Live data from Hacker News

Smishing

zitadel.ch

21–30 of 32 posts

Re: Smishing

#21
post #20
post #2

To the puzzled: 'Smishing' = 'SMS' ∩ 'phishing' > Signs that you are getting "Smished": [...] when you receive a message from bigger service providers, (f.e. banks, post offices, or delivery services) they will mostly have their company names displayed instead of their numbers The formulation in the article may lead to a very bad advice: in some areas, scammers do display a "company name", regularly. So: a numeric se…

This is odd and completely counter to my own anecdotal experience. SMS messages from large companies I interact with (My bank, cell phone provider) always come from fairly static short codes. The elephant in the room here is that SMS is not a medium where integrity or authenticity of a message can be guaranteed—which is one of the big reasons it’s such a popular medium for phishing.

Me thinks your gut is leading you correctly.

Generally speaking, there are short codes, and long codes. Sometimes alphanumerics are allowed, but the rules vary regionally.

Long codes resemble traditional phone numbers and tend to be treated as more disposable, low volume, and person-to-person. As such, they are typically easier to spoof with.

Short codes tend to be more like car license plates: short random/vanity codes that require a more in-depth process to get access to. They are easier to verify ownership, suited for higher volume messaging, and tend to be backed by automation systems that respond to a set of automated commands like "HELP". These qualities make them less likely to be used for nefarious purposes.

It's definitely a topic I'd love to understand more. Any corrections/additions are very much welcome!

Re: Smishing

#22

> The number of the sender and that of the service provider they claim to be, do not match. Don't forget that the caller ID here can be spoofed. It's best to disregard it completely. One of the infographics in the article suggests looking up the number of the text, which I'd suggest is actively harmful advice - it gives you zero information and risks lulling people into a false sense of security. Assume that all text…

Yes and to add: if an SMS’ sender ID successfully spoofs another number, the message would appear threaded into an existing “legitimate” conversation.

Re: Smishing

#23

Earlier quoted context omitted.

I'm not sure it's one-click. Visiting a page isn't exactly "clicking" - I'd expect a "click" in this sense to be like a browser asking "are you sure?" and you clicking through, or "play video". But it's not super clear cut. Like, let's say you had to open up a message on your phone for the exploit to work - you clicked the message, right? idk

I'd say it is one-click when compared to older MMS exploits where just receiving the message would activate the exploit.

Yeah, fair

Re: Smishing

#24
post #20
post #2

To the puzzled: 'Smishing' = 'SMS' ∩ 'phishing' > Signs that you are getting "Smished": [...] when you receive a message from bigger service providers, (f.e. banks, post offices, or delivery services) they will mostly have their company names displayed instead of their numbers The formulation in the article may lead to a very bad advice: in some areas, scammers do display a "company name", regularly. So: a numeric se…

This is odd and completely counter to my own anecdotal experience. SMS messages from large companies I interact with (My bank, cell phone provider) always come from fairly static short codes. The elephant in the room here is that SMS is not a medium where integrity or authenticity of a message can be guaranteed—which is one of the big reasons it’s such a popular medium for phishing.

> This is odd and completely counter to my own anecdotal experience. SMS messages from large companies I interact with (My bank, cell phone provider) always come from fairly static short codes

And what do those which come from scammers look like? In some areas, they are identical to those from the «large companies».

Re: Smishing

#25
post #24
post #20

Earlier quoted context omitted.

This is odd and completely counter to my own anecdotal experience. SMS messages from large companies I interact with (My bank, cell phone provider) always come from fairly static short codes. The elephant in the room here is that SMS is not a medium where integrity or authenticity of a message can be guaranteed—which is one of the big reasons it’s such a popular medium for phishing.

> This is odd and completely counter to my own anecdotal experience. SMS messages from large companies I interact with (My bank, cell phone provider) always come from fairly static short codes And what do those which come from scammers look like? In some areas, they are identical to those from the «large companies».

I believe we’re making the same point from different angles:

I’m pointing out that companies I work with don’t exhibit easily identifiable characteristics to verify authenticity.

You (correct me if I’m wrong) are stating that bad actors will craft messages that look like legitimate ones.

In either case, we end up in a place where I would be unable to determine if a message is legitimate barring further out of band confirmation.

Re: Smishing

#26

It would be great if a section about BEC [0] was included. At $WORK we see a lot of "Smishes" that pretend to be our CEO/CTO that ask for the user to send them money. E.g. "Hello it's $CEO, I'm in a meeting currently and need your help. Can you send me 300 dollars in apple gift cards?" [0] https://www.fbi.gov/scams-and-safety/common-scams-and-crimes...

