You don't need a spoofed email to steal someone's crypto. Criminals can just hold a gun to your head and demand your keys. It's happened lots of times and it's why traditional banks are way more secure than crypto. Well done to the author for talking about it, but I hope the real lesson is learned that crypto isn't a real store of wealth and can be stolen at any time....
There's a non-zero chance someone can just roll a new key and it happens to be yours, and poof, your money is gone with no recourse. It's a tiny, infinitesimal chance: but it's a heck of a lot greater of a chance than the same thing happening with a bank account, especially the "no recourse" part.
Scammed out of $130K via fake Google call, spoofed Google email and auth sync
341–350 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#342Earlier quoted context omitted.
Justifiable in a vacuum, but the end result is grandma knows "sometimes it's OK to give the code to the person on the phone"
They should have users receive the code and then submit said code into the application for verification, with clear instructions that this code is produced as a result of a support call, and to confirm you are on an existing call when submitting the code. Doing so would not force users to divulge codes over the phone, and enable support staff to verify identity all without training users that reading codes over the p…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#343A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#344I got scammed because somebody put a fake bank location into Google Maps and so the Google voice caller ID said it was my bank. Luckily, I realized I got scammed and called the bank up right away and they got the charges reversed, which is why I still use that bank. Moral of the story: never trust inbound calls. They are the easiest vector for scammers to spoof.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#345This is a great lesson on 2FA fundamentals. Picking time-based codes for 2FA is equal to picking something you know twice. That isn't strong 2FA. That is 1FA with an extra step (1.5FA). To make it all the way to 2.0FA, you must pick something you know (password) and a private key (Yubikey, smart card, etc.) that does operations in-situ, that cannot be computed anywhere else, to then match to an expected value on the…
The security bottleneck is the one institution that holds all of the responsibility. It cannot be fixed by giving more hoops to authenticate themselves to the one institution
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#346Earlier quoted context omitted.
> official phone number Great idea unless the attacker has SS7 access.
Yeah, if you're a high profile target then you need extra layers of security, but for regular folks that one weird trick is enough to make you just enough of an annoyance to make another target preferred. But in a world with Pegasus, and telecoms in smaller vacation countries selling off SS7, etc, etc - if someone good really wants to target you normal security protocols aren't going to cut it.
The phone network is just not a secure channel for any sort of communication
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#347Earlier quoted context omitted.
Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…
I know Wells Fargo gets a bad wrap (and rightly so) for some of their behavior, but IME they've always had their stuff together with online access and banking.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#348The most infuriating part of the story by far.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#349Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#350Earlier quoted context omitted.
I have a 1-2 second rule. I pick up I say hello, if someone doesn't respond in 1-2 seconds, I hang up. They have the scammers working off phone queues, it takes a little bit of time to get the call to the scammer, who has to start off with a script, so there's a delay. Remember, the scammer, also likely not a native english speaker, also probably bored out of their mind, has to spin up, they have to read the name, un…
In those 2 seconds, do you count the inevitable preamble of "Hellooooo... Hello? ... Heeeello? Yes now I can hear you." or is that just me?