...and to press #4 to talk to their security department Does something bad happen by pressing a number on dial pad or they just transfer to a human to talk to. Just curious because I heard from someone that pressing a button was good enough for the spammer who is calling you, but it does not makes sense how that can harm.
Your PBX has been hacked
21–30 of 63 posts
Re: Your PBX has been hacked
#22I've been wondering increasingly often over the past few years why we tolerate a phone network that allows for caller ID spoofing. I don't see how a system analogous to BCP38 would have any significant downsides, and there's a huge demand for anything that stems the rising tide of fraudulent robocalls.
There are significant downsides to technically prohibiting caller ID spoofing. First, you would no longer be able to preserve caller ID when forwarding calls. Consider how much less useful Google Voice would have been if you couldn't see the caller ID of calls forwarded to you. Second, in VoIP, outgoing calls (termination) and incoming calls (origination) are completely decoupled services. This is really nice because…
Re: Your PBX has been hacked
#23...and to press #4 to talk to their security department Does something bad happen by pressing a number on dial pad or they just transfer to a human to talk to. Just curious because I heard from someone that pressing a button was good enough for the spammer who is calling you, but it does not makes sense how that can harm.
I have however seen a slightly different breed of attack, where an attacker calls a victim (usually a switchboard attendant) and asks to be transferred to extension 9190. If this happens, they dial the rest of a 1-900 number and rack up charges.
Re: Your PBX has been hacked
#24Earlier quoted context omitted.
It really isn't a big deal though, CID/ANI should never be trusted to identify the caller anyway.
That's only because we let that system be gamed. It doesn't have to be that way . Telcos always know who they're billing for a call; they have the capability to make caller ID reliable.
tldr: The technology isn't the only thing that's over 100 years old, the business practices are also extremely broken too. And telcos are not an honest bunch.
Re: Your PBX has been hacked
#25Re: Your PBX has been hacked
#26Earlier quoted context omitted.
There are significant downsides to technically prohibiting caller ID spoofing. First, you would no longer be able to preserve caller ID when forwarding calls. Consider how much less useful Google Voice would have been if you couldn't see the caller ID of calls forwarded to you. Second, in VoIP, outgoing calls (termination) and incoming calls (origination) are completely decoupled services. This is really nice because…
I think the idea is that caller ID forwarding should be implemented in some authenticated or verifiable way. I hesitate to call credential forwarding a solved problem, but surely a modern protocol design could do a lot better than the current free-for-all, I-am-who-I-say-I-am system.
Re: Your PBX has been hacked
#27Second, how does he know the bank's phone system was compromised, just because he couldn't reach it? I'm no expert on phone systems, but it seems like any number of other possibilities are at play here. Like, the bank's phone system actually being down and the call minion he talked to not being in a position to know anything about it (common). Or maybe the call center was up, but it was inaccessible for a brief period of time. I can't imagine phone systems are very reliable. Again, an unsubstantiated conclusion.
Third, he also concludes the bank's records were compromised, leaking his phone number. I get fake calls from "banks" a few times per year, even ones with the right names. I see no reason to assume the bank's records have been compromised, just because you coincidentally got a fake call with your bank's name. Either it was coincidence that the name matched his current bank, or the information leaked through the usual means (bank selling your information to third-parties, who turn out to be unscrupulous or have their information stolen; or any retailer you've used your banks credit/debit card at selling your information).
Fourth, how does any of this lead to the conclusion that "[w]e’ve lost control of our phone network"? These were all typical phracker activities that have been occurring for decades.
And finally, the mention of the Do Not Call list is also a non sequitur. It's only loosely related to what the author previously mentioned.
I'm all for being security aware, but I'm not seeing the story here. In my honest opinion, this looks like a big pile of FUD with no useful substance and it surprises me that it's on the HN front page right now.
Re: Your PBX has been hacked
#28I've been wondering increasingly often over the past few years why we tolerate a phone network that allows for caller ID spoofing. I don't see how a system analogous to BCP38 would have any significant downsides, and there's a huge demand for anything that stems the rising tide of fraudulent robocalls.
It really isn't a big deal though, CID/ANI should never be trusted to identify the caller anyway.
Re: Your PBX has been hacked
#29This article is making all sorts of illogical conclusions from the stories it's telling. First, how was the company hacked "through their corporate phone system"? They were hacked through social engineering and malware. The phone network was just used for reconnaissance. I'm sure hackers have been mining phone networks for decades. Not that this story isn't interesting, but the conclusion doesn't lead from the tale.…
If you're talking about a good CO switch like a 5ESS or DMS-100, they're extremely reliable, well engineered machines. They consistently meet and exceed five nines reliability.
Re: Your PBX has been hacked
#30Phone numbers are going to (eventually) disappear. They are inefficient, hard to remember and not human-friendly (they are great for computer-based routing :P ). Easier thing we can do, is to map them down like we do it with IPs and domain names, but as usual, this is far from being a practical solution. Best think is to let conventional telephony die and VoIP take over its place.
Right, because voip has a reputation for sounding great and being reliable. (/s)