Live data from Hacker News

Woman loses over $44k after downloading third-party app to buy fish

straitstimes.com

11–20 of 67 posts

Re: Woman loses over $44k after downloading third-party app to buy fish

#11

I wonder how best to solve this from a software or hardware POV, rather than from a policy standpoint. It seems so easy to take full control of phones these days.

This is a social problem. She was instructed to do xyz over whatsapp. Any device can be compromised. It’s all about informing people what not to do. Like how very slowly old people are starting to wake up to the idea that you don’t pay the IRS with google play gift cards.

The likelihood you get scammed as you age approaches 1.

Older people start defaulting to trust due to the mental burnout induced by having to overthink every situation.

Insurance companies are trying to figure out right now how to cover scam insurance per your age.

Re: Woman loses over $44k after downloading third-party app to buy fish

#12
I find it interesting that many people lament crypto about lack of transparency and how we went through this and that and that's why we have these sort of regulations in the legacy banking system, etc.. etc.. The reality is that, these regulations mostly exist in the US (through credit card protection), and some in the EU. For the rest of the world, if you got your account siphoned, you are mostly on your own.

And about transparency: I have a debit card from an EU bank. It's barely usable because every time I need to make a purchase, it has to go through 3DS and 50/50 the transaction gets rejected. On POS in Asia, it's 80/20. So quite frustrating. Anyway, two months ago, I get a 60-70 EUR transaction on it from some merchant. Not sure how the scammer got the numbers (some shady POS in Thailand?) but the operation was via "an online interface" and there was no confirmation.

More bizarre: No one can tell me who exactly debited my card. Not even the bank itself has any idea who the merchant or his identity is. There you have it, a fully dysfunctional system and yet somehow it has become solid because a "less" secure one has lost some people some money.

Re: Woman loses over $44k after downloading third-party app to buy fish

#13
post #9
post #5

Mark Cuban recently lost $870k in crypto by a fake app scheme: > “I’m pretty sure I downloaded a version of MetaMask with some shit in it,” Cuban told DL News. He said he had searched for Circle on Google, not MetaMask. [1] [1]: https://www.dlnews.com/articles/people-culture/mark-cuban-lo...

I don't know. But if you have $870K in crypto and don't use a hardwallet, I kind of don't feel bad for you.

To be fair, at Cuban scale that's your hot wallet.

Re: Woman loses over $44k after downloading third-party app to buy fish

#14

I wonder how best to solve this from a software or hardware POV, rather than from a policy standpoint. It seems so easy to take full control of phones these days.

> It seems so easy to take full control of phones these days.

What?

The lady agreed to install and run an app, because someone asked her to do so.

She literally handed over control of her phone with its bank account accesses, essentially.

Also, that's an Android phone, which might or might not matter, but i imagine this social engineering (as if) scam would work in general.

In the words of Laocoon, "quidquid id est, timeo danaos et dona ferentes" if i remember.

Re: Woman loses over $44k after downloading third-party app to buy fish

#15
My mom always says no to any marketing offers. Last time I thought she was stupid for missing out on deals, but now I think she's a genius for having a strong spam filter and delegating the rest to her "IT" son.

The amount and sophistication of scam is very worrying.

Re: Woman loses over $44k after downloading third-party app to buy fish

#16

I wonder how best to solve this from a software or hardware POV, rather than from a policy standpoint. It seems so easy to take full control of phones these days.

This is a social problem. She was instructed to do xyz over whatsapp. Any device can be compromised. It’s all about informing people what not to do. Like how very slowly old people are starting to wake up to the idea that you don’t pay the IRS with google play gift cards.

Totally agree that it’s a social problem. But it’s getting worse, not better.

There are hard security rules that you should always follow, for example, never click on links from an unknown sender. In the last five years I’ve noticed a trend of bureaucracies in every institution now want you to violate generally accepted security rules for their own convenience.

For example, I got a text from a new number saying (sic) “we’re your dentist office and we’ve changed over to a new system, please click this link and provide some sensitive PII for us ahead of your visit.” Although I had a dentist appointment coming up in a week, I called their office to confirm the appointment, no one over the phone asked me to do anything different, so I ignored the text.

When I got into the office, the receptionist politely told me that I did not fill out the patient forms ahead of my visit, and that I should have received a text message, and now they had to print the forms, which is a problem for them because they’re trying to go paperless. It was a very polite interaction, but the subtext was that I violated an implied contract with their office to engage regularly with them.

As members of the public, we’re asked to click on links from places we don’t recognize, to support the functioning of bureaucracies. Everyone engages in this behavior. I’ve found financial and insurance companies to be the worst offenders.

Regardless, institutions in authoritative positions are opening up massive avenues for social engineering by requiring the general public to ignore security best practices to interact with them. It succeeds in reducing administrative costs from them, but introduces systemic risk that the public is paying for in the form of security breaches.

Re: Woman loses over $44k after downloading third-party app to buy fish

#17
post #9
post #5

Mark Cuban recently lost $870k in crypto by a fake app scheme: > “I’m pretty sure I downloaded a version of MetaMask with some shit in it,” Cuban told DL News. He said he had searched for Circle on Google, not MetaMask. [1] [1]: https://www.dlnews.com/articles/people-culture/mark-cuban-lo...

I don't know. But if you have $870K in crypto and don't use a hardwallet, I kind of don't feel bad for you.

"Look, idiot, if you do not perfectly follow all of this op sec, your money could disappear at literally any moment. In which case, sucks to be you. Oh, and also those crypto exchanges where people leave their money - those also have a good chance of disappearing in the night. Best to keep it under the digital equivalent of your mattress."

I will stick with a bank which is regulated to protect my money, and heads will roll if funny business happens.

Re: Woman loses over $44k after downloading third-party app to buy fish

#18
I've been seriously thinking of getting a separate phone which would just be used for financial apps. It seems apps are now required to log into a few of the institutions I use, and you can do virtually everything with their apps. Two factor seems to edging towards one factor, when a fingerprint can do everything.

Re: Woman loses over $44k after downloading third-party app to buy fish

#19
post #9
post #5

Mark Cuban recently lost $870k in crypto by a fake app scheme: > “I’m pretty sure I downloaded a version of MetaMask with some shit in it,” Cuban told DL News. He said he had searched for Circle on Google, not MetaMask. [1] [1]: https://www.dlnews.com/articles/people-culture/mark-cuban-lo...

I don't know. But if you have $870K in crypto and don't use a hardwallet, I kind of don't feel bad for you.

870k is Cuban dipping his toes with a test account. Everyone has different risk profiles and adversity.

Re: Woman loses over $44k after downloading third-party app to buy fish

#20
post #12

I find it interesting that many people lament crypto about lack of transparency and how we went through this and that and that's why we have these sort of regulations in the legacy banking system, etc.. etc.. The reality is that, these regulations mostly exist in the US (through credit card protection), and some in the EU. For the rest of the world, if you got your account siphoned, you are mostly on your own. And ab…

> I have a debit card from an EU bank. It's barely usable because every time I need to make a purchase, it has to go through 3DS and 50/50 the transaction gets rejected

I have 2 debit cards and two credit cards from UK banks, and my partner has the same. I genuinely don't think I've ever had 3DS reject a transaction for either of us.

> a fully dysfunctional system and yet somehow it has become solid because a "less" secure one has lost some people some money.

No, it's solid because of legislation. Improving the technical details doesn't help the situation, as most of the issues are legislative.

Post reply on HN