Live data from Hacker News

Voice Phishing Scams Are Getting More Clever

krebsonsecurity.com

111–120 of 226 posts

Re: Voice Phishing Scams Are Getting More Clever

#111
post #36

Earlier quoted context omitted.

For those worried about a situation like this, I set up automated purchase alerts on my credit cards and withdrawal alerts on my bank accounts. I see it all in close-enough-to-real-time, and it's helped me catch fraud before the banks did at least twice in the past few years.

Also, for anyone that doesn't know: you can request an old school ATM card (not a debit card, i.e. no MC/Visa logo) from your bank and use a credit card for purchases instead. This reduces the exposure of a critical account. And if you do become a victim of fraudulent charges, you don't have to worry about your bank account being drained immediately (possibly resulting in overdrafts, etc).

Also have two accounts:

- Account #1: salaries and deposits go here, no ATM

- Account #2: gets regular transfers from account #1, whatever you spend each week on your ATM, has an ATM, blocked on overdraft

If ATM is compromised the only money at risk is whatever is left in Account #2

This minimizes your exposure

Re: Voice Phishing Scams Are Getting More Clever

#112

This is 100% destroying the phone for younger generations ... my kids answer nothing, not even my own phone calls because they set their phones on do not disturb to curb the endless robo, scam, and cold calls. If it wasn't for https://hiya.com/ , I'd be at the end of my wits. Seems like the number of fake calls has ramped up exponentially in the last months. I finally just set it up completely block all telemarketing…

It's completely destroyed the phone for me... I get about 10 calls a day from scams. I don't answer my phone anymore unless it's from a number I already have programmed. Once the scammers get a hit on some of those numbers my phone is toast.

I do this too.. And then they started hitting my work number, which forwards to my phone, and only displays as my company's number so I have to check, just in case.

Re: Voice Phishing Scams Are Getting More Clever

#113
post #102

Earlier quoted context omitted.

A better analogy that I use (especially with nontechnical folks) is the return address on an envelope. You can, technically, write anything in it and there’s no way to guarantee it’s authentic.

In email the From: address rarely delivers the mail. From: and To: are the ones that you see in your mail client and correspond to the addresses on the letter within. For example here are some headers from some spam I received: From: "Jeremy Adamson" Reply-To: "Jeremy Adamson" From: is what I see in my client and Reply-To: is where a reply would go to. This one is much better, note how I'm BCCd and To: is complete bo…

What about an out of band verification by the carriers?

Basically a large registry. When I call someone I tell t-mobile who I'm calling, and they register it. Then on the receiving end Verizon checks with T-mobile or a central registry, and says yep James's number is calling this number. Then it marks it as a verified call.

Re: Voice Phishing Scams Are Getting More Clever

#114
I haven't even had a debit card issued for my core bank account, and there is very little chance I ever would at this point. There just isn't a good reason to put my money at risk when I can use a variety of credit cards instead, and just pay them off every month. On the rare occasion I need cash, I can do a cash advance (with an associated charge....really useful motivation to avoid needing cash more than once or twice a year).

Unrelated, but I'm pretty sure I know what credit union they're talking about. Super nice place that is focused on the tech workers in the Portland area, and I've always had good experiences with them.

Re: Voice Phishing Scams Are Getting More Clever

#115

Earlier quoted context omitted.

> I usually laugh at them and tell them they they are the unverified party in this phone call, not me. This is one of the related reasons why I finally got my ducks in a row and switched away from Chase three years ago. Their potential-fraud-has-happened outreach department was, in my experience, terrible about this. It didn't help that their potential-fraud-detection department was similarly bad. ("You used your deb…

their potential-fraud-detection department was similarly bad. ("You used your debit card at an AM/PM in Washington State!!!!" Yes, I know, it is about 900 feet from my house; I go there regularly.) A year ago I had an awful experience with this. We were on vacation at Big Bend National Park, which is hours away from everything in southwest Texas. When trying to pay for breakfast, our card was denied. I tried to call…

I learned not travel with just one credit card after my CU botched a software update while I was in a middle of the trip in Prague - already checked out from the hotel but not yet taken the rental car to drive to the next hotel in a different city. The looming possibility of sleeping in the street was rather instructive.

