Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

201–210 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#201
post #155

Something isn't adding up here. The author is excruciatingly rigorous with documenting lots of stuff here, including the screenshots. Then glosses over this bit awfully fast: > So when he asked me to read back a code — supposedly to prove I was still alive — in a moment of panic, I did This was an account with authenticator enabled. I'm no expert, but I really don't think there's a recovery process that works as simp…

I don't get this part either.

if the scammers had spoofed the email, they would already have that code, and if they hadn't spoofed that email... I mean it looks like a case ID, why would they need it?

Maybe the reading back the code was to get buy in, then there's a missing step here like they had him hit "allow" on a 2fa prompt. Or maybe the email was legit, since it references a "temporary code" and the case ID allowed access with that code?

Good chance my reading comprehension is shot and I'm missing something, I suppose, but I don't understand.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#202
post #201
post #155

Something isn't adding up here. The author is excruciatingly rigorous with documenting lots of stuff here, including the screenshots. Then glosses over this bit awfully fast: > So when he asked me to read back a code — supposedly to prove I was still alive — in a moment of panic, I did This was an account with authenticator enabled. I'm no expert, but I really don't think there's a recovery process that works as simp…

I don't get this part either. if the scammers had spoofed the email, they would already have that code, and if they hadn't spoofed that email... I mean it looks like a case ID, why would they need it? Maybe the reading back the code was to get buy in, then there's a missing step here like they had him hit "allow" on a 2fa prompt. Or maybe the email was legit, since it references a "temporary code" and the case ID all…

> Good chance my reading comprehension is shot and I'm missing something, I suppose

That's more charitable than me. My UnreliableNarrator sense is tingling really badly here.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#203

Earlier quoted context omitted.

> The risk of not syncing — when you lose/reset your phone, so does your OTP app. If you don't have backup codes saved, you're cooked. Most clued-up places enable you to register a Yubikey as 2FA. So then it doesn't matter if you loose your OTP app and your backup codes because you've still got a Yubikey. (And those that don't allow Yubikey, almost certainly will have SMS as a secondary option).

You really shouldn’t use SMS 2FA. SIM swapping does happen. This kind of depends on the jurisdiction though. In some countries operators won’t reassign the phone number willy-nilly. Still, better to just not do SMS auth. These days Yubikeys are not that expensive. Get three, register them all at the most important places, and put one at a parents’ place or similar.

I agree entirely.

But the point I was making that IF the website does not allow Yubi THEN SMS is almost certainly available, and you should use that as a backup mechanism.

Why ? Some sort of backup mechanism is better than none at all.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#204
post #192

Earlier quoted context omitted.

The author knew that the scam existed and he even was skeptical. Then chose to rely on it being true despite all the red flags. That’s his fault. At some point people have to accept responsibility for their own stupid actions.

Yes, they made a mistake. They were honest about that. A little secret which will help you in life: everyone makes mistakes, even people who don’t think they will, even you. Looking all the way back to last week and 2 major NPM hacks ago, you can get access to a lot of systems simply by hitting someone when they’re busy and distracted.

There's a difference between taking accountability for your mistake and blaming other people for your mistake. Blaming others when you are clearly in the wrong is reprehensible.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#205
> The attacker already had access to ... my Google Authenticator codes, because Google had cloud-synced my codes.

This was such an obvious mis-feature I can't believe they actually rolled it out. For those using Google Authenticator you can and should disable cloud sync of your TOTP codes.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#206

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

> — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that!

I tried making this point downthread but it bears repeating higher up. Per OP, this was account with Authenticator enabled. If you have a working authenticator setup, they aren't going to "ask for a code", since by definition you're already authenticated. And while I'm no expert, I really don't think there is such a thing. Recovery for a lost account never goes back to device-in-hand once you have enabled full 2FA.

Something is being skipped in the description of the phish here. I don't think OP is being completely honest.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#207

Earlier quoted context omitted.

> Wouldn't the Apple account reject it because it fails DKIM/etc? Yeah, I would be curious to see the actual email headers of what was received. As an aside, fun fact, this would not be possible with @apple.com because Apple employees have old-school S/MIME signatures as an additional security layer.

How would recipients know to expect an S/MIME signature though. It's not like it's enforced by MTAs like DMARC is.

IIRC, if you're using Apple's Mail client it gets validated against the root cert shipped with MacOS/iOS. You get a little black tick next to the sender.

In theory, third-party places like gmail could (should ?) automagically verify S/MIME sigs where a root cert is readily available.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#208

Earlier quoted context omitted.

Dmarc/spf https://en.m.wikipedia.org/wiki/DMARC Basically, the from field on an email can be anything you want. It's like sending physical mail and using a fake letterhead with someone else's info, just type what you want. No verification. That's sometimes a good feature. Like, a third party provider can send newsletters on behalf of company A. But can also be bad, when used for phishing. However, the email doesn't j…

DMARC does check the from field in the mail, so I don't know how could this happen

Yeah, sorry if that wasn't clear in my explanation. Without these in place, you will accept anything from anyone claiming to be @A.com,but with dmarc the whole point is to flag when they're only pretending to be.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#209
post #199

> The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-synced my codes. Don't do that. Don't put your 2FAs somewhere else than in an unsynched app. Not in Bitwarden, not in any online account, nowhere else than "Something you have".

Just wondering what is the plan in case this thing you have gets lost? And would you say that using something like authy with encryption using a totally unique password is safe?

Typically you print out recovery codes and keep them somewhere safe

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#210

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Google support actually did ask me for that code when I had them disable energy savings on my nest thermostat. (it's insane that this had to be done through support, it's the setting where the power company can essentially control your thermostat in exchange for savings) To their credit/discredit, when I said no I'm not giving that out it says not to they just moved on. Not sure why they even asked then.

Yes, it is so easy to enable this setting, they even keep sending us notifications to enable it. But once enabled, it is impossible to disable it.

It is a setting that let your power company to change your temperature settings when grid is under load. We wouldn’t mind it but they turned our heat way down during one freezing night while we were sleeping. Everyone woke up with cold next day.

Post reply on HN