Live data from Hacker News

Woman loses over $44k after downloading third-party app to buy fish

straitstimes.com

1–10 of 67 posts

Re: Woman loses over $44k after downloading third-party app to buy fish

#3

I wonder how best to solve this from a software or hardware POV, rather than from a policy standpoint. It seems so easy to take full control of phones these days.

On the front page of HN right now as you posted this: https://news.ycombinator.com/item?id=37623479

Re: Woman loses over $44k after downloading third-party app to buy fish

#5
Mark Cuban recently lost $870k in crypto by a fake app scheme:

> “I’m pretty sure I downloaded a version of MetaMask with some shit in it,” Cuban told DL News. He said he had searched for Circle on Google, not MetaMask. [1]

[1]: https://www.dlnews.com/articles/people-culture/mark-cuban-lo...

Re: Woman loses over $44k after downloading third-party app to buy fish

#6

I wonder how best to solve this from a software or hardware POV, rather than from a policy standpoint. It seems so easy to take full control of phones these days.

On the front page of HN right now as you posted this: https://news.ycombinator.com/item?id=37623479

There’s a little bit of alert fatigue on this stuff. Online internet privacy/security folks kick up a fuss about a lot of things that I don’t think cause me any harm, and it’s reducing my ability to detect legitimate threats. I can’t constantly evaluate whether something is Google “spying on my web browsing” or “this guy can steal your money”.

Fortunately, the solution of just sticking to mainstream platforms works. If I’m on a Mac with an iPhone, anything that hits me hits half of Americans. I’ll be in a nice big class-action once the damages are widespread.

Interestingly, this disincentivizes niche platforms.

Re: Woman loses over $44k after downloading third-party app to buy fish

#7
post #5

Mark Cuban recently lost $870k in crypto by a fake app scheme: > “I’m pretty sure I downloaded a version of MetaMask with some shit in it,” Cuban told DL News. He said he had searched for Circle on Google, not MetaMask. [1] [1]: https://www.dlnews.com/articles/people-culture/mark-cuban-lo...

It's mind boggling how crypto people still trust hot wallets that run as fucking browser extensions.

Re: Woman loses over $44k after downloading third-party app to buy fish

#8

I wonder how best to solve this from a software or hardware POV, rather than from a policy standpoint. It seems so easy to take full control of phones these days.

This is a social problem. She was instructed to do xyz over whatsapp. Any device can be compromised. It’s all about informing people what not to do. Like how very slowly old people are starting to wake up to the idea that you don’t pay the IRS with google play gift cards.

Re: Woman loses over $44k after downloading third-party app to buy fish

#9
post #5

Mark Cuban recently lost $870k in crypto by a fake app scheme: > “I’m pretty sure I downloaded a version of MetaMask with some shit in it,” Cuban told DL News. He said he had searched for Circle on Google, not MetaMask. [1] [1]: https://www.dlnews.com/articles/people-culture/mark-cuban-lo...

I don't know. But if you have $870K in crypto and don't use a hardwallet, I kind of don't feel bad for you.

Re: Woman loses over $44k after downloading third-party app to buy fish

#10

I wonder how best to solve this from a software or hardware POV, rather than from a policy standpoint. It seems so easy to take full control of phones these days.

Can't be solved completely, anything can be social engineered. But thats no excuse for not solving as completely as possible. I couldn't discern from the article the extent to which any technical vulnerabilty was involved -- or if it was pure social engineering, eg with the criminals using the info they had gotten out of the user to gain access to their accounts via more social engineering of their bank? Was an Android system exploit involved? Was the malware app able to escalate its privilege and access info from other apps? If either of those, what about Android's security model or implementation needs to be further hardened? (Naive questions, I'm neither a security nor a Android engineer.)
Post reply on HN