Live data from Hacker News

The golden age of scammers: AI-powered phishing

mailgun.com

31–40 of 143 posts

Re: The golden age of scammers: AI-powered phishing

#31
post #22

Earlier quoted context omitted.

I mean SSNs are the worst possible authentication mechanism and yet we still have to freak out every time they're leaked. Security practices are so utterly backwards everywhere that it's quite apparent no one powerful is incentivised to care even a little bit

what's the practical alternative?

Not pretending a GUID constitutes a security measure in the first place? It's just not the right tool for the job in any sense

Re: The golden age of scammers: AI-powered phishing

#32

It’s actually worse than that - AI powered phishing sites will also copy your device profile and mouse, gesture and keyboard signature and use this to get past common anti-fraud techniques like device fingerprinting and behavioural biometrics.

What does AI have to do with capturing inputs ?

Not just capturing, but training on captured inputs to replicate the fingerprint.

Re: The golden age of scammers: AI-powered phishing

#33

Hey, just going to say what I've been telling folks IRL, if you are reading this, and your parents and family members aren't tech savvy, you need to set them up with two factor authentication now. Because you know how to do that, and it's so much easier than helping them when they get hacked.

MFA doesn't stop this kind of phishing. If you're tricked to put in your password, you'll likely put in your 2FA code right after. A yubi key or device passkey that uses webauthn can stop these methods, since the domain seeking authentication is checked and won't authenticate unless it's the original domain.

Even then, that won't help scams and fraud that just trick you into sending money, or direct you to install malware.

Re: The golden age of scammers: AI-powered phishing

#34
post #6

It’s actually worse than that - AI powered phishing sites will also copy your device profile and mouse, gesture and keyboard signature and use this to get past common anti-fraud techniques like device fingerprinting and behavioural biometrics.

I mean, the mere existence of said biometrics imply that they're inferrable and thus bad security, like basically all biometrics

basically everything that retains the same structure between two occurrences can be inferred. Only randomness cannot be inferred.

But true randomness is not useful for determining if you are who you say you are.

Re: The golden age of scammers: AI-powered phishing

#36
post #6

It’s actually worse than that - AI powered phishing sites will also copy your device profile and mouse, gesture and keyboard signature and use this to get past common anti-fraud techniques like device fingerprinting and behavioural biometrics.

I mean, the mere existence of said biometrics imply that they're inferrable and thus bad security, like basically all biometrics

I think this is one of those "the only thing that's worse is everything else" situations. Surely there are solutions, but I doubt there are solutions banks and payment processors would be interested in paying for, and at least the US government isn't particularly interested in compelling banks to do anything expensive.

Re: The golden age of scammers: AI-powered phishing

#38

Hey, just going to say what I've been telling folks IRL, if you are reading this, and your parents and family members aren't tech savvy, you need to set them up with two factor authentication now. Because you know how to do that, and it's so much easier than helping them when they get hacked.

I set up 2fa codes through Google Authenticator with my family, and employees. That is to say I generate a QR code, we all scan it while we are in the room together and can use it at any time to check who we are really speaking to. This is in addition to a question/answer pair that we have had with my immediate family for years (duress question, duress answer, standard question, standard answer).

Re: The golden age of scammers: AI-powered phishing

#40
post #39

I expect that with AI, we'll be less able to rely on the heuristic of bad grammar to easily detect phishing. That one flaw gave the phishers away so often, and made it so obvious ...

It goes the other way now, overly verbose responses and perfect grammar sets off the warning bells.
Post reply on HN