Live data from Hacker News

Woman loses over $44k after downloading third-party app to buy fish

straitstimes.com

51–60 of 67 posts

Re: Woman loses over $44k after downloading third-party app to buy fish

#51
post #27

Earlier quoted context omitted.

"Look, idiot, if you do not perfectly follow all of this op sec, your money could disappear at literally any moment. In which case, sucks to be you. Oh, and also those crypto exchanges where people leave their money - those also have a good chance of disappearing in the night. Best to keep it under the digital equivalent of your mattress." I will stick with a bank which is regulated to protect my money, and heads wil…

> heads will roll if funny business happens To be fair, a lot of the crypto hype is predicated, if indirectly, on how few heads roll when (barely quasi-legal) funny business happens through official institutions.

A. "I lost my money while it was in my bank... I got it back, but nobody got in trouble!"

B. "I lost my money while it was in crypto... I didn't get it back and nobody got in trouble!"

I'm not really sure B sounds like much of an improvement over A.

Re: Woman loses over $44k after downloading third-party app to buy fish

#52
post #38

Can someone explain how a third party app is getting access to her banking information on Android? Aren't apps sandboxed? Was this using regular Android security permissions, or was this relying on security vulnerabilities? And if vulnerabilities, is the problem that Androids often stop getting updates, so a large proportion of phones are sitting ducks?

The bit about the phone getting hot and crashing hints at a vulnerability being used. I would consider an android app sandbox escape bug to be the lowest level of difficulty in mobile phone exploit chains.

Really? In my mind that would be the most difficult. The simplest is telling a non-tech person to install a shady app, approve a bunch of permissions, and ask them to input even more information directly. The phone being hot can just be them running a crypto miner as they already maxed out the information she gave them. Or them intentionally crashing her phone to give themselves more time to siphon off accounts, avoiding her from contacting her banks and freezing cards.

I am more interested in the question if this was available on the app store or if the social engineering included her enabling 3rd party apps and side loading. A redacted copy of the chat would probably reveal a lot more how this worked.

Re: Woman loses over $44k after downloading third-party app to buy fish

#53
post #27

Earlier quoted context omitted.

> heads will roll if funny business happens To be fair, a lot of the crypto hype is predicated, if indirectly, on how few heads roll when (barely quasi-legal) funny business happens through official institutions.

A. "I lost my money while it was in my bank... I got it back, but nobody got in trouble!" B. "I lost my money while it was in crypto... I didn't get it back and nobody got in trouble!" I'm not really sure B sounds like much of an improvement over A.

I'm not saying they're right, just saying that "regulations will help" won't really be a big selling point for those who already have lost trust in such institutions.

Re: Woman loses over $44k after downloading third-party app to buy fish

#54

Earlier quoted context omitted.

"Look, idiot, if you do not perfectly follow all of this op sec, your money could disappear at literally any moment. In which case, sucks to be you. Oh, and also those crypto exchanges where people leave their money - those also have a good chance of disappearing in the night. Best to keep it under the digital equivalent of your mattress." I will stick with a bank which is regulated to protect my money, and heads wil…

I too love my bank which, like most others, is known for its lack of funny business, owing to the regulations that it definitely doesn't skirt at every opportunity (otherwise its execs would go to jail for doing crimes, obviously)

Like all those Wells Fargo execs? Uh huh.

Re: Woman loses over $44k after downloading third-party app to buy fish

#55
post #18

I've been seriously thinking of getting a separate phone which would just be used for financial apps. It seems apps are now required to log into a few of the institutions I use, and you can do virtually everything with their apps. Two factor seems to edging towards one factor, when a fingerprint can do everything.

Samsung offers a secure folder feature in recent versions of its phones that can quarantine banking apps from the rest of the phone.

I think it's based on their Knox framework.

Not sure how much security this adds overall but may still be worth considering.

Re: Woman loses over $44k after downloading third-party app to buy fish

#56

Earlier quoted context omitted.

"Look, idiot, if you do not perfectly follow all of this op sec, your money could disappear at literally any moment. In which case, sucks to be you. Oh, and also those crypto exchanges where people leave their money - those also have a good chance of disappearing in the night. Best to keep it under the digital equivalent of your mattress." I will stick with a bank which is regulated to protect my money, and heads wil…

I too love my bank which, like most others, is known for its lack of funny business, owing to the regulations that it definitely doesn't skirt at every opportunity (otherwise its execs would go to jail for doing crimes, obviously)

Probably a poor choice of words, but with a bank I have strong assurances that my account will not be drained tomorrow without possibility of recourse.

