Live data from Hacker News

I'm a scam prevention expert and I got scammed

lupinia.net

421–430 of 562 posts

Re: I'm a scam prevention expert and I got scammed

#421
ALWAYS CALL BACK. If they are legitimate, advise they should block the transactions until you've been able to reconnect with them. Get their details, and advise you will call back on the company's dedicated fraud prevention hotline.

NEVER give details over the phone on a call you didn't initiate EVER.

Re: I'm a scam prevention expert and I got scammed

#422
post #119

Earlier quoted context omitted.

There may be inferences you can make from the sum that aren't immediately obvious. If cards can end in four zeros, the sum and the last four digits contain equivalent information, but you would also confirm that three of the digits are zeros if the sum was 1. It's something that, if I were a bank, I would want someone with a background in number theory to weigh in on. If I were a paranoid bank exec, I wouldn't trust…

Don't forget the last digit is a checksum digit too. Which I still can't give you an attack, but I also agree that I definitely can't say I'm sure there isn't one.

That does reduce the number of possibilities greatly, which might matter for some attack scenarios, but usually not IMHO as rate limits should thwart any online brute force.

I'd be interested to know how greatly, if someone has the equation for that.

Re: I'm a scam prevention expert and I got scammed

#423
post #6

I nearly got taken by a scammer because Amazon transferred me to one. I purchased a set of Reolink cameras on Amazon, (they've been great) one of them failed a couple months in. I contacted Amazon customer support (via my Amazon login and in their interface) and they wanted to troubleshoot with their technical team. Eventually the (very helpful) Amazon technician suggested contacting Reolink for support and started a…

Keep in mind some manager 1000% got promoted for introducing this “innovative” feature.

Re: I'm a scam prevention expert and I got scammed

#424
Uh, I'm not a scam prevention expert, yet I would NOT have followed your steps. If a bank (or ANY entity) calls me up claiming to be X, I usually ask them what the issue is, then hang up and call the number listed on my card, the official website or documentation, etc.

You should never give out ANY information on the receiving end of a phone call. Period. Ask what their name is, what department they are in, hang up, call the number you were provided prior, and ask for the same department/person and describe the details of the call.

Re: I'm a scam prevention expert and I got scammed

#425
post #6

I nearly got taken by a scammer because Amazon transferred me to one. I purchased a set of Reolink cameras on Amazon, (they've been great) one of them failed a couple months in. I contacted Amazon customer support (via my Amazon login and in their interface) and they wanted to troubleshoot with their technical team. Eventually the (very helpful) Amazon technician suggested contacting Reolink for support and started a…

It sounds like you bought a product not sold by Amazon and got transferred to the company in question.

Don't buy 3rd party products sold on Amazon. I always tell people this. They ignore me and then stories like yours pop up.

NOTE: This applies to prime items as well. Amazon's vetting services for 3rd party sellers is nonexistent. I could literally sell you dog shit right now; with no verification I even exist. I've had a seller account for over a decade, and I've not sold a single item. The Amazon Marketplace is an anonymous Craigslist. Please don't forget that.

Re: I'm a scam prevention expert and I got scammed

#426
post #150
post #137

Earlier quoted context omitted.

So just ask the other party to give you a salt they generate on the spot? And/or you do so on your end? You can still get targeted for a direct attack but much less likely to end up caught in a dragnet approach.

That would prevent using a pre-generated lookup table but doesn't help much with brute force attacks. All possible card numbers is a finite set, and if you have the sha256(card number + salt), you can figure out which card number was used as input given the improbability of sha256 collisions within that set. Keep in mind this in the context of an account holder asking the bank to authenticate themselves on a phone ca…

Not to mention, how many bits of salt can you transmit by voice in this context without this turning into a whole song and dance?

> That would prevent using a pre-generated lookup table

Only for a healthy pinch of salt, not a couple grains, right?

Re: I'm a scam prevention expert and I got scammed

#427
post #343

Earlier quoted context omitted.

I saw this sort of thing in american sitcoms as a child, and I was always mildly triggered by it. Here in Australia the landline phone system disconnects as soon as either person hangs up. On the shows they would sometimes hang up the phone, then somebody else picked up a receiver and the call continued?? Phones don't work like that! Go try it on your real phone, and you'll see! It never occurred to me that US phones…

Just going from memory - but I’m fairly sure that around 25 to 30 years ago, in Australia, it did work the way that is being described. That is, the person receiving the call could not disconnect the call by hanging up. The person making the call needed to hang up, otherwise the line stayed open. I messed around with this a few times because I was amazed it existed. Editing to add that more detail, since I’m basicall…

Was harassment by exploiting this ever a big problem? Seems like you could call someone and if they pick up, you now control their phone line... indefinitely?

Re: I'm a scam prevention expert and I got scammed

#428
post #339
post #211

Earlier quoted context omitted.

This has a similarity to the original story here, in that the original sounded like: "They behaved a lot like a scammer would, but I also totally expect my real bank to behave like a scammer would" .

Many years ago, I have worked in a call centre for a bank and the process for calling customers was exactly what you’d expect from a scammer. In the standard/credit card section (not, for example, credit card debt collections), it was rare to have to make outbound calls, but when they were needed, no information could be given out until the customer answered security questions. Some customers questioned this because…

This happened to me with Bank of America’s fraud department. I had a charge that tripped the fraud detector on a relatively new card. I don’t recall the sequence of events, but I believe I was prompted to request a callback from the fraud department. When they called back I had to answer a bunch of PII questions, and then they pushed a 2FA code to me and asked me to read it back over the phone. I told him, the 2FA message literally says to never give this number out to anyone, but they insisted it was necessary to continue. I was shocked that the banks fraud department would be so cavalier.

Re: I'm a scam prevention expert and I got scammed

#429

ALWAYS CALL BACK. If they are legitimate, advise they should block the transactions until you've been able to reconnect with them. Get their details, and advise you will call back on the company's dedicated fraud prevention hotline. NEVER give details over the phone on a call you didn't initiate EVER.

Yes, but banks shouldn't be using these insecure processes in the first place. I got a legit fraud text alert from my bank directing me to call a certain number. It should have asked me to call the number on my card.

Re: I'm a scam prevention expert and I got scammed

#430
post #21

There's one easy rule that could have avoided all of this - never give out any info on incoming calls. If I get a call or text about fraudulent transactions, I'll keep them on hold while I log into the bank website. If I get a call about a late payment, I'll thank them for the info and ask them to stay on while I pay online. If I get an inbound call with a more complex request, I'll ask them for their employee info a…

I feel like the author made two mistakes that anyone who goes after scammers should know. First is to never trust the caller. Didn't matter what info they have. Second is never give your 2fa. Who cares if some third party product has some wonky scheme that requires it. Don't do it.
Post reply on HN