Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

331–340 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#331

DHL, FedEx, and UPS are experts in overcharging to process a form and not caring about customers. Duty and VAT are usually low compared to this processing fee, and shipping has already been paid. Here is the catch in the EU, this simple duty form can be processed by the receiver, an agent (some related to the carrier), or an attorney-in-fact of the receiver. The big three carriers (and many others) threaten you if yo…

Same in Canada, though, if I understand correctly, you have to visit a customs checkpoint in person to make a declaration: https://goingawesomeplaces.com/how-to-avoid-paying-ups-broke...

The processing fee is as high as $35 when the taxes are as low as $10, and then you get charged tax on the fee too!

CBSA should require affirmative opt-in to use the shipper as the broker, and allow you to file the paperwork yourself on their site.

Re: Thanks FedEx, this is why we keep getting phished

#332

Earlier quoted context omitted.

I ordered a computer from Southern California, they shipped it to Texas, Florida, Maine, and then back to Northern California. My last two orders were just stolen from someone at FedEx. They got the shipment, but it never left the facility after that. Customer service is an offshore apology machine that can't help with anything. I used to prefer fedex, but the standard of service is so subpar I go out of my way to av…

I assume you know that you can open a claim? They'll either find your package really fast, or will have to pay its full value. Often the vendor has to initiate the claim. If the vendor doesn't want to open a claim, refund. If the vendor doesn't want to refund, chargeback.

Be careful about those chargebacks. I bought two new pixel phones directly from Google and only one arrived. Google support was of course awful and Fedex did absolutely nothing outside of asking me what color the phone was. lol

I ended up reversing charges for the missing phone and Google immediately wrecked me - I was using Fi at the time so they killed my cell service and killed my ability to use Google Pay for anything - including the Play Store. Probably some other stuff I don't even remember. Between my personal account and my business accounts I realized at that moment that Google could completely wreck my life. Be careful about retaliation for a chargeback, if you live within one company's ecosystem it can be a brutal retaliation you're not ready for.

Re: Thanks FedEx, this is why we keep getting phished

#333

There really needs to be some kind of cryptographic authentication system for text messages and caller ID that gives the recipient absolute certainty about the identity of the sender. Registering a name in this system should require real-world proof of identity including a business address and the contact information of real people. There should be serious financial penalties for identity fraud. It should be an open…

This will never work as long as calls and SMS messages are routed over the existing telecom networks. The infrastructure is simply too insecure to enable this kind of scheme. If calls are routed over internet then it becomes more viable but obviously there is still a large coordination problem and misalignment of incentives.

BS. Many countries have successfully implemented SMS sender registration/verification schemes. See for example here for a list: https://support.sms.to/support/solutions/articles/4300056265...

The details differ per country, but either all non-registered senderids will be blocked, or registered senderids will be allowed only from authorized sources. The degree of mandatoriness varies also, in some places its mandatory for telcos to comply, in other places it is some voluntary cooperative scheme.

But despite such details, the problem is clearly not completely intractable.

Re: Thanks FedEx, this is why we keep getting phished

#334

This reinforces the need for "mutual trust security" that I've been calling for now for years. All of the significant authentication schemes are built to validate the customer, and none validate the vendor. When your bank or mobile provider gives you a call : how do you know it's them? They start asking you for personal data right away, but you have no idea who you are sharing information with. We need "mutual authen…

For voice calls, and maybe SMS, there could be mechanism to do bidirectional authentication with words. The problem is that would have to switch to app to generate the words and validate the response. For user, password or passkey would work. For company, the SSL cert on domain might work. Otherwise, would need to download certificates.

For SMS and voice calls, it would help if they could implement call authentication so can trust the number. Phones should show the user if the number is validated. It would also be good to add trusted CallerID names; Google does with some numbers.

Re: Thanks FedEx, this is why we keep getting phished

#335

At my company, they announced that in the upcoming month there would be an internal phishing sensibility campaign. Then, in the same month, they started sending out incredibly dodgy looking emails to "security training" provided by an external website. Of all emails, those looked the most like phishing but they are not. I decided that I refuse to do this training completely because to me it seems crazy how that was c…

My company uses an outside vendor for security training that requires us to login using company credentials.

The outside security vendors also run phishing security campaigns that they send out from their own domain, and that have "phishing" URLs that point to the same domain we do the training on.

I got reported as being phished for following a link that goes to the SAME domain as our required security training. Our security compliance team got my point when I reported every required training reminder as coming from a known phishing domain.

