Live data from Hacker News

The golden age of scammers: AI-powered phishing

mailgun.com

131–140 of 143 posts

Re: The golden age of scammers: AI-powered phishing

#132

Earlier quoted context omitted.

People realize the risk, they just think it can't happen to them personally , and/or just don't care because they personally aren't going to bear the risk. People run businesses the way they drive their cars, i.e. selfishly and arrogantly.

Are all people bad drivers? Technology gives diffusion of responsibility. And business gives limited liability. Put them together and you have magnified sense of agency and invulnerability. But without wheels and a windshield people couldn't travel at 100 miles an hour. The question is how gracefully the person at the wheel handles that. Are you a gentleman in a Jaguar or a BMW driver? [0] [0] https://www.fastcompany…

It's not a question of how gracefully the person behind the wheel handles it. There is a certain moral expectation and minimum standard of handling, and this expectation is more often than not enforced by law and/or threat of civil suit, sometimes with severe penalties for deviating from expectation. That legal framework exists precisely because individuals cannot be trusted to handle it properly.

The natural set of incentives does not work well with human psychology. It does not prevent mishandling of motor vehicles, or at least fails to prevent it in enough cases that additional disincentives are needed, to ensure the safety of the public.

Stated another way: Enough people are bad enough drivers that we need laws and civil liability to create additional incentives against bad driving. The threat of collision, property damage, injury, or death to oneself, passengers, and people outside the vehicle is clearly not sufficient.

Driving is actually a great analogy, but maybe not for the reason you intended. If we relied only on individuals to act responsibly, the roads would be much more dangerous than they currently are.

Re: The golden age of scammers: AI-powered phishing

#133
using ai might be bringing out some low-effort success but at the end of the day, it is skill issue on our front.

a common heuristic to look out for is "badly"-written/spoken communication. the "AI vs Actual Indian" comment and nigerian prince emails stand out for most people, but they still ended up working well enough to become this wide-spread.

you just need to employ some critical thinking now for most external communication now. it is no different from some highly-motivated scammers doing it the old-fashioned way. at the end of the day, we are trying to replicate the success of some native-speaking teens (https://news.ycombinator.com/item?id=32959001).

Re: The golden age of scammers: AI-powered phishing

#134
post #100

Earlier quoted context omitted.

Even a password can be changed if there's a compromise. Biometrics are bad because they can be imitated, but not changed. A breach is permanent

good point, but that was left out of the earlier statement about inference. I suppose I should have inferred it however.

Yea, my bad I guess. I tend to think people mostly get that biometrics are, well, mostly immutable and that not being able to switch them up in response to a suspected breach is a huge inherent weakness. So the only defense I really get of them from anyone is that the effort for the user is minimized while the effort for the attacker is still fairly high. The problem with that is why I mention inferrability: The existence of a computer system that can authenticate via a biometric implies the existence of one that can capture and spoof it, and we don't have any reason to believe this involves, say, more of a cost disparity than cracking a password, let alone anything approaching a strong one-way function. If your face is your key, do you start hiding your face on the street so no one can steal it? Same thing for behaviorals

Re: The golden age of scammers: AI-powered phishing

#136
post #77

Earlier quoted context omitted.

> Tbh the browser/email client makers are complicit in these phishing attempts for hiding the URLs and the actual email addresses. It's worse. Research "Scamicry". Big business now is so fake, such a grift, drenched in PR deception, and lacking integrity and trustworthiness, there isn't much space left between what is "legitimate" and what is a scam. If businesses like Google or Facebook hide URLs and email addresses…

I beat that drum so long it turned into beating my head against a wall. The last two companies I worked for insisted that customer account security was the highest priority, but as soon as I said we needed to stop hiding links to our own website behind Hubspot tracking URLs so we don't train our customers to click links that look like gobbledygook garbage, the marketing team melted down and it became clear where user…

I like your priest's style. Maybe more cybersecurity and anti-fraud from the pulpit is the way to go now the digital realm has failed. I'll have a word with our vicar, see if we can't squeeze a bit of Kevin Mitnick and Julian Assange in between Proverbs and Revelations.

Re: The golden age of scammers: AI-powered phishing

#137

Earlier quoted context omitted.

Are all people bad drivers? Technology gives diffusion of responsibility. And business gives limited liability. Put them together and you have magnified sense of agency and invulnerability. But without wheels and a windshield people couldn't travel at 100 miles an hour. The question is how gracefully the person at the wheel handles that. Are you a gentleman in a Jaguar or a BMW driver? [0] [0] https://www.fastcompany…

It's not a question of how gracefully the person behind the wheel handles it. There is a certain moral expectation and minimum standard of handling, and this expectation is more often than not enforced by law and/or threat of civil suit, sometimes with severe penalties for deviating from expectation. That legal framework exists precisely because individuals cannot be trusted to handle it properly. The natural set of…

> Driving is actually a great analogy

Not sure we should stretch the car analogy too far, but you're right about rules and regulations. Most people can be relied on to be considerate, but that one percent of assholes ruin it for everyone.

From where I'm standing that one percent is basically American big tech. Problem is, we have traffic lights, stop signs, speed limits, and highway cops patrolling, but the big US corporations just drive like assholes and get away with it anyway. In fact they're more like terrorists that drive a truck into a crowd of people, and we all stand around helplessly and wail... "what can be done?!"

Now, if this was a proper American tale, there would be a Blues Brothers style 500 car chase, and at the last moment, just as the bigtechmobile is about to jump the unfinished bridge Dukes of Hazard style, Bruce Willis swoops down in an Apache attack helicopter and blows them off the map!

oops I think I've stretched the car analogy too far.

Re: The golden age of scammers: AI-powered phishing

#139
post #75

I'm kind of amazed how slow 'AI phishing' has been to roll out. The technology for customised text based attacks at scale has been available at least since Llama was open sourced. The tech for custom voice and image based attacks is basically there too with whisper / tortoise and stable diffusion - though clearly more expensive to render. I'm honestly not sure why social networks aren't being leveraged more to target…

The ROI on scams based in Indian call centers is already huge. They recently took my mom for $25k for what was a few hours of “work” over the span of two days. When I reviewed their communications and got the full story from my mom they’re in some ways laughably bad and in other ways very cunning. Turns out it all started with a comically bad initial e-mail, pop-up, and then remote access. Then follow-up calls and te…

The “comically bad e-mail” is a test to see if you have a critical eye or not/willing to gloss over things/give the benefit of doubt

Re: The golden age of scammers: AI-powered phishing

#140

Earlier quoted context omitted.

I’m skeptical we can develop effective ones, due to the fact that we have been unable to solve non-AI phishing problems but I welcome their attempt.

When Google added Yubikeys it reduced phishing internally to zero. https://krebsonsecurity.com/2018/07/google-security-keys-neu... I adore my Yubikey.

Good article, but that does not cover or solve B2B email compromise/scams. It’s impossible to take the human out of the box here.
Post reply on HN