Live data from Hacker News

USPS jumps to first place as most imitated brand in phishing attacks

guard.io

31–40 of 74 posts

Re: USPS jumps to first place as most imitated brand in phishing attacks

#31
post #30

Earlier quoted context omitted.

> It’s a daily chore to take out the mailbox trash Return it to the sender.

That's incredibly expensive. Bulk mail can't be returned for free.

> Bulk mail can't be returned for free

True. It’s surprisingly effective, though. Another route is to fish around for their return envelope and send them a pretty leaf or whatnot, but that could just spur them into paying more attention to you.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#32
Doesn't surprise me. The USPS is doing some idiotic things with their Informed Delivery emails that I get every morning.

Sometimes they contain inbound and outbound tracking links. If I click on a tracking link, I land on a webpage that requires me to log in. That's annoying. So I copy-and-paste that tracking code into Google, and Google gives me a link that does not require me to log in.

The USPS has trained people to happily provide authentication information whenever someone pretends to be the USPS. No wonder scammers are abusing it.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#33
post #30

Earlier quoted context omitted.

> It’s a daily chore to take out the mailbox trash Return it to the sender.

That's incredibly expensive. Bulk mail can't be returned for free.

I write "return to sender" on the envelope and drop it into a post box. It doesn't cost anything.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#34
post #30

Earlier quoted context omitted.

That's incredibly expensive. Bulk mail can't be returned for free.

I write "return to sender" on the envelope and drop it into a post box. It doesn't cost anything.

> I write "return to sender" on the envelope and drop it into a post box. It doesn't cost anything

This technically only works for first-class mail. Bulk mail doesn’t have return services.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#35
post #17
post #11

Earlier quoted context omitted.

I agree it surprises me how much people keep trusting SMS in general and how companies keep using SMS for two-factor auth, although it shouldn't at this point, but you're saying networks did a good job protecting against SMS spam and this is the reason why people trust it?

Spam delivered over SMS and the security (perceived or real) of SMS-based 2FA are entirely different subjects, though. But to kibitz on the second: a validated phone account remains by far the easiest 2FA mechanism to deploy and rely on, and 2FA remains by far more secure than simple password authentication. Advocate for apps and hardware keys all you want, don't dump on an extemely valuable technology, please. The w…

> Advocate for apps and hardware keys all you want, don't dump on an extemely valuable technology, please. The worst possible situation would be for someone to "take your advice" and refuse to use any 2FA at all.

It was your interpretation that I advise people to not use any 2FA at all. I won't honor the request to not dump on SMS, as I am perfectly happy to dump on an "extremely valuable technology" on technical demerits, on the grounds of security while simultaneously acknowledging highly debatable, highly questionable positive merits on grounds of user-experience, which more often than not oppose each other. Why do you construct a single-faceted single-shot ability for us to evaluate SMS? It sucks and it also doesn't, and saying it sucks isn't going to entirely destroy its already-terrible reputation amongst technicals. I would much rather have a message sent to my email address since that is harder to lose than a text message or phone number, and it costs me far less per month.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#36
post #26

The networks did such a good job for so long keeping spam out that people almost inherently trust sms, I've had to help multiple people with fallout from these types of texts.

Is this satire? Networks don't block spam.

They very much did, for a long time. Think of how easily enumerable phone numbers are, it's insane that you don't receive hundreds of ads per day.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#37
post #15

Fuck the USPS for allowing advertisers to bulk send junk mail to everyone for a couple dollars. It’s a daily chore to take out the mailbox trash before it’s so full they start returning important letters back to sender for not being able to fit it in.

You know you can fill out one form and 90% of it will stop?

What’s the form? Never heard of it before

Re: USPS jumps to first place as most imitated brand in phishing attacks

#38

Yup, I've gotten a couple of the USPS texts per month for the last few months now. The USPS will never text you, I asked. They only do things by mail :]

> The USPS will never text you, I asked. They only do things by mail :] Rather the USPS will never text you unprompted. There are a number of services (like package tracking) where the USPS will text you. PS: Sorry for the pedantry

No worries, probably important to point out considering the topic

Re: USPS jumps to first place as most imitated brand in phishing attacks

#39

Yup, I've gotten a couple of the USPS texts per month for the last few months now. The USPS will never text you, I asked. They only do things by mail :]

> The USPS will never text you, I asked. They only do things by mail :] Rather the USPS will never text you unprompted. There are a number of services (like package tracking) where the USPS will text you. PS: Sorry for the pedantry

The appointment scheduling system also sends out texts.

(Passport document acceptance is by appointment, not sure what other services might be)

Re: USPS jumps to first place as most imitated brand in phishing attacks

#40
post #14

Just heard from a client last week who had their credit card compromised and while waiting for their new card to arrive via mail, had more of their cards compromised by a USPS phishing text. The scam was basically a text that said "there was a problem mailing your new credit card" which lead to a USPS cloned website that asked for $0.30 to resolve the issue. My client tried two credit cards (each "failed") before fin…

I'm continually astounded how many people will be asked for a credit card through no direct action of their own (e.g. an unsolicited text not part of a conversation they initiated) and will just do it. And multiple times! Edit to be clear: I don't think these people are dumb, and I'm sure there is some scenario in which I could fall victim to a similar claim. This is more a comment on people generally as opposed to "…

The Call to Action has a ton of grip.
Post reply on HN