Earlier quoted context omitted.
> The problem with SS7 is that you extend your SMTP analogy, there is no way to implement the equivalent of SPF, DKIM and DMARC for verification of incoming traffic without breaking SS7-to-SS7 links between the vast majority of installed phone switching gear out there on the PSTN. Why not? That's how it was done for email. SPF doesn't prevent interoperability for sending domains that don't use it or recipients that d…
Because it's a huge installed base of non-upgradeable equipment that is 15, 20, 25 years old. People doing oldschool SS7 telco stuff are just not going to upgrade. They'll sue their upstream carriers if they suddenly cut them off because their new re-implementation of SS7 is incompatible with their old gear. I'm a senior network engineer for a mid sized regional ISP, and encounter this shit on a fairly regular basis.…
Voice Phishing Scams Are Getting More Clever
191–200 of 226 posts
Re: Voice Phishing Scams Are Getting More Clever
#192This is why I don't answer the phone unless it's a contact. Everyone else can leave a message.
Did you read the article? The Many people have their bank or credit union in the contacts. This won't help if they're spoofing a bank number. > Cabel Sasser is founder of a Mac and iOS software company called Panic Inc. Sasser said he almost got scammed recently after receiving a call that appeared to be the same number as the one displayed on the back of his Wells Fargo ATM card.
Re: Voice Phishing Scams Are Getting More Clever
#193I'll give you the flip side of the scammer's deterioration of trust in the phone... a few months back I got a phone call from what appeared to be my bank, and they were asking me about a fraudulent charge that I didn't recognize. Worried that this was the beginning of a scam, I delayed a bit on the phone while I logged in independently to my bank account... and lo, yes, indeed, there was a fraudulent charge to my acc…
It makes me laugh when my banks fraud department calls me and then asks me to verify myself to them by giving personal information before asking me questions. I usually laugh at them and tell them they they are the unverified party in this phone call, not me. I always pull up the website and confirm before telling them anything.
The method they choose to do that, though, is to ask me for a phone number to which they can send an authentication code. I give them the phone number I'm using - the one they called me on. They ask if I want a text or a voice call. Tempting though it would be to put them on hold while I accept the voice call with the security code, I opt for the text message. Phone buzzes, I read out the number, and they seem happy with the result.
I really hope that when they asked me for a phone number they verified it against a list of known numbers associated with the account, but... it really wasn't clear in the context of the interaction.
Re: Voice Phishing Scams Are Getting More Clever
#194The problem here is the ability to spoof caller ID. This should not be possible. Regulations set up the phone system, regulations need to make this change. I don't care what excuse anyone has, don't care about your stupid PBX or any of that. Caller ID should be mandatory and reliable. Having said that, always assume someone calling you is a fraud. If your "bank" calls you, tell them you'll call back and don't call a…
There is no way to fix the ability to spoof caller ID with the way SS7 is built. Not without breaking functionality to something like 85% of the installed base of PBX and phone switch equipment, most of which is anywhere from 10 to 45 years old. The legacy telco SS7 phone system needs to be burnt to the ground and rebuilt, but it never will be, because people have moved on to friend-opt-in based message platforms lik…
Not sure about the US, but in most of the rest of the world regulators come up with new rules and regulations requiring some form of network upgrade all the time – SLAs, connectivity and routing requirements, legal interception, data residency, etc.
And telcos have no other way but to spend billions to protect some monopoly or enable more surveillance power for the governments. It's a matter of priorities, really.
Re: Voice Phishing Scams Are Getting More Clever
#195Seems like this would solve almost all of these problems.
Re: Voice Phishing Scams Are Getting More Clever
#196Earlier quoted context omitted.
> I went into my contacts and changed the ringtone associated with them to be one that makes noise. That gets the job done, but rather than modify each of your existing contacts (and each new one), consider just turning on Do No Disturb and setting your Do Not Disturb level to "Allow Calls From All Contacts" (or a particular Group or Favorites). These are iOS options but I assume there's an equivalent in Android.
On my particular Android phone (Pixel) this is not a great solution because setting Do Not Disturb alters the behavior of other things like Calendar reminders or email alerts. You could make DND not do that, but sometimes I do want to mute other things. If you're using DND all the time, you essentially lose that feature on your phone. The best solution I've found is to just go into the Google Dialer app and set the o…
Re: Voice Phishing Scams Are Getting More Clever
#197This is 100% destroying the phone for younger generations ... my kids answer nothing, not even my own phone calls because they set their phones on do not disturb to curb the endless robo, scam, and cold calls. If it wasn't for https://hiya.com/ , I'd be at the end of my wits. Seems like the number of fake calls has ramped up exponentially in the last months. I finally just set it up completely block all telemarketing…
Re: Voice Phishing Scams Are Getting More Clever
#198Most robo-callers feel like Phishing scams. I've been contemplating giving up my cellphone and just using a Calyx mobile data ( https://www.calyxinstitute.org ) and use Signal, email and Mumble only. Anyone else do something like this successfully?
I did it for 6 years when I lived in Germany. I had a data only sim card and a google voice US phone number. Verdict: It's not doable if you want it to work 100%. And in the US I would say it's not doable at all because Android/dumbphone users are still using SMS instead of a messenger app like Whatsapp, so you have no way of communicating with them at all. The biggest problem for me was online services that want to…
I'm not concerned about Whatsapp, and I figured I use Twilio for text messages. Out of service phones can still call emergency services, 911. My main concern is being "that guy" who everyone has to make exceptions for when contacting.
Re: Voice Phishing Scams Are Getting More Clever
#199Earlier quoted context omitted.
Also, for anyone that doesn't know: you can request an old school ATM card (not a debit card, i.e. no MC/Visa logo) from your bank and use a credit card for purchases instead. This reduces the exposure of a critical account. And if you do become a victim of fraudulent charges, you don't have to worry about your bank account being drained immediately (possibly resulting in overdrafts, etc).
Card skimming has become so rampant where I live that I don't ever put a bank or credit card in a gas pump. I got a gas company card (non-Visa/MC) with a super-low limit, and when I need to buy gas I make a payment online with my phone, then pump away knowing if it got skimmed, the perps would probably throw the info out because it's not usable anywhere else, and even if they used it at the gas station, they'd only g…
Re: Voice Phishing Scams Are Getting More Clever
#200Earlier quoted context omitted.
Card skimming has become so rampant where I live that I don't ever put a bank or credit card in a gas pump. I got a gas company card (non-Visa/MC) with a super-low limit, and when I need to buy gas I make a payment online with my phone, then pump away knowing if it got skimmed, the perps would probably throw the info out because it's not usable anywhere else, and even if they used it at the gas station, they'd only g…
How quick does the payment from your phone go through? Australia's only just implemented fast cross-bank transfers (PayID) but the implementation compromised privacy and only works in some circumstances.