Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

191–200 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#191
post #45

Earlier quoted context omitted.

Google/Chrome Password Manager?

But how did they get his Gmail password in the first place? I'm not sure if I have the same password reset flow as OP, but when I try to reset my password and even provide the 2fa code, it basically doesn't let me get past a certain point without contacting my backup email address or making me use a phone which I'm logged in on to complete the reset

The article gives advice to change your passwords because of leaks. So as the post above suggests, it really sounds like they reused their google password somewhere. Then had Google sign-on for Coinbase, or had their Coinbase password in Google.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#192
post #102

Earlier quoted context omitted.

This is like saying it’s not Ford’s fault that they didn’t put in seatbelts and safety glass because people knew driving was unsafe. When bad outcomes happen at scale, you need a system-level fix. EDIT: to be clear, the fix has arrived: had he used passkeys, this attack would have been impossible and every login would’ve been faster and easier. There are edge cases but this is literally the reason why U2F was created…

The author knew that the scam existed and he even was skeptical. Then chose to rely on it being true despite all the red flags. That’s his fault. At some point people have to accept responsibility for their own stupid actions.

Yes, they made a mistake. They were honest about that.

A little secret which will help you in life: everyone makes mistakes, even people who don’t think they will, even you. Looking all the way back to last week and 2 major NPM hacks ago, you can get access to a lot of systems simply by hitting someone when they’re busy and distracted.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#193

Earlier quoted context omitted.

Would (the actual) Amazon even agree to provide this kind of information over the phone to someone?

is talking to amazon on the phone at all even actually possible?

That's the easiest way to spot a scam: "Hello this message is from Google customer service..."

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#194

> Note: if you’re a developer and your users have gmail accounts, an authenticator code is NOT a 2nd factor, if that user is using Google Authenticator. So many people and developers do not understand two factor authentication. If the necessary information is automatically sync'd to another device, you likely don't have two factor auth. Example: If you log in from a Macbook, and the second auth is sent to your phone,…

It doesn’t work because people don’t understand it. They understand they are getting harassed all the time and in a state of terror because you might get locked out from your accounts because you lost a device or because something went wrong with your relationship with Apple, Google, Microsoft and other large unaccountable vendors —- something you may or may not get an explanation of. Since you’re getting harassed al…

[dead]

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#195

Earlier quoted context omitted.

I usually don't answer calls from numbers I don't recognise - but a couple of days back it was a scammer claiming to be from Amazon - said I had ordered an iPhone for £600 and was it a real order. I was pretty suspicious but thought I would get them to authenticate their identity as someone really from Amazon by telling me the last thing I had really ordered was... I must have stayed on the call for 20 minutes, event…

Even when you know it’s fake, the whole thing is very disconcerting. I received a scam call ostensibly from a local utility and filed an identity theft report with local police naming the utility as “victim”. The caller even told me where they (probably really) were. Police do nothing, scams continue until something breaks.

A few years back I got a call from a scammer selling a device that would help stop scam phone calls - that actually took me a while to realise it was a scam (this is like 15 years ago).

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#196

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Include SPAM call blocker in that list! Notably, both iOS and Android have that feature. Never pick the first call from an unknown number! If it's urgent and they are genuine, they'd leave either a voicemail or a text.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#197

My favourite Pixel feature is Screen Call. My primitive security precautions: 1. DO NOT use your Gmail for recovery. Use another email provider. 2. Use a family member's phone number for recovery. 3. DO NOT install your bank's app. Somehow the Royal Bank of Canada's app was used as an attack vector. If the RBC app can get hacked, smaller banks are even more vulnerable. 4. Use incognito mode on your browser for bankin…

> 4. Use incognito mode on your browser for banking so a thief or hacker can't use your browser history to find out your bank.

You can buy that information. Databrokers will sell it. Your bank sells your transactions.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#198
> The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-synced my codes.

Don't do that. Don't put your 2FAs somewhere else than in an unsynched app. Not in Bitwarden, not in any online account, nowhere else than "Something you have".

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#199

> The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-synced my codes. Don't do that. Don't put your 2FAs somewhere else than in an unsynched app. Not in Bitwarden, not in any online account, nowhere else than "Something you have".

Just wondering what is the plan in case this thing you have gets lost?

And would you say that using something like authy with encryption using a totally unique password is safe?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#200
post #22

> Google enabled Authenticator cloud sync by default. Never understood this convenience and never will. This is exactly the wrong way to deal with people losing their authenticator secrets.

The convenience is that people don’t drop their phone in the toilet and suddenly lose access to all of their accounts.
Post reply on HN