Live data from Hacker News

Voice Phishing Scams Are Getting More Clever

krebsonsecurity.com

151–160 of 226 posts

Re: Voice Phishing Scams Are Getting More Clever

#151

Number one advice I give my family: never give out any information (no matter how inconsequential it seems) to a person purporting to be from a company calling you. Hang up and call the company yourself using a trusted number (e.g., the number on the back of a credit card).

Banks should really just stop calling customers and taking them through security. If there's something urgent, the protocol should be that they call you, give you a ticket number, and tell you to call them back on the bank's standard number for customer service. Anything else just conditions people to expect incoming calls with security questions which will always result in scammers finding a way through.

This can also be scammed due to the timeout "feature" in telephone systems. Ie, the scammer calls, tells you to call the number on your card. You believe they hung up, but they are still on the line. When you pick up your phone again, you're still contected, and they're playing a dial tone.

https://www.geekrant.org/2016/05/08/phone-scam-part-1/

Re: Voice Phishing Scams Are Getting More Clever

#152
I believe that phone companies are complicit in this criminal activity, as they seem to have virtually no interest in actually stopping it. I've already turned off calls on my phone because "why bother", and more and more people I know are doing the same thing. The phone companies probably make so much on streaming that they don't give a shit about the phone system. This is a really bad thing for crime, but might help accelerate the death of a decades-obsolete technology.

Re: Voice Phishing Scams Are Getting More Clever

#153

More and more, my plan seems wiser. I’ll generally get a phone call like this, and hang up and re-initiate a request myself starting from the phone number listed on my card.

You can still be scammed by this technique if you're answering on a landline:

https://www.geekrant.org/2016/05/08/phone-scam-part-1/

Re: Voice Phishing Scams Are Getting More Clever

#154
post #99

Earlier quoted context omitted.

How exactly could they do that for calls originating outside their network? Most spammers are using VoIP, not cell phones on major US companies.

They could not fix it. However, it would be a big value-add to me if, say, the big 4 US carriers could add an out-of-band security check and block calls to their networks from numbers they control but which are spoofed. I get way too many calls from area codes and prefixes I recognize. This would help me get some of that back.

There are legitimate use cases like Google Voice for sending caller ID that another carrier owns. Despite that, a basic authorized users list would be an easy fix, doubt that'll ever happen though. Look at the mess that LRN and CNAM data are, providers will nickel and dime for access to data that doesn't cost much to maintain...

Re: Voice Phishing Scams Are Getting More Clever

#155

Earlier quoted context omitted.

> I went into my contacts and changed the ringtone associated with them to be one that makes noise. That gets the job done, but rather than modify each of your existing contacts (and each new one), consider just turning on Do No Disturb and setting your Do Not Disturb level to "Allow Calls From All Contacts" (or a particular Group or Favorites). These are iOS options but I assume there's an equivalent in Android.

On my particular Android phone (Pixel) this is not a great solution because setting Do Not Disturb alters the behavior of other things like Calendar reminders or email alerts. You could make DND not do that, but sometimes I do want to mute other things. If you're using DND all the time, you essentially lose that feature on your phone. The best solution I've found is to just go into the Google Dialer app and set the o…

Just wait. You will get scammers that can pass the "scam likely" threshold, and then your scam call volume will go up.

Re: Voice Phishing Scams Are Getting More Clever

#156
post #106
post #37

The issue, as I understand it, is that the SS7 telephone network is completely insecure assuming that you have the ability to connect to it. Shady gateway providers will allow you the privilege, and once you're in, you can do just about anything. There is precious little within SS7 to prevent or respond to spoofing. It's a major nightmare for telephone companies.

It seems that what changed is that sometime in recent years it became much easier for shady gateway providers to remain in business. In earlier times, it would appear that originators of fraudlent caller ID data where shut down rapidly.

The telecom "industry" has seen massive market compression, with players who rarely innovate. Its sad that Scam ID is considered groundbreaking IMO, the implementation is pretty crummy.

Re: Voice Phishing Scams Are Getting More Clever

#157

I believe that phone companies are complicit in this criminal activity, as they seem to have virtually no interest in actually stopping it. I've already turned off calls on my phone because "why bother", and more and more people I know are doing the same thing. The phone companies probably make so much on streaming that they don't give a shit about the phone system. This is a really bad thing for crime, but might hel…

> I've already turned off calls on my phone

How do you do that on an Android phone?

Re: Voice Phishing Scams Are Getting More Clever

#158

Earlier quoted context omitted.

Does this imply I should answer the 1-800 calls and keep them on the line as long as possible? :D

If you suspect a scammer called you, always keep them on the line as long as possible. Feed into the scam and act as gullible as possible, give them fake cc numbers, etc.

Best to extract as much iinfo as possible, business name, callback numbers, email addresses, etc. The more info, the easier it is for the FCC to bring enforcement action against fraudulent callers.

Re: Voice Phishing Scams Are Getting More Clever

#159

My bank's fraud department sent me a voicemail saying my card had been deactivated and I needed to call them at 1-800... Yeah, fuck you. I'm not calling a fraud prevention number that was given to me over the phone and more to the point, what is wrong with you for asking your customers to trust people that called them on the phone. I called the main switchboard for the bank and couldn't find the fraud number from the…

Yes! This happened to me too and is very alarming. It’s training users to fall for phishing. I’m not sure what a correction looks like though. Should they call customers and instruct them to find or verify a phone number and call back? Instruct them to log into their online account? That would be fine for you and me, but I’m thinking of the average cardholder.

Telling them to call the customer service number on their credit card seems pretty good?

Re: Voice Phishing Scams Are Getting More Clever

#160
post #82

Earlier quoted context omitted.

The problem here is the ability to spoof caller ID. This should not be possible. Think of incoming CLID in the same way that you do email From: addresses. Often and easily faked. Funnily enough both my office PBX and SMTP daemon check incoming CLID/HELO and drop attempts to spoof their own identity. Its not a particularly sophisticated protection these days but is one of many, many rules. Actually, now I come to thin…

The problem with SS7 is that you extend your SMTP analogy, there is no way to implement the equivalent of SPF, DKIM and DMARC for verification of incoming traffic without breaking SS7-to-SS7 links between the vast majority of installed phone switching gear out there on the PSTN. Which nobody wants to pay money to completely replace.

> The problem with SS7 is that you extend your SMTP analogy, there is no way to implement the equivalent of SPF, DKIM and DMARC for verification of incoming traffic without breaking SS7-to-SS7 links between the vast majority of installed phone switching gear out there on the PSTN.

Why not? That's how it was done for email. SPF doesn't prevent interoperability for sending domains that don't use it or recipients that don't verify it. What it does is inhibit forged messages from a domain that does use it to a recipient that does verify it.

Then the more senders who have an SPF record, the stronger a spam signal it is for a domain to not have one, and the stronger the incentive gets for senders to use it. It's already in the recipient's interest to verify it when it's used.

They could even use DNS for this exactly like email. Create a lookup zone equivalent to in-addr.arpa but for phone numbers.

Post reply on HN