Earlier quoted context omitted.
I just want the major cellphone companies numbers to show up correctly and everything else can be ???. That does not require fixing all these other systems.
How exactly could they do that for calls originating outside their network? Most spammers are using VoIP, not cell phones on major US companies.
Voice Phishing Scams Are Getting More Clever
101–110 of 226 posts
Re: Voice Phishing Scams Are Getting More Clever
#102The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…
The problem here is the ability to spoof caller ID. This should not be possible. Think of incoming CLID in the same way that you do email From: addresses. Often and easily faked. Funnily enough both my office PBX and SMTP daemon check incoming CLID/HELO and drop attempts to spoof their own identity. Its not a particularly sophisticated protection these days but is one of many, many rules. Actually, now I come to thin…
You can, technically, write anything in it and there’s no way to guarantee it’s authentic.
Re: Voice Phishing Scams Are Getting More Clever
#103The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…
The problem here is the ability to spoof caller ID. This should not be possible. Think of incoming CLID in the same way that you do email From: addresses. Often and easily faked. Funnily enough both my office PBX and SMTP daemon check incoming CLID/HELO and drop attempts to spoof their own identity. Its not a particularly sophisticated protection these days but is one of many, many rules. Actually, now I come to thin…
Re: Voice Phishing Scams Are Getting More Clever
#104Earlier quoted context omitted.
The problem here is the ability to spoof caller ID. This should not be possible. Think of incoming CLID in the same way that you do email From: addresses. Often and easily faked. Funnily enough both my office PBX and SMTP daemon check incoming CLID/HELO and drop attempts to spoof their own identity. Its not a particularly sophisticated protection these days but is one of many, many rules. Actually, now I come to thin…
Curious: how does the PBX verify caller ID? Do you know how it works in practice?
However, just like email the CLID can be trivially faked and just like email, the lookup in your contacts is then wrong and potentially dangerous. In the case of telephony, if you subscribe to the BT service (I presume it still exists) that will return a name given a CLID (just like DNS for a price!) then you may end up with completely the wrong thing on your display.
Just to re-iterate the point: a PBX/phone/whatever cannot ... CANNOT ... verify CLID (Calling Line IDentification) it can only show what is presented to it.
Remember this, please: CLID is nominally under the control of the caller and could also be changed in transit. It should absolutely NOT be considered authoritative in any way.
Re: Voice Phishing Scams Are Getting More Clever
#105I'll give you the flip side of the scammer's deterioration of trust in the phone... a few months back I got a phone call from what appeared to be my bank, and they were asking me about a fraudulent charge that I didn't recognize. Worried that this was the beginning of a scam, I delayed a bit on the phone while I logged in independently to my bank account... and lo, yes, indeed, there was a fraudulent charge to my acc…
For those worried about a situation like this, I set up automated purchase alerts on my credit cards and withdrawal alerts on my bank accounts. I see it all in close-enough-to-real-time, and it's helped me catch fraud before the banks did at least twice in the past few years.
Re: Voice Phishing Scams Are Getting More Clever
#106The issue, as I understand it, is that the SS7 telephone network is completely insecure assuming that you have the ability to connect to it. Shady gateway providers will allow you the privilege, and once you're in, you can do just about anything. There is precious little within SS7 to prevent or respond to spoofing. It's a major nightmare for telephone companies.
Re: Voice Phishing Scams Are Getting More Clever
#107Earlier quoted context omitted.
Curious: how does the PBX verify caller ID? Do you know how it works in practice?
It doesn't actually verify it, all it can do is read it. Just like email. When the PBX is told that the caller is say 01460223344 (I'm in the UK) then it would infer that the caller is from Crewkerne in Somerset due to the 01460 which is a designated area code. It may also be able to look up the whole number and infer a source. However, just like email the CLID can be trivially faked and just like email, the lookup i…
Re: Voice Phishing Scams Are Getting More Clever
#108Still, I've been paying too much for that crusty old landline, and finally got motivated to do something about it. I just ported it out last month, and the new VoIP service I'm using costs less per month than what AT&T was charging just for Caller ID. Even funnier, they offer telemarketer blocking like I've set up, at no extra charge.
Farewell and f*ck you very much, AT&T. You didn't even lift a finger to insure that the Caller ID I paid for was accurate.
Re: Voice Phishing Scams Are Getting More Clever
#109Earlier quoted context omitted.
The problem here is the ability to spoof caller ID. This should not be possible. Think of incoming CLID in the same way that you do email From: addresses. Often and easily faked. Funnily enough both my office PBX and SMTP daemon check incoming CLID/HELO and drop attempts to spoof their own identity. Its not a particularly sophisticated protection these days but is one of many, many rules. Actually, now I come to thin…
A better analogy that I use (especially with nontechnical folks) is the return address on an envelope. You can, technically, write anything in it and there’s no way to guarantee it’s authentic.
For example here are some headers from some spam I received:
From: "Jeremy Adamson"
Reply-To: "Jeremy Adamson"
From: is what I see in my client and Reply-To: is where a reply would go to.This one is much better, note how I'm BCCd and To: is complete bollocks:
Reply-To: dr.ahmed.faruk@outlook.com
From: Dr Faruk Ahmed
Subject: MANAGER AUDIT AND ACCOUNT DEPT
To: undisclosed-recipients:;
BCC:
Return-Path: dr.faruk.ahmed1@gmail.com
Given that Reply-To and Return-Path are in different domains, where would a reply go to?Re: Voice Phishing Scams Are Getting More Clever
#110Once that hits general usage along with the kind of ML and social network graphs being done up couldn't that just plain be it for phone usage if companies can't come up with a proper cryptographically verified call scheme (which would require new phones, for everyone)? I mean, if a call coming in directly from a "trusted contact's number" that is literally in their voice becomes generally a scam too I think that'd have to be a real tipping point for the general population. I can't see any choice at that point but to disable all incoming calls period, and move my family over to something else as well. And that tech train is coming down the tracks pretty fast, there have to be at least some phone providers who can see that right? Heavily automatically run personalized ML powered social media and ad network profile fed phishing calls in a relative's voice, yeah that'll be really fun.