Live data from Hacker News

The clever reason scammers can’t spell (2019)

itservices.wp.st-andrews.ac.uk

31–40 of 117 posts

Re: The clever reason scammers can’t spell (2019)

#32

Close to 20 years ago I got an email that in it's entirety said "I have a powful tool. I suspect youd like it", exactly as written. No links, no attachments, just plain text. I showed it to my then girlfriend and now wife and since then we have adopted "powful tool" as a term we apply to really great devices or machinery of impressive heritage or even some good software. Warms my heart.

I’ve also gotten mysterious scam emails that contain no information. What’s their purpose?

If I had to guess, it’s a trick to get people engaged.

There’s no link or request for money, so people probably respond more often.

I imagine like many areas of persuasion (like interrogation), getting someone to start talking is the “foot in the door” that starts to snow ball, even if it’s not about anything relevant.

Re: The clever reason scammers can’t spell (2019)

#33

Close to 20 years ago I got an email that in it's entirety said "I have a powful tool. I suspect youd like it", exactly as written. No links, no attachments, just plain text. I showed it to my then girlfriend and now wife and since then we have adopted "powful tool" as a term we apply to really great devices or machinery of impressive heritage or even some good software. Warms my heart.

A cursory search gave back this gem. Same spam email in 2003 except it goes off on a tangent about a Symantec deal worth a lot of money (since someone mentioned they used Norton 2003) that someone used to buy a company sports car. Then people just keep talking about sports cars.

https://www.mail-archive.com/membersozdat@datascribe.com.au/...

Re: The clever reason scammers can’t spell (2019)

#34
post #20

Ah yes, “smart people don’t get scammed, you’re smart aren’t you?” Very smarmy line of thinking. Unfortunately on the rise in recent years. We are all vulnerable to scams and victim blaming doesn’t help the conversation any.

It irks me that this is the bulk of what we're taught of phishing training - just to look for the obvious mistakes.

We've been seeing a rise in attacks that are launched from compromised accounts, where the email is a reply to a previous thread. So you have the context, name and address of someone you're presumably already familiar with. The last one I looked at had the body "What do you think of this?", their signature was missing, and the payload was a html file that delivered a passworded zip via a data: blob, and the password was in the html file. "for security".

The attachment was the only real tell. Also noticed the sending server was in the wrong country, but since the thread they were replying to had to come from compromised access, I wouldn't trust that either. If the attachment was an office doc, the payload would have been delivered before I heard anything about it.

It's not quite spear-phishing (you're still a target of opportunity rather than a selected target), but it's effective and convincing. But trainings haven't got much past the nigerian princes yet.

Re: The clever reason scammers can’t spell (2019)

#35

The same trick is applied to trick potential customers into going through a sales funnel and convert to a paying customer. "There are 42 people watching this hotel right now! Only 3 rooms available for your dates! We'll murder ANOTHER puppy if you don't book right now!" Yes, I worked for Booking.com. They don't do it everywhere, in some places it's illegal, and sometimes they simply change the words slightly to make…

Is this why when I'm on Etsy, some obscure, niche item that I'm looking at will always say "13 people have this in their carts right now"? Etsy doesn't seem like the type to me, or maybe that code is just flawed

Re: The clever reason scammers can’t spell (2019)

#36
post #3

I was wondering that recently. But I don't know -- I feel like they'd catch even the discerning people if they did a better job of it. Why don't they exactly replicate what a Google or Chase email looks like? I don't see how I wouldn't fall for that.

I'd buy the argument made in the article more if they could explain what harm the scammers are avoiding by weeding those of us who can spot a misspelling as early as possible. Do they immediately start investing a great deal of time in a possible "mark" right after one reply from them?

Re: The clever reason scammers can’t spell (2019)

#37

The same trick is applied to trick potential customers into going through a sales funnel and convert to a paying customer. "There are 42 people watching this hotel right now! Only 3 rooms available for your dates! We'll murder ANOTHER puppy if you don't book right now!" Yes, I worked for Booking.com. They don't do it everywhere, in some places it's illegal, and sometimes they simply change the words slightly to make…

For a while on change.org (2021 was when I observed it) if you were looking at a petition with n signatures, they would show you n-10 or so, and increment the counter erratically over the next couple minutes to add the remaining 10... as though people were rapidly trickling in to sign this very hot petition right this minute.

Re: The clever reason scammers can’t spell (2019)

#38

Close to 20 years ago I got an email that in it's entirety said "I have a powful tool. I suspect youd like it", exactly as written. No links, no attachments, just plain text. I showed it to my then girlfriend and now wife and since then we have adopted "powful tool" as a term we apply to really great devices or machinery of impressive heritage or even some good software. Warms my heart.

> From: "Neateye"

> Subject: Gouranga

> Call out Gouranga be happy!!!

> Gouranga Gouranga Gouranga ....

> That which brings the highest happiness!!

It’s been, fuck, two decades and this is still in my mbox. My wife and I still shout Gouranga at each other some days and, hell, who am I to argue that it doesn’t bring the highest happiness!!

Re: The clever reason scammers can’t spell (2019)

#39
post #30

The real reason scammers can't spell and use good grammar is because they are not proficient at spelling and grammar.

This. I recently got approached by a scammer on Facebook marketplace. It was never going to work but the spelling/grammar issues instantly made me think something fishy was going on.

They put plenty of investment into scamming me before I called them out, and I don't think their grammatical errors would have served to filter anyone (because it also could have just been someone wanting to buy something who happens to have bad English).

Re: The clever reason scammers can’t spell (2019)

#40
post #6

The article misses one of the most common misspelling reason: getting thru Bayesian filters. It has more to do with tech and less with psychology.

This is true but also... In my experience[1] a large majority of facebook-level romance scammers use the same copypasta messages when possible, because they actually are from (e.g.)Nigeria and really do have poor English. This is especially relevant to your point because facebook could EASILY be flagging people based on known pasta messages, for review or shadowbanning etc. They presumably don't do this because "not…

Anyone ever tried flagging those obvious scam accounts with ridiculously obviously fake photos (or, at least misappropriated from some aspiring models insta account).

Even when it's blatantly obvious Facebook always tells me that their account doesn't break their community standards...

Post reply on HN