Live data from Hacker News

Thanks FedEx, This Is Why We Keep Getting Phished (2024)

troyhunt.com

21–30 of 86 posts

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#21
>Our Australian Communications and Media Authority body (ACMA) recently reported 336M blocked scam SMSs

Australia has mandatory identity verification for getting a SIM card.

The FCC is now proposing [1] to add a rule to require government ID, physical address, and alternative phone number for every phone line in the US.

KYC for phone lines would cause more IDs to be leaked, and more American dollars lost to scammers and fraudsters.

[1] https://www.404media.co/fcc-wants-to-kill-burner-phones-by-f...

Discussion:

https://news.ycombinator.com/item?id=48462308

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#22
post #7

There is a similar issue with the IRS. If you call the IRS they use a text-to-speech system to generate the voice for their call tree IVR. The problem is, it's a commercially available system that fake call center scammers also use, so they sound identical. It also doesn't help that it sounds fake and scammy, so you can't use that as a signal to avoid the number you're calling, either

With calls, it's easier: if you get an incoming call with someone is asking you for money, you hang up and call back using the number for that organization that you've found yourself from official sources. Never trust incoming calls when it comes to money.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#23
I wouldn’t assume that email is genuine. “Hi,” and “…the B-point link that I’ve sent”? Dodgy AF.

My first suspicion would be that they’re getting hold of the Fedex invoice data, via a software compromise or an insider.

If it really is real, then wow, FedEx Australia sounds like it’s one guy operating out of a shipping container down at the docks.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#25
post #22
post #7

There is a similar issue with the IRS. If you call the IRS they use a text-to-speech system to generate the voice for their call tree IVR. The problem is, it's a commercially available system that fake call center scammers also use, so they sound identical. It also doesn't help that it sounds fake and scammy, so you can't use that as a signal to avoid the number you're calling, either

With calls, it's easier: if you get an incoming call with someone is asking you for money, you hang up and call back using the number for that organization that you've found yourself from official sources. Never trust incoming calls when it comes to money.

I know that, does my grandmother? In the heat of the moment, will she remember that I told her 2 years ago when they call her?

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#26

>Our Australian Communications and Media Authority body (ACMA) recently reported 336M blocked scam SMSs Australia has mandatory identity verification for getting a SIM card. The FCC is now proposing [1] to add a rule to require government ID, physical address, and alternative phone number for every phone line in the US. KYC for phone lines would cause more IDs to be leaked, and more American dollars lost to scammers…

The phishing in Australia came from uncontrolled SMS gateways which allowed for sender impersonation, not physical phones with SIM cards. They've recently partly closed the loophole by requiring providers to register sender names.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#27

>Our Australian Communications and Media Authority body (ACMA) recently reported 336M blocked scam SMSs Australia has mandatory identity verification for getting a SIM card. The FCC is now proposing [1] to add a rule to require government ID, physical address, and alternative phone number for every phone line in the US. KYC for phone lines would cause more IDs to be leaked, and more American dollars lost to scammers…

Alternative Phone Line? You want the bootstrapping problem?

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#28
post #4

I swear, the proliferation of random ".xyz" type gTLD is not making things any easier in stopping non tech people from clicking on phishing links. There's so damn many of them. Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose... List of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt

I'm not convinced that would help. The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain. Its just attempting to work around incompetence, which always just shows up again somewhere else.

> The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain.

I think this might have some parallels with the 'shadow IT' problem in large corporations and organizations. Some work group or department or project within a very large entity decides it needs to implement something (like shipment tax payment notifications, as in the linked example) and decides to DIY it rather than going through the full process to do it with their own domain.

Reminds me a bit of large businesses where some sales or CRM-related department goes out and starts buying email-blasting/email-list features from some mailchimp-type company and only later on realizes they need to talk to whoever controls the domain to get approval for proper outbound DKIM in the DNS records, etc.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#29
post #10

In a recent example my step-mother, who is constantly getting cloud storage full scam emails, received an email from Google about 75% full storage that appears to be fully valid. However all the links use a domain c.gle and whois c.gle errors with "getaddrinfo(whois.nic.gle): Name or service not known". whois gle however does work. I was not sure of the validity of c.gle myself, my step-mother would have no idea.

Whois has been replaced by RDAP.

As far as I am able to find Google does not provide an RDAP server for gle either.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#30
post #25
post #22

Earlier quoted context omitted.

With calls, it's easier: if you get an incoming call with someone is asking you for money, you hang up and call back using the number for that organization that you've found yourself from official sources. Never trust incoming calls when it comes to money.

I know that, does my grandmother? In the heat of the moment, will she remember that I told her 2 years ago when they call her?

We've desperately needed secure identity verification for business callers for years, so we can start the decades long process of changing people's instincts about it.

There's no good reason any business should be able to contact me without whoever is calling cryptographically proving they're that business and my phone showing the name and logo from a copy or mirror of an official database.

It should just be a standard part of business registration processes.

Post reply on HN