Earlier quoted context omitted.
Google/Chrome Password Manager?
But how did they get his Gmail password in the first place? I'm not sure if I have the same password reset flow as OP, but when I try to reset my password and even provide the 2fa code, it basically doesn't let me get past a certain point without contacting my backup email address or making me use a phone which I'm logged in on to complete the reset
Scammed out of $130K via fake Google call, spoofed Google email and auth sync
191–200 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#192Earlier quoted context omitted.
This is like saying it’s not Ford’s fault that they didn’t put in seatbelts and safety glass because people knew driving was unsafe. When bad outcomes happen at scale, you need a system-level fix. EDIT: to be clear, the fix has arrived: had he used passkeys, this attack would have been impossible and every login would’ve been faster and easier. There are edge cases but this is literally the reason why U2F was created…
The author knew that the scam existed and he even was skeptical. Then chose to rely on it being true despite all the red flags. That’s his fault. At some point people have to accept responsibility for their own stupid actions.
A little secret which will help you in life: everyone makes mistakes, even people who don’t think they will, even you. Looking all the way back to last week and 2 major NPM hacks ago, you can get access to a lot of systems simply by hitting someone when they’re busy and distracted.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#193Earlier quoted context omitted.
Would (the actual) Amazon even agree to provide this kind of information over the phone to someone?
is talking to amazon on the phone at all even actually possible?
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#194> Note: if you’re a developer and your users have gmail accounts, an authenticator code is NOT a 2nd factor, if that user is using Google Authenticator. So many people and developers do not understand two factor authentication. If the necessary information is automatically sync'd to another device, you likely don't have two factor auth. Example: If you log in from a Macbook, and the second auth is sent to your phone,…
It doesn’t work because people don’t understand it. They understand they are getting harassed all the time and in a state of terror because you might get locked out from your accounts because you lost a device or because something went wrong with your relationship with Apple, Google, Microsoft and other large unaccountable vendors —- something you may or may not get an explanation of. Since you’re getting harassed al…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#195Earlier quoted context omitted.
I usually don't answer calls from numbers I don't recognise - but a couple of days back it was a scammer claiming to be from Amazon - said I had ordered an iPhone for £600 and was it a real order. I was pretty suspicious but thought I would get them to authenticate their identity as someone really from Amazon by telling me the last thing I had really ordered was... I must have stayed on the call for 20 minutes, event…
Even when you know it’s fake, the whole thing is very disconcerting. I received a scam call ostensibly from a local utility and filed an identity theft report with local police naming the utility as “victim”. The caller even told me where they (probably really) were. Police do nothing, scams continue until something breaks.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#196A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#197My favourite Pixel feature is Screen Call. My primitive security precautions: 1. DO NOT use your Gmail for recovery. Use another email provider. 2. Use a family member's phone number for recovery. 3. DO NOT install your bank's app. Somehow the Royal Bank of Canada's app was used as an attack vector. If the RBC app can get hacked, smaller banks are even more vulnerable. 4. Use incognito mode on your browser for bankin…
You can buy that information. Databrokers will sell it. Your bank sells your transactions.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#198Don't do that. Don't put your 2FAs somewhere else than in an unsynched app. Not in Bitwarden, not in any online account, nowhere else than "Something you have".
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#199> The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-synced my codes. Don't do that. Don't put your 2FAs somewhere else than in an unsynched app. Not in Bitwarden, not in any online account, nowhere else than "Something you have".
And would you say that using something like authy with encryption using a totally unique password is safe?
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#200> Google enabled Authenticator cloud sync by default. Never understood this convenience and never will. This is exactly the wrong way to deal with people losing their authenticator secrets.