Earlier quoted context omitted.
> never give out codes sent to use via sms or push notifications to someone requesting them via phone Unfortunately, some call centers DO use that for verification in some cases (i.e. you call them, and they send you a code to your email/phone that you read back).
I’ve personally never had that happen. It should go on a name and shame list.
Scammed out of $130K via fake Google call, spoofed Google email and auth sync
171–180 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#172Earlier quoted context omitted.
Passkeys also solve this even if they’re not hardware backed. He was able to give them a code but wouldn’t have been able to do a passkey handshake for a domain which isn’t Google.com. Plus they’re easier to use and faster.
I don't know about that. If they can hack your Google/iCloud account they can add a new device, sync all your passkeys to that device, then log into all your other accounts.
I don’t use Google but at least in the Apple world you also get a fairly different prompt for enrolling a new iCloud Keychain device than simply logging in. Obviously that’s not perfect but there is a good argument for not getting people accustomed to hitting okay for both high and low impact challenges using the same prompt.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#173Earlier quoted context omitted.
> never give out codes sent to use via sms or push notifications to someone requesting them via phone Unfortunately, some call centers DO use that for verification in some cases (i.e. you call them, and they send you a code to your email/phone that you read back).
I’ve personally never had that happen. It should go on a name and shame list.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#174Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#175A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
To their credit/discredit, when I said no I'm not giving that out it says not to they just moved on. Not sure why they even asked then.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#176Does anyone know how the email from (or appearing to be from) @google.com works? Wouldn't the Apple account reject it because it fails DKIM/etc?
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#177Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#178Earlier quoted context omitted.
In my actual real world experience of digging my elderly mother out of $25,000+ of scam debt, banks do not care at all unless they can be shown to be at fault, and then they weigh the loss expense vs the likely legal expense.
What kind of scam debt in particular? I’m not blaming your mom, but there’s a big difference for a bank between “someone stole my identity to falsely authorize this transfer“ and “someone tricked me into authorizing this transfer”.
With the former, your recourse is essentially zero. Banks won’t do anything, cops are useless.
With the latter, banks try to prevent it and it’s harder and riskier.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#179Earlier quoted context omitted.
> never give out codes sent to use via sms or push notifications to someone requesting them via phone Unfortunately, some call centers DO use that for verification in some cases (i.e. you call them, and they send you a code to your email/phone that you read back).
I’ve personally never had that happen. It should go on a name and shame list.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#180I notice none of the pieces of advice are "don't keep a hundred thousand dollars in a Coinbase account".
I split my crypto assets between Coinbase and what is now a corrupted hard-drive I've yet to recover.