Scammed out of $130K via fake Google call, spoofed Google email and auth sync
451–460 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#452Regardless of whether you received an email from Coinbase notifying that you were affected, the attack they suffered is much larger than they let on to the SEC.
https://www.coinbase.com/blog/protecting-our-customers-stand...
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#453Someone keeps trying to hack into my main Google account (I keep getting 2FA requests), which unfortunately was part of some early crypto activity and was traced back to me, and I don’t know what to do. I myself can keep denying them but I have a toddler and if he accidentally accepts one of them, I’m screwed. And since it’s impossible to reach anyone at Google, WTF do I do?
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#454Earlier quoted context omitted.
I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.
For some reason I can't seem to find my local Google branch's phone number on their website...
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#455How did they get the passwords to his Google and Coinbase accounts? He reused passwords? The same one for Google as for Coinbase? Or did they reset his Coinbase password via his Gmail? The post doesn't make this explicit, but it warns against password reuse.
I believe they logged into coinbase with Google SSO. And then they used my Google Authenticator codes which were cloud synced as the second factor auth method. A warning to auth engineers: if an account is using a Gmail address, then auth codes from Google Authenticator should not be considered a second factor.
Incredible take. I don't know what's worse here — suggesting gmail address = google authenticator, thinking you can know the source of "auth codes", or the fact this is coming from an auth engineer. I'm switching to handwritten HMACs on paper napkins today.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#456Earlier quoted context omitted.
I lost the original email—the attacker deleted all evidence and then cleared my trash (and yes I tried using the Google tool to find deleted emails, but the attacker cleared that too). The reason I have this email is because I forwarded this email on to phishing@google.com, before the attacker deleted everything. When I got control of my account, and removed the scammer recovery methods (he added a windows device—I d…
I updated the post and include the headers & html of the bounced-copy, although I don't think it's very useful.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#457Earlier quoted context omitted.
The convenience is that people don’t drop their phone in the toilet and suddenly lose access to all of their accounts.
Why would you have passwords/credentials to your accounts (including financial accounts with tens of thousands of dollars) on a device that not only you can drop in the toilet, but also lose, or get stolen, or hacked? Do you have any idea what access all your cute apps have to the contents of your device?
Google took forever before adding cloud-sync to their TOTP app even though pretty much all the other ones did it from day 1. And I bet a non-trivial amount of people got locked out of their accounts because they hadn't reliably stored recovery codes.
Financial services are actually the least of your worries since you can get ahold of customer service and eventually recover your credentials even if it takes a few days and some snail mail. However if you lose access to Gmail or Facebook, good luck unless you know an employee.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#458Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#459Earlier quoted context omitted.
Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…
I've gotten calls from my bank before, where they tried to get me to authenticate after I answered the phone. I said "look, you called me, I'd be crazy to just answer the phone and give out personal info." They refused to provide any info that I could have used to validate that they were legit (like telling me something about my account number, when my account was created, etc.). They said I had to authenticate with…
It was also difficult that when people asked whether they could call back, we encouraged them to, but couldn't guarantee they'd then speak to the same person. They'd need to just talk to whoever they got. That was usually enough to put the person off and they would just take the risk (unfortunately).
Edit: Just wanted to add that I personally didn't want the people to make an exception to their unknown caller scepticism. Perhaps this bugged me more than others, but I would strongly encourage them to call back, and then do my best to get the call-back transferred to me. For that and many other reasons which I like to think of as preferring quality over quantity, my stats were as bad as you'd imagine!
When that bank did really try to tackle this issue, they quickly realised that there was more than one level of risk, and for the vast majority of the calls, we could get by with very little of that customer verification process - basically just that we had called them on a number they had provided, and they stated their name (which I think was more as a recorded verification that they were at least stating they were the correct person). For the much smaller number of outbound calls with more risk, we could then ask the person to call back. Once the risk peeps were on board, it was vastly improved fairly easily.
I'm not in that space at all now, but it seems far easier than it was back then. A few banks I'm a customer of send notifications right into the online banking app, which the customer approves, confirming that they at least have access to that. I don't know what they do if you don't have the app installed. I do find it a little sad that it is yet another thing pushing you to need a smartphone (and to install yet another app). On the other hand, I think all of those banks require me to have the app to use as an authentication token to do any kind of online banking even on a desktop browser, so if you're going to do that, may as well take advantage of it everywhere.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#460Earlier quoted context omitted.
> It's interesting how easily Google results rankings are manipulated by bad actors, and how unvetted the scams are in paid adverts on and through Google. Well, SEO, I get that this kind of gaming is hard to prevent, not at Google's scale. But the AdWords scams? Or all the other fake ad scams, chumboxes and god knows what? The complete lack of audits around something that actually causes money to change hands should…
Yes, and that same lack of lawyers/friction is what also allows legitimate small businesses to thrive. I've worked for many, and out of those many, none of them had lawyers involved at all. It is all about balance. Google could do more here, however the answer is not as obvious as you might think. Especially in an age where identities get stolen often and the lag time on catching said fraud is quite long. The issue i…
Oh it is. A basic background check alone done by an actual human to see if the business is actually real, let's say this costs Google 1h @ 40 dollars plus 20 dollars for credit bureau fees. Google can offload that cost to the advertiser - even for a small cookie store, that's hardly an expense.
And after that, vet the campaign material for each asset. When you have 200 dollars in ad spend (which isn't much), 10 dollars should go pretty far in having a human see if the "pizza store" didn't just place an ad for penile enlargement.
> Automated checks work very well until they don't.
The key thing is, the entire ad industry is amoral. No one cares about fraud or brand reputation any more, not when you see chumbox ads on "reputable" newspapers. So everyone seems to think "why should I leave a few dollars on the table?".