The government went above and beyond (generating moral hazard) in protecting SVB clients.

Re: Woman loses over $44k after downloading third-party app to buy fish

#57
post #39

Earlier quoted context omitted.

My parents have always had the policy of, "if I didn't call you, I don't want it." I didn't understand it as a kid (being told to hang up the phone a lot), but the policy has saved us all a lot of heartache and I've adopted it for myself.

I broaden this rule to everything: - If you approach a random person on the street for help, etc, 99 times out of 100 they will be helpful or at least not malicious. - If one out of the 100 people on the street approaches you , there's a decent chance they are that 1 in 100 people looking to take advantage of you. Bad people are the exception, there are just a lot of people.

When you approach a random person on the street, they should assume you are that 1 in 100.

Re: Woman loses over $44k after downloading third-party app to buy fish

#58
post #42

My wife had a $50k transfer initiated yesterday from her savings account (Bank of America). She was able to cancel the transaction by calling the bank in time, but still have no idea how it happened. Uses an iPhone 12 and hasn't downloaded any new apps in a while. Primarily uses a Mac Air but sometimes does banking on a Windows machine but is admin-managed by her (large) corp. Getting scary out there... Edit: Has 2FA…

My policy:

No financial apps on the phone.

Only other apps are from big companies with a reputation for strong security practices. That means no sports and weather apps, no restaurant or game apps, no Samsung or Tmobile apps, no TikTok.

Banking and brokerage are all in the browser, on a Chromebook, with no third-party extensions installed. This means no adblock and no other browsing on that user profile.

Most banks and brokerages don't offer FIDO 2FA, they all just want to do SMS. Their hardware tokens are a pain, but they work.

Re: Woman loses over $44k after downloading third-party app to buy fish

#59
post #12

I find it interesting that many people lament crypto about lack of transparency and how we went through this and that and that's why we have these sort of regulations in the legacy banking system, etc.. etc.. The reality is that, these regulations mostly exist in the US (through credit card protection), and some in the EU. For the rest of the world, if you got your account siphoned, you are mostly on your own. And ab…

It's the same if you're not an elite anywhere. I once had an ex-girlfriend use my debit card to buy $18,000 worth of stuff over a few weeks on Amazon before I noticed.

Amazon said there was nothing they could do because I had purchased products to send to her address before (true). Police said they couldn't do anything because there was no proof(false they were too lazy to do anything). Bank said they couldn't do anything because I should have changed my bank account information.

I had to beg the judge and prosecutor to even press charges but she never showed up and the warrant for her arrest (for not showing up 3x) got thrown out within days of being filed.

Looked into getting a civil suit going and was quoted around the same amount of money as was stolen. I guess New Jersey must be "the rest of world".

Re: Woman loses over $44k after downloading third-party app to buy fish

#60
post #40
post #20

Earlier quoted context omitted.

> I have a debit card from an EU bank. It's barely usable because every time I need to make a purchase, it has to go through 3DS and 50/50 the transaction gets rejected I have 2 debit cards and two credit cards from UK banks, and my partner has the same. I genuinely don't think I've ever had 3DS reject a transaction for either of us. > a fully dysfunctional system and yet somehow it has become solid because a "less"…

>I have 2 debit cards and two credit cards from UK banks, and my partner has the same. I genuinely don't think I've ever had 3DS reject a transaction for either of us. I get a 50/50 rate with local businesses in Mexico when paying online with European cards. I don't even bother with foreign cards for local government portals, the success rate is close to 0% when paying online. Also, many payments have to be authentic…

Reading between the lines a little bit here, it sounds like you're a digital nomad of sorts, with an EU bank account, and are attempting to pay "household bills" in a foreign country using details that don't quite add up.

If so, surely you can see that you are likely to be an absolute outlier and how your behaviour is likely almost indecipherable from actual fraud, unless you tell your bank your not actually living in the country (at which point presumably they close your account which is why you're doing this in the first place).

> I'm talking about normal banks, fintech banks, such as Revolut, are actually pretty good.

My bank accounts are NatWest and starling and CC's are Amex and NatWest - pretty traditional.

Post reply on HN