Live data from Hacker News

Smishing

zitadel.ch

1–10 of 32 posts

Re: Smishing

#2
To the puzzled: 'Smishing' = 'SMS' ∩ 'phishing'

> Signs that you are getting "Smished": [...] when you receive a message from bigger service providers, (f.e. banks, post offices, or delivery services) they will mostly have their company names displayed instead of their numbers

The formulation in the article may lead to a very bad advice: in some areas, scammers do display a "company name", regularly. So: a numeric sender string increases the chances of the SMS being a scam; an alphanumeric sender string /does not/ decrease the chances of the SMS being a scam.

Re: Smishing

#3
> The number of the sender and that of the service provider they claim to be, do not match.

Don't forget that the caller ID here can be spoofed. It's best to disregard it completely.

One of the infographics in the article suggests looking up the number of the text, which I'd suggest is actively harmful advice - it gives you zero information and risks lulling people into a false sense of security. Assume that all texts are from scammers and act accordingly.

Re: Smishing

#4
> As software capable of zero-click exploit, Pegasus requires no user interaction to operate: ... As a result of a simple click on the URL, the spyware was granted unlimited access to every information stored on the iPhone.

That's a one-click exploit, no?

Pegasus has demonstrated zero-click exploits (e.g. PDF embedded in GIF), but this is not one.

edit: the provided CitizenLab link [0] describes two classes of attacks, "zero-click exploits and malicious SMSes". Looks like the author conflated the two?

[0] https://citizenlab.ca/2022/04/catalangate-extensive-mercenar...

Re: Smishing

#5
post #2

To the puzzled: 'Smishing' = 'SMS' ∩ 'phishing' > Signs that you are getting "Smished": [...] when you receive a message from bigger service providers, (f.e. banks, post offices, or delivery services) they will mostly have their company names displayed instead of their numbers The formulation in the article may lead to a very bad advice: in some areas, scammers do display a "company name", regularly. So: a numeric se…

Thanks for the feedback. That's true it is not a single one indication.

Re: Smishing

#6

> The number of the sender and that of the service provider they claim to be, do not match. Don't forget that the caller ID here can be spoofed. It's best to disregard it completely. One of the infographics in the article suggests looking up the number of the text, which I'd suggest is actively harmful advice - it gives you zero information and risks lulling people into a false sense of security. Assume that all text…

Reminds me of the time in highschool when I would send my teacher an email from the principle to come see them immediately. The teacher would sit down at their computer and a few minutes later leave the class for about 10-15 minutes. The SMTP server totally trusted every device on the network and worked without any authentication whatsoever.

Ah, the joys of the early internet.

Re: Smishing

#7

> The number of the sender and that of the service provider they claim to be, do not match. Don't forget that the caller ID here can be spoofed. It's best to disregard it completely. One of the infographics in the article suggests looking up the number of the text, which I'd suggest is actively harmful advice - it gives you zero information and risks lulling people into a false sense of security. Assume that all text…

Reminds me of the time in highschool when I would send my teacher an email from the principle to come see them immediately. The teacher would sit down at their computer and a few minutes later leave the class for about 10-15 minutes. The SMTP server totally trusted every device on the network and worked without any authentication whatsoever. Ah, the joys of the early internet.

Haha or the good old netsend fun on school pcs ;-)

Re: Smishing

#8
post #2

To the puzzled: 'Smishing' = 'SMS' ∩ 'phishing' > Signs that you are getting "Smished": [...] when you receive a message from bigger service providers, (f.e. banks, post offices, or delivery services) they will mostly have their company names displayed instead of their numbers The formulation in the article may lead to a very bad advice: in some areas, scammers do display a "company name", regularly. So: a numeric se…

> The formulation in the article may lead to a very bad advice: in some areas, scammers do display a "company name", regularly. So: a numeric sender string increases the chances of the SMS being a scam; an alphanumeric sender string /does not/ decrease the chances of the SMS being a scam.

Just curious, which part of the text did you understand this way?

If I would guess it could be with this part:

> The number of the sender and that of the service provider they claim to be, do not match. Moreover, when you receive a message from bigger service providers, (f.e. banks, post offices, or delivery services) they will mostly have their company names displayed instead of their numbers.

As I understand it, the article suggests that you still should compare the numbers even if only a name is displayed? But yeah your explanation is still on point.

Re: Smishing

#9
Anything that has anything to do with the cellular network is irredeemably broken and should be avoided.

Re: Smishing

#10

> The number of the sender and that of the service provider they claim to be, do not match. Don't forget that the caller ID here can be spoofed. It's best to disregard it completely. One of the infographics in the article suggests looking up the number of the text, which I'd suggest is actively harmful advice - it gives you zero information and risks lulling people into a false sense of security. Assume that all text…

exactly.

Best practice is to not click on any link in an sms/whatsapp. I don't recall any useful link sent by SMS. Whenever it is important it is always a warning telling you to connect yourself via the offical app/website eventually using the token/parcel code/identifier sent on the actual sms.

Post reply on HN