Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

341–350 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#341
post #101

You don't need a spoofed email to steal someone's crypto. Criminals can just hold a gun to your head and demand your keys. It's happened lots of times and it's why traditional banks are way more secure than crypto. Well done to the author for talking about it, but I hope the real lesson is learned that crypto isn't a real store of wealth and can be stolen at any time....

There's a non-zero chance someone can just roll a new key and it happens to be yours, and poof, your money is gone with no recourse. It's a tiny, infinitesimal chance: but it's a heck of a lot greater of a chance than the same thing happening with a bank account, especially the "no recourse" part.

The odds of the bank making an error related to your account and crediting you money is far greater than the odds of generating the same keypair as someone else.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#342
post #288

Earlier quoted context omitted.

Justifiable in a vacuum, but the end result is grandma knows "sometimes it's OK to give the code to the person on the phone"

They should have users receive the code and then submit said code into the application for verification, with clear instructions that this code is produced as a result of a support call, and to confirm you are on an existing call when submitting the code. Doing so would not force users to divulge codes over the phone, and enable support staff to verify identity all without training users that reading codes over the p…

Still not foolproof. Attacker can MITM the connection by initiating their own call to the real support line and relaying instructions between the user and support.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#343

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

I know Wells Fargo gets a bad wrap (and rightly so) for some of their behavior, but IME they've always had their stuff together with online access and banking.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#344

I got scammed because somebody put a fake bank location into Google Maps and so the Google voice caller ID said it was my bank. Luckily, I realized I got scammed and called the bank up right away and they got the charges reversed, which is why I still use that bank. Moral of the story: never trust inbound calls. They are the easiest vector for scammers to spoof.

Same for emails. If you didn't reach out to the person first, don't trust ANY email with alarming call-to-action text, especially if it contains a link to where you can take care of the issue.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#345

This is a great lesson on 2FA fundamentals. Picking time-based codes for 2FA is equal to picking something you know twice. That isn't strong 2FA. That is 1FA with an extra step (1.5FA). To make it all the way to 2.0FA, you must pick something you know (password) and a private key (Yubikey, smart card, etc.) that does operations in-situ, that cannot be computed anywhere else, to then match to an expected value on the…

Strong 2FA is holding your cryptocurrency in a multisignature setup instead of an exchange that holds your keys for you and can disregard the 2FA whenever it wants.

The security bottleneck is the one institution that holds all of the responsibility. It cannot be fixed by giving more hoops to authenticate themselves to the one institution

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#346
post #318

Earlier quoted context omitted.

> official phone number Great idea unless the attacker has SS7 access.

Yeah, if you're a high profile target then you need extra layers of security, but for regular folks that one weird trick is enough to make you just enough of an annoyance to make another target preferred. But in a world with Pegasus, and telecoms in smaller vacation countries selling off SS7, etc, etc - if someone good really wants to target you normal security protocols aren't going to cut it.

I imagine it will be like SIM swapping attacks where attackers will pool all their money together, gain temporary SS7 access and conduct a ton of attacks in a short window of time. Reducing the per-attack cost.

The phone network is just not a secure channel for any sort of communication

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#347

Earlier quoted context omitted.

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

I know Wells Fargo gets a bad wrap (and rightly so) for some of their behavior, but IME they've always had their stuff together with online access and banking.

For future reference: https://www.merriam-webster.com/grammar/usage-bad-rap-vs-bad...

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#350

Earlier quoted context omitted.

I have a 1-2 second rule. I pick up I say hello, if someone doesn't respond in 1-2 seconds, I hang up. They have the scammers working off phone queues, it takes a little bit of time to get the call to the scammer, who has to start off with a script, so there's a delay. Remember, the scammer, also likely not a native english speaker, also probably bored out of their mind, has to spin up, they have to read the name, un…

In those 2 seconds, do you count the inevitable preamble of "Hellooooo... Hello? ... Heeeello? Yes now I can hear you." or is that just me?

Whenever I have bluetooth headsets in a 20m radius from my phone I do that too.
Post reply on HN