>Keep your crypto on an exchange
This gets the same level of sympathy as a person without backups suffering from data loss.
261–270 of 677 posts
>Keep your crypto on an exchange
This gets the same level of sympathy as a person without backups suffering from data loss.
> The attacker already had access to ... my Google Authenticator codes, because Google had cloud-synced my codes. This was such an obvious mis-feature I can't believe they actually rolled it out. For those using Google Authenticator you can and should disable cloud sync of your TOTP codes.
Don't disable cloud sync unless you have a backup of all your TPTP secret keys. It's dangerous to advise people to disable cloud sync without mentioning backups. Being locked out of thousands of dollars in your crypto account is as damaging as losing that crypto to hackers.
Email spoofed from legal@google.com and he read it in Google's Gmail app for iOS. The original title was correct: "Google Helped It Happen"
> So when he asked me to read back a code — supposedly to prove I was still alive — in a moment of panic, I did. I am not clear how the account access occurred. What code did he read? He voluntarily read his own 2FA code from his Authenticator?
Seems likely to be an SMS code, Google will use a phone for recovery if you claim to have no other access. This person read an SMS code — one that explicitly says not to give it to anyone — and then they said "I work in tech. I design authentication experiences. I know you’re not supposed to share verification codes! And yet, I got phished." This person's greatest mistake was answering the phone to a stranger. Who kn…
This is key. I would "never" fall for a scam like this. But who knows for sure? I would also never cheat on my partner, but can I say with 100% certainty that some insane situation can't possibly ever come up where my many layered defenses are compromised? Can some sufficiently charismatic individual deliver a perfect AI script to me based on info from 5 other breaches, in my brother's voice, to make me give up a 2fa token in an emergency? Maybe! So just never answer the phone, ever
To Me this quote says so much about the crypto space more than anything.
Also not shocked it was crypto theft.
Earlier quoted context omitted.
Well easy to say, but if you are working in the real world, then unknown callers may be important - i.e. FedEx trying to push your package through the customs and if they can not contact you, your package goes either back or is destroyed.
Legitimate callers for events you initiated leave messages. The correct avenue for critical notifications not initiated by you is still paper mail.
>Fall for spoofed email sender >Keep your crypto on an exchange This gets the same level of sympathy as a person without backups suffering from data loss.
Mistake cost him 80k. Author is feeling burnt, but the cost is the cost at transaction time.
Extending this further, based on the stated value it looks like he probably had 40 or 50 ethereum. He might have bought them for a fraction of today's price - say $50 - so might only be out $2500 based on cost at transaction time...
A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
- from a number with no results on Kagi search
- claiming to be the online banking support of my bank
- asking me to read them a code sent to me via SMS
and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration because I had refused to engage with their support agent.
I then had to create a new login in their app, call the phone number on their letter and read that guy the SMS code and, to my surprise, that was the only !!! authentication needed to activate the new login credentials that I had just created.
(BTW, this was one of the top 100 largest banks worldwide)
It's almost like some companies are training you to fall for scams.
EDIT: This specific instance was Deutsche, but Chase has the exact same horrible habit of calling and then asking for an OTP code.
The load bearing question is, why didn't the attacker also clear out OP's bank account, retirement savings, and max out his credit cards? Unfortunately, the difference is that banks care literally at all about their customers accounts being emptied.
And transferring money from a bank or brokerage account takes time. Enough time that anyone paying attention should be able to report the transfer as fraudulent before it completes and have the account frozen.