Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

161–170 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#161

Earlier quoted context omitted.

I usually don't answer calls from numbers I don't recognise - but a couple of days back it was a scammer claiming to be from Amazon - said I had ordered an iPhone for £600 and was it a real order. I was pretty suspicious but thought I would get them to authenticate their identity as someone really from Amazon by telling me the last thing I had really ordered was... I must have stayed on the call for 20 minutes, event…

I get this kind of call about 5-15 times a day I do not answer calls

A lot of them phone me and ask for my wife by name "Can I speak to XYZ" - I usually reply "No" and end the call. Actually, for the last few calls I've not even been saying the "No".

Maybe 3 or 4 of these a day

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#163
> Note: if you’re a developer and your users have gmail accounts, an authenticator code is NOT a 2nd factor, if that user is using Google Authenticator.

So many people and developers do not understand two factor authentication. If the necessary information is automatically sync'd to another device, you likely don't have two factor auth.

Example: If you log in from a Macbook, and the second auth is sent to your phone, Apple will helpfully forward that code to the Macbook, completely removing the second factor.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#167
post #152
post #136

Earlier quoted context omitted.

You miss the point. You can't mug someone for their Vanguard account. Robbery risk is limited to cash on hand, or arguably whatever the ATM limit is on your bank account.

Aren't elderly phone scammed out of huge amounts from bank accounts often??

Not sure about the distribution, often it’s cash or jewelry that’s already home. Bank tellers and even taxi drivers get increasingly educated to stop such suspicious withdrawals/meetings.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#168
If you want to keep $100k in a crypto exchange, it doesn’t cost much comparatively to purchase a few yubikeys.

The thought of having all my online services centralized with a single provider for email, SSO, 2FA, and so on is scary. Especially at Google, where you can lose all access at the drop of a hat, with no recourse.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#169
post #129

Earlier quoted context omitted.

> never give out codes sent to use via sms or push notifications to someone requesting them via phone Unfortunately, some call centers DO use that for verification in some cases (i.e. you call them, and they send you a code to your email/phone that you read back).

I’ve personally never had that happen. It should go on a name and shame list.

My bank does it. Chase will send OTP via the bank app to verify you're identity for phone support.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#170
post #158

Earlier quoted context omitted.

Same. I don't store my 2FA with my passwords. I also use Authy, I'd like to move to something else but as long as it's working. I was annoyed they got rid of the Mac app.

Same, the desktop app worked great. Probably for the best though, ideally you want to pull your codes from a phone and password from your desktop device.

Yeah, I won't argue that it doesn't make sense security wise. It does.
Post reply on HN