knew enough about him that he wasn't especially on alert. I can well imagine that flag in my mind that I was on an incoming call having been lost before we got to that point. And I suspect that's exactly how the scam was designed.

Re: I'm a scam prevention expert and I got scammed

#374

Just don't give people 2FA codes? I am never going to give a 2FA code to someone who calls me, no matter what combination of words come out of their mouth.

Until you play with 15 different companies each which have slightly different variants of how they do their authentication security theater, as well as them throwing odd balls at you every month until you really have no idea how anything is supposed to work anymore.

Re: I'm a scam prevention expert and I got scammed

#375

Earlier quoted context omitted.

Yep. I've been ordering from Target, Best Buy, and Walmart much more often these days. I just assume the product descriptions and reviews on Amazon are all lies.

God I wish walmart’s site was better, it is like punishment shopping there, why does home depot outclass them in every way?

It is pretty bad. They're my last resort.

Re: I'm a scam prevention expert and I got scammed

#376

Banks will never call you. It's that simple. And if they do, hang up and call them back. I've had this attempted scam tried on me twice in last 4 months. You know it's a scam for sure when they try to prevent you from hanging up. Also, always disconnect. Don't just listen for a "dial tone" after they hang up.

Yes, 50 people ITT have already pointed out this one weird trick. If anyone actually thinks this fixes the general problem, no it doesn't.

Re: I'm a scam prevention expert and I got scammed

#377

These 2FA bypass scam calls genuinely unnerve me - because they're specifically designed to trick someone who knows how scams work and has actually put some effort into securing their accounts. Hardware authentication factors are, of course, immune to these sorts of attacks because you can't confuse the victim into forwarding their second factor back to you. However, I don't see why you couldn't construct a specific…

Why are you talking about hardware? Just get rid of these weird snakeoil auth flows and make user / password the be all end all way to authenticate. If there's a problem with that, well there isn't. No company on earth has ever tried it, not even in the 90s.

Re: I'm a scam prevention expert and I got scammed

#378
post #6

I nearly got taken by a scammer because Amazon transferred me to one. I purchased a set of Reolink cameras on Amazon, (they've been great) one of them failed a couple months in. I contacted Amazon customer support (via my Amazon login and in their interface) and they wanted to troubleshoot with their technical team. Eventually the (very helpful) Amazon technician suggested contacting Reolink for support and started a…

> I was blown away that Amazon would transfer me to a scammer. I contacted Amazon again and let them know what had happened. Hopefully they will figure out how their guy got this scammers phone number and teach him how to find a 3rd party phone number... 1) Amazon is complicit in shady behavior on their platform, whether it's inventory commingling, sketchy sellers repurposing existing, well-reviewed listings for a to…

> Amazon is complicit in shady behavior on their platform

Bought some wireless earbuds a while back, they sent me a horrible knock off. Contacted the store, he said the delivery guy made the switch, took forever but sent me new ones. Left a review stating all of this and warning users not to buy from this sketchy store, my review never saw the light of day.

Re: I'm a scam prevention expert and I got scammed

#379
post #71

I expected some crazy new attack vector that was so sophisticated it could fool this Scam Prevention Expert, but this post is laughable. They fell for textbook "scamming 101" that my grandma knows to avoid. Here's one tip for this expert – if you get a 2FA code over text or email that clearly has the line "we will never contact you for this code over phone or text" right under it, DON'T give it to a "support agent" o…

This feels like an unreasonably nasty and condescending response to an article about how anyone can make mistakes in the moment. I thought it was a pretty good article about how easy it is to sit at your computer and look down at people who fall for scams, but that scams are effective precisely because they take advantage of mistakes and the fallibility of people - even knowledgable ones.

I feel like this comment misses the core thesis of the article - that condescension and expectations of human perfection are not effective ways to prevent social engineering attacks and that building systems that anticipate human error is a better approach.

Re: I'm a scam prevention expert and I got scammed

#380
post #219

Earlier quoted context omitted.

Well, most IP cameras cannot be accessed this way when you look at the global pool of IP cameras. However many on them on Amazon, particularly from OEM companies like Reolink that are more of a custom relabeller vs. a real camera manufacturer have all kinds of backdoor access methods. Best practice is to put your IP cameras on a separate isolated network, connected to a dual-NIC recorder/PC running trusted software (…

Can't you just use VLAN tagging and firewall rules?

Yes, of course. Though most people who understand that are already doing things to mitigate exposing these devices to open internet access. My comment was targeted more towards anyone who might not have considered the risks, or might not be comfortable with virtual segmentation vs. physical segmentation.
Post reply on HN