I expect that with AI, we'll be less able to rely on the heuristic of bad grammar to easily detect phishing. That one flaw gave the phishers away so often, and made it so obvious ...
The bad grammar is on purpose. I know of two possible reasons: * Bayesian poisoning https://en.wikipedia.org/wiki/Bayesian_poisoning * Weeding out poor mark candidates https://josephsteinberg.com/why-scammers-make-spelling-and-g...
The golden age of scammers: AI-powered phishing
61–70 of 143 posts
Re: The golden age of scammers: AI-powered phishing
#62> Is it your fate now to do due diligence on every email you receive? Always has been. Tbh the browser/email client makers are complicit in these phishing attempts for hiding the URLs and the actual email addresses. Put them back!
It's worse. Research "Scamicry".
Big business now is so fake, such a grift, drenched in PR deception, and lacking integrity and trustworthiness, there isn't much space left between what is "legitimate" and what is a scam.
If businesses like Google or Facebook hide URLs and email addresses that's not a casual "mistake". It's because that's to their profitable advantage to do so. And they know it puts you in harms way. So yes, they're complicit in scams.
To make themselves a little more competitive businesses are always learning from scammers, meanwhile good scammers keenly learn from businesses to look more legit. Some ransomware "services" even have better customer support than billion dollar companies. And big business is certainly using the same AI tools as cybercriminals.
So a problem isn't how clever and scurrilous scammers have gotten, it's how far legitimate services have fallen so that ordinary folk struggle to know the difference.
How can we trust our own insticts for selecting what is good and wholesome from what is rotten, when there are few moral differences? The only difference resides in a digital identifier.
Re: The golden age of scammers: AI-powered phishing
#63Re: The golden age of scammers: AI-powered phishing
#64Hey, just going to say what I've been telling folks IRL, if you are reading this, and your parents and family members aren't tech savvy, you need to set them up with two factor authentication now. Because you know how to do that, and it's so much easier than helping them when they get hacked.
MFA doesn't stop this kind of phishing. If you're tricked to put in your password, you'll likely put in your 2FA code right after. A yubi key or device passkey that uses webauthn can stop these methods, since the domain seeking authentication is checked and won't authenticate unless it's the original domain. Even then, that won't help scams and fraud that just trick you into sending money, or direct you to install ma…
Re: The golden age of scammers: AI-powered phishing
#65Earlier quoted context omitted.
For laughs
Now they have a recording of you saying yes that can used to justify signing you up for services that you never intended to.
Re: The golden age of scammers: AI-powered phishing
#66Artificial Intelligence vs. Actually Indian
Probably the funniest thing here is that this call reached me despite the fact that I am French, living in France. And so I really wonder how they ended up calling me. I mean, chance I would understand some English speaker with an Indian accent (I like how it sounds, but it’s definitely an additional difficulty as a non-native).
I read here and there how extortion of old USA citizens by some organized Indian citizens is really a thing. To my mind the main issue at stake is that we have global level communication facilities, extremely high wealth disparities at world scale, and no compelling global social endeavor to reach an harmonization of human quality of life for everyone. I don’t mean the latter is on the official agenda of most countries out there either, but at global scale it’s obviously even worst.
With all that in mind, blaming a whole nation for the illegitimate actions of some minority in the country, all the more when the international geopolitical context itself is all but fair, is probably not going to solve any issue.
Re: The golden age of scammers: AI-powered phishing
#67Re: The golden age of scammers: AI-powered phishing
#68Earlier quoted context omitted.
I mean SSNs are the worst possible authentication mechanism and yet we still have to freak out every time they're leaked. Security practices are so utterly backwards everywhere that it's quite apparent no one powerful is incentivised to care even a little bit
what's the practical alternative?
Just give it to everyone. Today, it can likely be embedded in a cell phone instead of separate physical card.
Re: The golden age of scammers: AI-powered phishing
#69Earlier quoted context omitted.
I mean SSNs are the worst possible authentication mechanism and yet we still have to freak out every time they're leaked. Security practices are so utterly backwards everywhere that it's quite apparent no one powerful is incentivised to care even a little bit
what's the practical alternative?
Re: The golden age of scammers: AI-powered phishing
#70Earlier quoted context omitted.
MFA doesn't stop this kind of phishing. If you're tricked to put in your password, you'll likely put in your 2FA code right after. A yubi key or device passkey that uses webauthn can stop these methods, since the domain seeking authentication is checked and won't authenticate unless it's the original domain. Even then, that won't help scams and fraud that just trick you into sending money, or direct you to install ma…
surely it won't hurt. at minimum, it makes the attacker's job much harder -- their window to exploit becomes max 30 seconds instead of however long you don't change your password.