Re: Thanks FedEx, this is why we keep getting phished

#336

Earlier quoted context omitted.

You can spend as much as lawyer money as you want on arguing whatever nonsense you want, reasonableness is a common standard so sure, people will have spent lots of money pointlessly arguing about it but that's not a problem with reasonableness.

Sometimes the arguers win and set a new precedent... so it definitely creates a new problem with everyone who subsequently encounters the issue.

Sure, I'm certainly not going to pretend this is perfect, but it seems to be working basically fine and I don't see "reasonableness" - which actually avoids a lot of wrangling - as a problem.

Compare Legal Tender against an ordinary Reasonableness test. Legal Tender says that I only have to accept payment of your debt in specific forms (the "Legal Tender") and I can refuse to accept other payment.

So maybe our currency is Doodads, the Legal Tender law specifies that the 10 and 50 Doodad Coins shall be Legal Tender, and you owe me 15000 Doodads. You try to pay by card, I refuse. You try to write a cheque, I refuse. You try to pay with 150 of the 100 Doodad Coins, but again I refuse. Eventually I take you to court and... I win?! You did not pay your debt in the required Legal Tender.

With Reasonableness the court might buy that it was OK to refuse to accept the card (maybe I don't have a merchant account) and maybe even the cheque too (but already by then I expect a judge to have a lot of questions about how I thought you would pay and I'd better have a really good answer) but the 100 Doodad Coins are clearly money, with Reasonableness as our standard it's obvious that I lose my case, there's no need to write a law saying "Yeah duh, the 100 Doodad Coin is money" because a reasonable person can see that.

Re: Thanks FedEx, this is why we keep getting phished

#337
post #245

A while ago my wife applied for a home equity loan. At some point I got a call from someone claiming to be from the bank she had applied through (I forget which one), calling to make sure I approved the loan since the home is in both our names. He asked for my name, which I gave him, and then the last four digits of my social security number, which I also gave him. He then proceeded to ask for my full social security…

Terms of service from my bank say you're not allowed to give your PIN or secrets like one-time passwords (called "TAN" here) to third parties, not even the bank employees themselves.

But when I contacted them about a phishing practice, it was A-OK because it was a "legitimate" website that phished your credentials to view the last 180 days of transaction histories, compute a credit score, and then withdraw the money. They would "look into the situation and see if a better solution could be found" with this german company...

I don't understand how anyone is okay with this but klara or klarna or something is a pretty popular payment provider in germany as far as I know, but so my experience is now that banks like to change their security-relevant terms one-sided. But it's your fault if you give out secrets to the wrong person of course, not like the bank was going to care if your social security number had gone to a scammer for example

Re: Thanks FedEx, this is why we keep getting phished

#338

Earlier quoted context omitted.

On one hand, I agree that just disagreeing with a guideline isn’t perjury. Especially in a case like this where lots of the industry still uses the old (bad, imo) plan. On the other, an expert witness has specifically represented themselves to be an expert. Is there any level of incompetence that raises to the level of perjury in that case? IMO there ought to be.

That would be argued in cross-examination. A witness can be shown to be not a good witness. Perjury is very specific to knowingly lying while testifying under oath. We really don't want to expand it to areas of ignorance or disagreement; that way would stop people from testifying entirely.

An expert is someone who claims to know though, and thus if they say something that contradicts established facts they are lying under oath.

Re: Thanks FedEx, this is why we keep getting phished

#339

Earlier quoted context omitted.

Now that I think of it, I'm not sure I've ever seen a government payment site hosted on .gov; usually .com.

You can tell it's legit if they charge you $2 extra for a credit card instead of a bank transfer lol

Most have gone that way, but a few were still letting you put your entire property tax on credit card with no fee whatsoever as recently as last year.

Woohoo free miles! Sometimes the fee is so low that even when they do charge it, it's worth using the credit card.

Re: Thanks FedEx, this is why we keep getting phished

#340
post #3

Maybe its just the hunan brain bad at perception, but I feel like there's some system compromised and info is leaked so scammers know when you are expecting a package because FedEx/USPS spam text increases.

But in a modern day and age, when aren’t you expecting a package? Nearly 100% of the time, I am expecting a notification from Canada Post or Amazon (FedEx less frequently, but still). Even outside of that, you can often predict when people are expecting a package. Christmas. After various sales weeks.

What are you buying constantly? Apart from food and hygiene items, I mostly shop online. I feel I do order too much already, but the parcels are one every 1-2 months. Any more than that and the apartment would start filling up, I imagine.
Post reply on HN