Live data from Hacker News

Americans duped into losing $10B by illegal Indian call centres in 2022: report

timesofindia.indiatimes.com

491–500 of 504 posts

Re: Americans duped into losing $10B by illegal Indian call centres in 2022: report

#491

It's mind-boggling that the United States allows this kind of thing to happen. In the EU I get maybe one spam call every couple of months. From the stories you hear from Americans on HN, Americans get multiple spam/scam calls a day, and the vast majority of their inbound calls are spam/scams. What is going wrong in the US that isn't going wrong in the EU? Language barrier? Regulatory capture?

The US just has large number of people in one country code who mostly speak English, have high incomes, a uniform retail landscape ("go to CVS and get a Google Play card" works everywhere), and an abundance of options for telephony. It's not like Indian scammers are beholden to EU law but not US law.

So basically, monocrops are vulnerable to pests.

Re: Americans duped into losing $10B by illegal Indian call centres in 2022: report

#492
post #462

Earlier quoted context omitted.

> actually useful identity cards It costs like 100 euros to buy a fake ID that'll work at any bank in Germany. This is a bizarre trope oft-repeated on HN by techies who think that banks actually verify chipped ID cards, they do not. And even if they did, they have to accept a plenty of EU IDs which do not have chips. Google and look at how a Greek ID card looks like, it's literally a piece of paper. > opening fake ba…

> It costs like 100 euros to buy a fake ID that'll work at any bank in Germany. This is a bizarre trope oft-repeated on HN by techies who think that banks actually verify chipped ID cards, they do not. And even if they did, they have to accept a plenty of EU IDs which do not have chips. I'm not talking about the eID chip, that isn't verified indeed - but at least in my experience, when opening a bank account in perso…

>but at least in my experience, when opening a bank account in person, they do diligent checks

Most banks don't even have UV lights, not that fake IDs don't usually have decent UV markings anyway. Hardly very diligent.

>for non-German cards they even have a database how different nations' ID cards should look like and what the security markings are.

As do essentially all banks in the world, doesn't save you though. Many European IDs (Romanian, Greek for example) do not have any meaningful security features, Romanian IDs can look completely different depending on which day and which city they're printed in and there's no reference guide for this.

Even a good enough German fake won't cost much https://telegra.ph/ID-Cloning-Only-12-17 The hologram isn't perfect, but that'll work at any bank.

>Video-Ident aka holding your ID card into your webcam is indeed vulnerable, and banks like N26 got in really hot water, which forced them to ramp up their anti-fraud measures to a degree even legitimate customers got massively impacted [1].

Pretty much any fake ID that'll pass Video-Ident will generally work at the bank too.

>The classic scams are the majority, and yet even these they yield the scammers only something like 13 million euros a year [2], that's laughable compared to the amount Americans lose, even if one assumes that only a tenth of the cases gets reported at all.

This is totally wrong, there are individual people running car-selling scams on mobile.de netting more than that.

>And again: entire classes of scams like "I got arrested and need bail money" or "I was involved in a traffic accident and need to pay the hospital cash advance for treatment" don't work here because we don't have cash bail or bills from hospitals and people know that. If you would try this scam on any European, they'd laugh you off because they know that this doesn't exist.

Those scams are common in the US and UK, but they only make up a small part of the $ losses. The bulk of the losses comes in the form of people losing all of their savings as their bank account is emptied.

Re: Americans duped into losing $10B by illegal Indian call centres in 2022: report

#493

Earlier quoted context omitted.

Are you referring to STIR/SHAKEN that is a requirement and has been/is being rolled out? I'm not sure how much was commercial benefit vs lazyness/no incentive to solve the issue directly - the telcos aren't making a lot of money on inbound calling. It's just a problem that didn't impact them directly - only their customers.

Have to touch on this as it's a common theme to my response. There absolutely are regulations. However, regulations being in place, and the enforcement of these regulations are different. STIR/SHAKEN is a requirement, however it's an easy requirement for scammers to meet. (Numbers are super cheap to buy in bulk, pennies per month typically). Sooner or later they'll run out. The second side of the regulation miss is t…

Isn't that basically what they did? I think the FCC authorized the disconnection of a handful of service providers, and has been aggressively sending notices to others.

https://www.engadget.com/robocall-company-may-receive-the-la...

Re: Americans duped into losing $10B by illegal Indian call centres in 2022: report

#494
post #433

Earlier quoted context omitted.

Are you referring to STIR/SHAKEN that is a requirement and has been/is being rolled out? I'm not sure how much was commercial benefit vs lazyness/no incentive to solve the issue directly - the telcos aren't making a lot of money on inbound calling. It's just a problem that didn't impact them directly - only their customers.

The telco's complacency have trained their customers to not answer the phone thereby destroying one of their primary businesses. Gen Z and Y consider it rude to call people.