I know this sounds cold, but I feel like some of these scams are really just a stupidity tax. How do people operate in the outside world if they believe that the CEO would be hitting them up for gift cards?

what are the consequences of what youre saying? is it better if these scams mostly affect stupid people? should we care less about whats happening to stupid people?

Re: Smishing

#27

It would be great if a section about BEC [0] was included. At $WORK we see a lot of "Smishes" that pretend to be our CEO/CTO that ask for the user to send them money. E.g. "Hello it's $CEO, I'm in a meeting currently and need your help. Can you send me 300 dollars in apple gift cards?" [0] https://www.fbi.gov/scams-and-safety/common-scams-and-crimes...

I know this sounds cold, but I feel like some of these scams are really just a stupidity tax. How do people operate in the outside world if they believe that the CEO would be hitting them up for gift cards?

I agree with you, but you might not be aware of some of the crap that happens in small companies with certain kinds of CEOs and salespeople. Others too, but the pubic-facing staff are always the problems.

The harried assistants and lower-level functionaries in those companies regularly field requests like "I'm in a sales meeting/airport terminal/Dunkin Donuts and need to demo something, and I need you do something stupid the wrong way".

So, it's a stupidity tax indeed, and even on the right people (CEO), but it's the assistants who get blamed and/or feel responsible.

Even at bigger and well-run companies, the assistants have stories that would shock you. CEO-speak can often tend toward illiterate and nonsensical, and their requests unreasonable -- even if they can be interpreted correctly. In contrast, COOs and CFOs are pretty reliable. And CTOs run the gamut, I'm sorry to say. :)

Re: Smishing

#29

It would be great if a section about BEC [0] was included. At $WORK we see a lot of "Smishes" that pretend to be our CEO/CTO that ask for the user to send them money. E.g. "Hello it's $CEO, I'm in a meeting currently and need your help. Can you send me 300 dollars in apple gift cards?" [0] https://www.fbi.gov/scams-and-safety/common-scams-and-crimes...

I know this sounds cold, but I feel like some of these scams are really just a stupidity tax. How do people operate in the outside world if they believe that the CEO would be hitting them up for gift cards?

It's all about spray and pray aka sending volume.

We had a sales woman fall for it. The email said from our CEO that said he was at a conference and needed her to go out and buy 10 $100 Visa gift cards and send him the numbers bc he wanted to use them as giveaways.

The issue is that our CEO actually WAS at a conference on that day!

She actually went to the closest CVS and bought them and thankfully mentioned something about it to me when she got back. I paused for a moment and then was like wait a second how did you hear about this request? Email only? so I called our CEO to confirm. Was able to go back to CVS and get them all refunded and the scammer got nothing.

But, that being said, I can see how people fall for it. Employee and user training and awareness are key to prevent these types of things.

Re: Smishing

#30

It would be great if a section about BEC [0] was included. At $WORK we see a lot of "Smishes" that pretend to be our CEO/CTO that ask for the user to send them money. E.g. "Hello it's $CEO, I'm in a meeting currently and need your help. Can you send me 300 dollars in apple gift cards?" [0] https://www.fbi.gov/scams-and-safety/common-scams-and-crimes...

I know this sounds cold, but I feel like some of these scams are really just a stupidity tax. How do people operate in the outside world if they believe that the CEO would be hitting them up for gift cards?

It is cold. And I think it's harmful to infer that the people that fall for these are stupid. It does nothing to help the situation.

If the prevailing thought is that you're stupid for falling for a scam, then the victim is less likely to share and inform, and then education does not spread. All it does is make them feel awful, which is not helpful and just even more hurtful.

I think we have to come at it from the angle of the scammers are tactical and that it's okay if you are a victim. It sucks, of course, but no blame necessary on the victim.

I know someone who got a similar message from her priest asking for gift cards. The scammer got a hold of the church directory and used that to send out messages. The person thought she was doing a favor for her priest and wanted to help; it is not her fault that the red flags weren't as strong as they should've been. Not everyone operates on suspicion mode.

I know another who was almost a victim of the the sobbing phone call: "Granpda, I'm in jail! Please send me bail. Also don't tell anyone!"

These types of scams target emotions and kindness. That's how these people operate in the real world. It's not that these people are stupid, it's more that they are unaware and not sensitive to the red flags.

Post reply on HN