Live data from Hacker News

Gone (Almost) Phishin'

ma.tt

11–20 of 93 posts

Re: Gone (Almost) Phishin'

#11

> Apple Support lives on apple.com and getsupport.apple.com, nowhere else. Meanwhile: “Microsoft support uses the following domains to send emails: microsoft.com microsoftsupport.com mail.support.microsoft.com office365support.com techsupport.microsoft.com” [1] [1] https://learn.microsoft.com/en-us/troubleshoot/azure/general...

That's just for support. Legit password resets for example come from more random top level domains with "microsoft" in it, like microsoftonline.com

Another fun one is facebook, they use facebookmail.com or whatever else for serious security stuff

Re: Gone (Almost) Phishin'

#12
post #6

I told my parents: if they are ever called by anyone, to tell them "now is not a good time, please give me a case number and I'll call back when I do have the time." And then, this is important, look up the number for the customer service hotline online. I feel like this is a simple solution that works 100% of the time.

Mike Tyson once said "Everyone has a plan until they get punched in the mouth". I think you are underestimating the underhanded tactics and emotional tools available to scammers to keep you on the line.

Re: Gone (Almost) Phishin'

#14
post #6

I told my parents: if they are ever called by anyone, to tell them "now is not a good time, please give me a case number and I'll call back when I do have the time." And then, this is important, look up the number for the customer service hotline online. I feel like this is a simple solution that works 100% of the time.

My dad googled “amex phone number” and called the first result. I spent most of a Saturday cleaning up after the scammers.

I told him, next time call the number on the back of your card.

Re: Gone (Almost) Phishin'

#15

> Apple Support lives on apple.com and getsupport.apple.com, nowhere else. Meanwhile: “Microsoft support uses the following domains to send emails: microsoft.com microsoftsupport.com mail.support.microsoft.com office365support.com techsupport.microsoft.com” [1] [1] https://learn.microsoft.com/en-us/troubleshoot/azure/general...

That's just for support. Legit password resets for example come from more random top level domains with "microsoft" in it, like microsoftonline.com Another fun one is facebook, they use facebookmail.com or whatever else for serious security stuff

The number of redirects while using ms properties is just insane. It makes white listing them in uBO impossible because they redirect so fast, through multiple domains. The White listing is needed to sometimes make them work.

Re: Gone (Almost) Phishin'

#17

> Apple Support lives on apple.com and getsupport.apple.com, nowhere else. Meanwhile: “Microsoft support uses the following domains to send emails: microsoft.com microsoftsupport.com mail.support.microsoft.com office365support.com techsupport.microsoft.com” [1] [1] https://learn.microsoft.com/en-us/troubleshoot/azure/general...

That's just for support. Legit password resets for example come from more random top level domains with "microsoft" in it, like microsoftonline.com Another fun one is facebook, they use facebookmail.com or whatever else for serious security stuff

Is this because at one point @facebook.com was a valid communication method? Great concept to be fair, but once you pull back the first layer you can immediately see its problems.

Re: Gone (Almost) Phishin'

#18
post #15

Earlier quoted context omitted.

That's just for support. Legit password resets for example come from more random top level domains with "microsoft" in it, like microsoftonline.com Another fun one is facebook, they use facebookmail.com or whatever else for serious security stuff

The number of redirects while using ms properties is just insane. It makes white listing them in uBO impossible because they redirect so fast, through multiple domains. The White listing is needed to sometimes make them work.

It's a thing with google and facebook too. If you login to youtube or go to facebook account settings, at least 3 redirects through very random places. I guess 3 is not a lot compared to microsoft's 15.

Re: Gone (Almost) Phishin'

#19
Currently my device has no passwords, and the only apps that lead to anything personal are browsers, and then sign into my website/email. I have eliminated online banking, except for allowing people to pay me through direct deposit, which I confirm on my once a week trip to an actual bank. Very occasional online purchases use a dedicated credit card. The above, I believe makes me a smol, challenging target, and I use the many many attempts to fish through, text, email, and voice, as practice sessions to refine my customer faceing presence, and answer all calls, and chearfully deflect anything or anyone that is not a legitimate human and/or customer, in under 10 seconds. Going forward I would train any office helpers to use the same methods on any work devices.

Re: Gone (Almost) Phishin'

#20

> Apple Support lives on apple.com and getsupport.apple.com, nowhere else. Meanwhile: “Microsoft support uses the following domains to send emails: microsoft.com microsoftsupport.com mail.support.microsoft.com office365support.com techsupport.microsoft.com” [1] [1] https://learn.microsoft.com/en-us/troubleshoot/azure/general...

That's just for support. Legit password resets for example come from more random top level domains with "microsoft" in it, like microsoftonline.com Another fun one is facebook, they use facebookmail.com or whatever else for serious security stuff

>Legit password resets for example come from more random top level domains with "microsoft" in it, like microsoftonline.com

Or aka.ms

Post reply on HN