> Note: if you’re a developer and your users have gmail accounts, an authenticator code is NOT a 2nd factor, if that user is using Google Authenticator. So many people and developers do not understand two factor authentication. If the necessary information is automatically sync'd to another device, you likely don't have two factor auth. Example: If you log in from a Macbook, and the second auth is sent to your phone,…
Scammed out of $130K via fake Google call, spoofed Google email and auth sync
211–220 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#212Earlier quoted context omitted.
You miss the point. You can't mug someone for their Vanguard account. Robbery risk is limited to cash on hand, or arguably whatever the ATM limit is on your bank account.
Aren't elderly phone scammed out of huge amounts from bank accounts often??
Like crypto, wire transfers are difficult to track and irreversible.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#213I am not clear how the account access occurred. What code did he read? He voluntarily read his own 2FA code from his Authenticator?
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#214I have a cell phone with an area code where I no longer have any connections or ties. Almost all the spam calls I receive come from that area code. By simply ignoring or blocking calls from that area code, I can avoid nearly all of the spam.
On the plus side, iOS and Android now have features for auto-answering and filtering so thankfully I have that.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#215Its not a GREAT carrier, but I have a legacy plan for unlimited everything at $20 a line.
But if I have to call in, they do send a 2fa SMS code, and require to tell them over the call. Its absolutely ridiculous. But, Ive only had to call in 4 times in the last 9 years, so, yeah.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#216Earlier quoted context omitted.
I don't get this part either. if the scammers had spoofed the email, they would already have that code, and if they hadn't spoofed that email... I mean it looks like a case ID, why would they need it? Maybe the reading back the code was to get buy in, then there's a missing step here like they had him hit "allow" on a 2fa prompt. Or maybe the email was legit, since it references a "temporary code" and the case ID all…
> Good chance my reading comprehension is shot and I'm missing something, I suppose That's more charitable than me. My UnreliableNarrator sense is tingling really badly here.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#217Your story is humbling, and a good reminder that anyone can get “got”. We shouldn’t think ourselves above such incidents.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#218Something isn't adding up here. The author is excruciatingly rigorous with documenting lots of stuff here, including the screenshots. Then glosses over this bit awfully fast: > So when he asked me to read back a code — supposedly to prove I was still alive — in a moment of panic, I did This was an account with authenticator enabled. I'm no expert, but I really don't think there's a recovery process that works as simp…
Did they send the fake legal email and at same time trigger a recovery code to be sent?
Is this like the same thing in discord where they ask you for your email to join a server then ask you for a code sent to verify you own that email but really they submitted the email for password reset. The victim doesn't realize it's a real recovery code sent by Microsoft, etc instead in the moment thinking it is a "discord code". Once you submit the code in discord they have your account stolen in seconds.
Is this what the article is attempting to describe?
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#219Earlier quoted context omitted.
Google Authenticator app defaults to backing up the TOTP secrets so if you log in on a new device you have them there. Pretty poor default for security, and you can disable it, but not the first time I've heard of this biting someone.
The risk of not syncing — when you lose/reset your phone, so does your OTP app. If you don't have backup codes saved, you're cooked.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#220Earlier quoted context omitted.
I’ve personally never had that happen. It should go on a name and shame list.
>I’ve personally never had that happen. It should go on a name and shame list The key situation for giving out an SMS code that the gp is pointing out is the customer initiates the call to the support center . For example, suppose somebody wants to add a credit-card to their smartphone digital wallet. They have to call the bank issuing their credit-card to do that . Once the customer support person answers the call,…
Note, however, that those are two "totally different sequences of steps" to you and I, and "completely analogous / equivalent sequences of steps" to my father in law :-/