It's not just the obvious "people can't abuse or lose data they don't have" why keeping your info to yourself protects you against abuse.
I was just subjected to the most credible phishing attempt I’ve experienced
101–110 of 360 posts
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#102Earlier quoted context omitted.
Oh it gets worse. My UK bank had a hardware token for years. They recently "upgraded" my security for online banking, and now use SMS 2FA codes for login and authorising new transfers. The hardware token is now unusable. I'd change banks, but I doubt the others are better.
They are better. One of my banks offer a hardware token which requires my card to be physically present and for a correct PIN to be entered. The other has an app with push notifications which can be used to approve or deny transactions. Seriously, switch bank.
I did wonder if it was some unintended consequence of the EU banking interop changes, but that didn't seem especially convincing. OK, changing bank it is then. At least it's so much easier than it used to be. :)
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#103The easiest way to avoid this entire class of attack, is to never be willing to answer any kind of question from someone who calls you. Always hang up, Google the customer support line for the business, then call them .
I've already taken the most effective security measures against this kind of attack, which is to never answer the phone.
I always thought the expectation of interrupting whatever you're doing at a few seconds notice was incredibly rude anyway, even more so now we have so many other ways of communicating.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#104OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…
I'm seriously surprised there are banks that send SMS codes without a reason for the code. All banks I deal with always send the reason for the code. For example: "This is a new payee addition authorisation code. Last 4 digits of the payee's account number are XXXX, the code is: XXXXXX" or "This a transaction authorisation code for the amount of $XX.XX, to an account ending digits XXXX. The number is XXXXXXX."
I would seriously reconsider giving your business to a bank that doesn't do that.
Interestingly there was an EU regulation passed recently that sets certain standards requiring 2FA for certain operations performed by bank customers. Having set up the 2FA auth app on an elderly relative's android phone and having to set up a pin to unlock a device as this is one of the 2FA app requirements and then spending 2 hours explaining how to unlock the phone, how to use it with a tablet to log in, how to authorise payments etc I have mixed feelings. On one side, it is a pretty secure system that will lower the number of victims of fraud. On the other hand it is a massive inconvenience for elderly people. I like the SMS verification system if done right. I think 2FA is a bit of an overkill.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#105I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…
Oh it gets worse. My UK bank had a hardware token for years. They recently "upgraded" my security for online banking, and now use SMS 2FA codes for login and authorising new transfers. The hardware token is now unusable. I'd change banks, but I doubt the others are better.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#106I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…
In Sweden we have BankID - a two-factor, two-way authentication using public/private encrypted keys that's bound to a smartphone as a signature. The process is user-friendly while keeping security high: - The place where you want to login has to trigger the authentication from their server on every login - and have to be certified for BankID. - You then have to open the app, enter your fingerprint or 6-pin code befor…
https://www.expressen.se/dinapengar/sparande/bedragerier-med...
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#107From mine (french big bank), they could be annoying (asking the bank to close accounts, ordering new checkbooks, getting all kind of information on past transactions, wire money between my accounts), but I can't see how one would effectively leverage that.
I mean, an attacker goal would be to draw money in some way; all money wirings to external bank accounts are protected by a code (SMS or in-app verification), with a 24h delay between the time one enters a destination account and the actual wiring.
Is that any different with other banks? Is an attacker able to effectively draw money as soon as they get access to the account?
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#108Earlier quoted context omitted.
My bank has terrible call waiting lines and they even overcharge for it! And it's not just banks that are being phished
Switch to a better bank. The only way you can make change happen is by using your consumer power. Switching accounts is easy - see https://www.currentaccountswitch.co.uk/ - all your bills are autoswitched, your pay cheque gets redirected, and it happens pretty quickly.
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#109The easiest way to avoid this entire class of attack, is to never be willing to answer any kind of question from someone who calls you. Always hang up, Google the customer support line for the business, then call them .
Re: I was just subjected to the most credible phishing attempt I’ve experienced
#110And as always: The best defense is minimizing data other people have about you. None of my banks needs my phone number, so none of my banks has my phone number, so if someone called and claimed they were my bank, that would obviously be bullshit. It's not just the obvious "people can't abuse or lose data they don't have" why keeping your info to yourself protects you against abuse.