Live data from Hacker News

Gone (Almost) Phishin'

ma.tt

21–30 of 93 posts

Re: Gone (Almost) Phishin'

#21
Thank you for writing this up (and getting it put into a video). I sent this blog post to my parents and my mum has decided to forward it on to all of her friends after watching.

Seems easily digestible and approachable for a specific target audience.

Re: Gone (Almost) Phishin'

#22
post #14
post #6

I told my parents: if they are ever called by anyone, to tell them "now is not a good time, please give me a case number and I'll call back when I do have the time." And then, this is important, look up the number for the customer service hotline online. I feel like this is a simple solution that works 100% of the time.

My dad googled “amex phone number” and called the first result. I spent most of a Saturday cleaning up after the scammers. I told him, next time call the number on the back of your card.

[dead]

Re: Gone (Almost) Phishin'

#23
>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else.

That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls.

  https://getsupport.apple.com/customer?cvid=8c11bcc71f684b6ab405d4fa1e86c146
  https://getsupport.apple.com.phish.xyz/customer?cvid=8c11bcc71f684b6ab405d4fa1e86c146
People just pattern match on the substring "apple.com" because they don't understand that the DNS system works right-to-left. Therefore, the 2nd url looks just as "legitimate" as the first one.

I work with senior citizens and tried to explain how to parse the domain in the URL by looking for the first forward "/" after the "https://" and then scan backwards but they find that mental algorithm confusing and those instructions don't stick. (This is actually an area where some AI on phones/desktops could assist people decipher urls or mark them as suspicious.)

The other problem with that advice is people can't "whitelist" the legitimate domains to look for because they don't know ahead-of-time what they are. E.g.:

- An Amazon verification email will be sent from "account-update@amazon.com". It's intuitive to predict something coming from "@amazon.com" so a mental whitelist filter works in that case.

- However, State Farm Insurance legitimate login verification codes are actually sent from "noreply@sfauthentication.com" instead of the expected "@statefarm.com"

Re: Gone (Almost) Phishin'

#24
As others have mentioned, one big issue is that every company does these things differently and just because someone texts you a link doesn't mean it's phishing, even though it feels shady. In Australia I have had calls by immigration officers on supressed numbers that wanted PII over the phone without being able to tell me what the purpose of the call is.

Re: Gone (Almost) Phishin'

#25
post #12
post #6

I told my parents: if they are ever called by anyone, to tell them "now is not a good time, please give me a case number and I'll call back when I do have the time." And then, this is important, look up the number for the customer service hotline online. I feel like this is a simple solution that works 100% of the time.

Mike Tyson once said "Everyone has a plan until they get punched in the mouth". I think you are underestimating the underhanded tactics and emotional tools available to scammers to keep you on the line.

When I'm at home with the old man (mam is unfortunately in a care home), it _really_ irritates me how many scam calls he gets some days. Most of them are obvious: they just hang up when you pick up, the line is very bad or the caller is otherwise barely intelligible (i.e. they are speaking their 4th language), they refer to an account that doesn't exist or a fictitious government agency. But the occasional one is very smooth, and sometimes even have a few details about Dad's life and/or accounts that give pause (either of the form “could this actually be real” or “I wonder how have they collected and associated that?”).

If my family are anything to go by, they definitely target the elderly more than even one generation down (so it isn't just due to those of the younger generations often only having mobile phones and landlines are more targeted) because they know those tend to be more susceptible to the con and more likely to have some savings worth pillaging.

Also in DayJob, some of our C*s and others associated with them (PAs, office managers) have seen some pretty sophisticated phishing attempts, both targeting the business's dealings and their personal accounts. I get the impression that these are reducing in number ATM (or the filtering of them is improving) but that those coming in are making an increasing effort to be convincing.

Re: Gone (Almost) Phishin'

#26
post #6

I told my parents: if they are ever called by anyone, to tell them "now is not a good time, please give me a case number and I'll call back when I do have the time." And then, this is important, look up the number for the customer service hotline online. I feel like this is a simple solution that works 100% of the time.

Another top tip is how to response to “can I just confirm”. No, they can't just confirm any details, until they have confirmed who they are, which they can't do without us calling them on the company's published support number.

Luckily my parents are appropriately cynical and have not fallen for anything like that, but I know a couple of people of my generation who have (in the worst case losing 5K+ in savings, back when there was no onus on UK banks to take any responsibility for such fraud through their systems so it was properly lost to them).

Re: Gone (Almost) Phishin'

#27
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

It is unfortunately normal for companies to impersonate scammers.

We can teach people as much as we want about security against phishing. It won't matter because people have to break these rules constantly. Companies actively train people to fall for phishing by doing everything in their power to be indistinguishable from phishing themselves.

Re: Gone (Almost) Phishin'

#28
What's the end goal here?

I know that after a phone has been stolen, attackers want to gain access to an Apple account to remove the activation lock. But in this case, no devices had been stolen yet. The most they could do would be to… remotely mark the devices as stolen? Then ask the victim to pay to unlock them?

Re: Gone (Almost) Phishin'

#29

The scammer sounds Australian, but he pronounces mobile as "mobil", like an American. I wonder if he's doing that intentionally to provide cover, or if he's worked with Americans so much in the past that it's changed his pronunciation.

The pause in replies also suggests he's not around the corner.

Re: Gone (Almost) Phishin'

#30
I’ve found that just not answering any calls from unknown numbers (and having my phone just silence those calls so I don’t even see them) prevents all of this. If the caller is legitimate (e.g., new dentist office regarding an appointment) they can leave a voicemail. And if it isn’t spam and they aren’t willing to leave a voicemail and have me call the back, it probably wasn’t important in the first place.

Sure, I may be missing out on some opportunities. But the peace of mind is far greater.

Post reply on HN