Live data from Hacker News

Thanks FedEx, This Is Why We Keep Getting Phished (2024)

troyhunt.com

51–60 of 86 posts

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#51
When I lived in Sunnyvale, CA, I got text that said "Renew your alarm license online at my-alarm-license-renew.info"

You do need a residential alarm license in Sunnyvale, but I was sure this was a scam. I called the city. It was the real address, and they were mystified as to why I'd call them. (I sent in a check to avoid the $1.50 processing fee, but that was before 50% of checks get stolen in the mail.)

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#52
post #36
post #22

Earlier quoted context omitted.

With calls, it's easier: if you get an incoming call with someone is asking you for money, you hang up and call back using the number for that organization that you've found yourself from official sources. Never trust incoming calls when it comes to money.

With calls, drop any non-prearranged calls, period. Over a few years I burned that approach into my parents. It was tough, but worth it.

My mom used to know what to do, but with dementia, she lost that ability. We now have a call block on her landline, so only a small whitelist can get through.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#53

If I had a nickel for every post I saw on HN front page involving companies confusing people on phishing-like patterns today, I would have two nickels. Which is not a lot but still weird that it happened twice. https://news.ycombinator.com/item?id=49172834

Consider yourself lucky. This happens very frequently these days.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#54

In a recent example my step-mother, who is constantly getting cloud storage full scam emails, received an email from Google about 75% full storage that appears to be fully valid. However all the links use a domain c.gle and whois c.gle errors with "getaddrinfo(whois.nic.gle): Name or service not known". whois gle however does work. I was not sure of the validity of c.gle myself, my step-mother would have no idea.

not that it really helps to know now, but .gle is a TLD operated by Google. the only domains on a .gle domain will be Google (in theory). Plus, a single letter domain (on any TLD), like c.gle would be expensive to burn on a phishing scam. But no one should need to know this. I don't know what's so wrong about just using google.com, or even .google for anything user facing... I understand the idea that they want an of…

I assume it's tied somehow to SMS character limits, where somebody decided a couple extra letters of content was worth it somehow.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#55
post #30
post #25

Earlier quoted context omitted.

I know that, does my grandmother? In the heat of the moment, will she remember that I told her 2 years ago when they call her?

We've desperately needed secure identity verification for business callers for years, so we can start the decades long process of changing people's instincts about it. There's no good reason any business should be able to contact me without whoever is calling cryptographically proving they're that business and my phone showing the name and logo from a copy or mirror of an official database. It should just be a standa…

But for which country, state, province, or city?

Put in the hierarchical angle, and we're kind of back at domain names.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#56
post #30
post #25

Earlier quoted context omitted.

I know that, does my grandmother? In the heat of the moment, will she remember that I told her 2 years ago when they call her?

We've desperately needed secure identity verification for business callers for years, so we can start the decades long process of changing people's instincts about it. There's no good reason any business should be able to contact me without whoever is calling cryptographically proving they're that business and my phone showing the name and logo from a copy or mirror of an official database. It should just be a standa…

[deleted]

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#57

Earlier quoted context omitted.

Also this was never a real problem. "All the good names are taken" is true if you insist that every name which isn't taken is a bad name but otherwise obviously false. The same exact "Somebody already had the good ideas, it's not my fault I'm just too late" whining can be seen centuries ago. People who live in a world with no electricity, absolutely convinced that every product which will ever be wanted already exist…

There are plenty of Chinese domains that are just numbers. If they can build entire businesses off of that, so can anybody. There's of course a ton of risk around scammers winning SEO and adwords competitions.

It works as long as the domain doesn't have a '4' in it or multiples of '4'

https://www.google.com/search?client=firefox-b-d&q=china+unl...

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#58
post #19

> Why are the "D" and the "T" capitalised? Dodgy AF! You should be more respectful, you’ve clearly received a Message direct from President Trump!

That would actually make it an order of magnitude dodgier-AF. Dodgiest-AF?

I'd rather be scammed by people who can at least theoretically go to jail for their crimes.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#59
post #58
post #19

> Why are the "D" and the "T" capitalised? Dodgy AF! You should be more respectful, you’ve clearly received a Message direct from President Trump!

That would actually make it an order of magnitude dodgier-AF. Dodgiest-AF? I'd rather be scammed by people who can at least theoretically go to jail for their crimes.

[deleted]

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#60
I keep getting this message and it might be legit, but I have no idea:

> BlueShieldCA: ANON, you have an important benefits message in your health feed. blueshieldca.customerfeed.com/a/abcd12345 Txt help/stop Msg&DataRatesApply

If I login to BSCA, their messaging section shows nothing. But some threads on the internet make “customerfeed” seem like a real service.

Post reply on HN