Since then I always carry three credit cards when traveling, from three different banks, and each from a different payment system in case if a systemic issue.

Re: Voice Phishing Scams Are Getting More Clever

#116
post #61

Earlier quoted context omitted.

> I usually laugh at them and tell them they they are the unverified party in this phone call, not me. This is one of the related reasons why I finally got my ducks in a row and switched away from Chase three years ago. Their potential-fraud-has-happened outreach department was, in my experience, terrible about this. It didn't help that their potential-fraud-detection department was similarly bad. ("You used your deb…

I contacted Wells Fargo because their survey emails come from a third party email address and link to a different third party site. I was very specific in my feedback that I thought the survey was legitimate but that they shouldn't habituate their customers to entering even general data on unaffiliated sites. They called me and I reiterated the above and even got a fancy case number. After a month I got a voicemail t…

Don’t despair. If large companies were efficient there would be no place for startups. And what kind of world would that be?

Re: Voice Phishing Scams Are Getting More Clever

#117

Easy solution don’t answer phone calls from those not in your contacts.

Huh? The caller ID was spoofed. Read the article. > Cabel Sasser is founder of a Mac and iOS software company called Panic Inc. Sasser said he almost got scammed recently after receiving a call that appeared to be the same number as the one displayed on the back of his Wells Fargo ATM card.

It didn’t say.. wife, friend, mom, joe, etc.. you know people you entered into your contacts.

Personally If someone needs to get a hold of me outside of my contacts email or text me and I’ll get back to you accordingly.

Re: Voice Phishing Scams Are Getting More Clever

#118

Earlier quoted context omitted.

It doesn't actually verify it, all it can do is read it. Just like email. When the PBX is told that the caller is say 01460223344 (I'm in the UK) then it would infer that the caller is from Crewkerne in Somerset due to the 01460 which is a designated area code. It may also be able to look up the whole number and infer a source. However, just like email the CLID can be trivially faked and just like email, the lookup i…

It's not quite "Just like email" because email has systems in place to authenticate this, while phone systems do not. https://en.wikipedia.org/wiki/DMARC

Have you ever tried to implement DMARC? DKIM and SPF are OK but DMARC breaks mail lists. Yes there are ways to mitigate but it might not be worth it unless you also do DNSSEC as well. Well actually I believe that every little helps and use every weapon available.

I do think that the analogy works really well. PBXs can have quite a few weapons of their own to attempt to authenticate callers. For example you can pass "anonymous" calls to a dialplan that gets the caller to identify themselves and then play that to the recipient who then gets to allow/disallow the call - basically make the (human) recipient part of the firewall. Also, PBXs that deal with VoIP can use IP rules just like a firewall to make decisions on what to do.

Traditionally, "telephony" and "systems" have been considered separate. Personally I'm a sysadmin AND telephony bod with around 25/15 (respectively) years experience. My PBXs (generally Asterisk with FreePBX) have quite a few sources of intelligence about what is inbound, beyond CLID. I also look after quite a few email systems, often fronted by an Exim MTA with an attendant rspamd or spamassassin (int al).

Re: Voice Phishing Scams Are Getting More Clever

#119

The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…

Won't this rapidly become beside the point?

With text to speech software becoming so amazing, see Google's Duplex, I'm not that concerned with caller ID and am massively concerned for aging boomers who will have to contend with nearly perfect speaking bots.

Re: Voice Phishing Scams Are Getting More Clever

#120

Who are the people manning the phones for the scam? Does it really pay better than a real job? I mean if you have the skills to scam like this you have skills that are valuable to legit business as well, no? I knew a few criminally-minded people back in high school and my early 20's (I don't associate with them anymore.) The thing that always stuck me about the "criminal mind" is that they were ready and willing to w…

> because it felt like having twice as much money

Hmmm... Here's a strange thought: What if that was a way of deal with a gambling addiction (or something similar, since I understand risk to be part of the addiction), except you lose significantly less than you would have gambled without the loan?

Post reply on HN