I think that was true long before robo calling was a big thing.

Since texting and even back from the AIM/IRC generation - when I was in college 20 years ago, with T9, people were already primarily were texting not calling.

Re: Americans duped into losing $10B by illegal Indian call centres in 2022: report

#495

Earlier quoted context omitted.

I suppose it's not that easy. They can use international VOIP providers to route their calls, maybe even run their own, rotating the numbers they use and disguising the actual origin. If that wouldn't work you could probably hire people in other countries to put some agent software on something like a smart phone and use these.

It is that easy. Regardless of what convoluted setup they're using, at some point those calls need to get to the US-based carrier. That is where they can be blocked. The carrier can simply say "we'll stop peering with you if more than 10% of your calls are spam" and the upstream carriers will have to clean up their act (better screen their customers or implement similar terms) or be cut off from being able to reach t…

That works until you land in a situation where the calls are coming from a carrier who can't (or won't) do enough about it, but the carrier has enough legitimate traffic that it will annoy many of your customers to just shut them out. Remember: All the actual companies or carriers you can identify have nothing to do with the actual scammers. They are intermediaries and the scammers will hide between legitimate calls in one way or other.

Re: Americans duped into losing $10B by illegal Indian call centres in 2022: report

#496

Earlier quoted context omitted.

The US just has large number of people in one country code who mostly speak English, have high incomes, a uniform retail landscape ("go to CVS and get a Google Play card" works everywhere), and an abundance of options for telephony. It's not like Indian scammers are beholden to EU law but not US law.

Nope, the incentives don't work like that. I regularly get spam calls in Chinese. My best guess is this is because if they randomly dial Bay Area area codes they sometimes get Chinese people.

That's the same statement, they wouldn't use a Chinese robo-caller in an area with little to no Chinese population

Re: Americans duped into losing $10B by illegal Indian call centres in 2022: report

#497

Earlier quoted context omitted.

Nope, the incentives don't work like that. I regularly get spam calls in Chinese. My best guess is this is because if they randomly dial Bay Area area codes they sometimes get Chinese people.

That's the same statement, they wouldn't use a Chinese robo-caller in an area with little to no Chinese population

I'm replying to someone who says the EU is too diverse for it to be worth spammers' effort. If it's worth their time to spam people with northern California area codes in Chinese that makes no sense. Calling people in Germany in German, for example, would be much more reliable.

Re: Americans duped into losing $10B by illegal Indian call centres in 2022: report

#498

Earlier quoted context omitted.

> There's no reason consumer SIMs should be able to call more than N distinct numbers in any 24h period. Oh jesus please no, whats next? Ther is no reason a consumer oven should cook more than 5 meals a day. There is no reason a consumer toasteer should toast mpre than 10 times a day. The bread you make tourself is unauthorised in a toaster

The difference between this and cooking/toasting bread is that your bread-making activities have no way to negatively affect someone else - we don't have an epidemic of spammers paying people to bake "underground bread" in their homes. Of course, an override should be provided - the restriction should be relaxed over time once the account is established for a long time without any complaints.

What you are describing is already done by carriers in countries with high sim box usage. (Basically, it costs ~$0.01/min to make a local call in Nigeria but $0.25/min to make an international call to Nigeria so people there set up SIM boxes and Asterisk to terminate calls locally and profit the difference between these rates. The reason it costs $0.25/min to call the official way is due to many governments taxing incoming international calls because they see it as an easy way to raise revenue at other people's expense). But anyways, because governments don't like this kind of arbitrage, they force carriers to add detection mechanisms. So they check for high ratio of outbound to incoming calls, high amount of distinct phone numbers called, 24/7 usage patterns, etc. Except Africa is still losing a few billion dollars a year to this kind of toll bypass because it is still massively profitable (see https://en.antrax.mobi/request-pricing/ for example) and these changes just require them to rotate sim cards slightly more often. Essentially what I am saying is that unless you can reduce the fraudsters' margin by a substantial amount you are wasting your time.

Re: Americans duped into losing $10B by illegal Indian call centres in 2022: report

#499
post #304

A lot of comments here suggest the Indian government is complacent in these types of operations, but I don't really believe that's the case. The Indian central government is a pretty small and unpowerful entity. Beyond securing the countries borders, and keeping the currency spinning, the government doesn't have the ability or power to do much more. They are not especially well funded (taxes are seen as especially un…

The Indian government is complacent because they allow such extreme poverty to exist where people need to seek out scams like this in order to survive. Extreme inequities rationalized by an abusive caste system, mixed with a culture that praises creative work avoidance.

[dead]

Re: Americans duped into losing $10B by illegal Indian call centres in 2022: report

#500
post #490
post #372

Earlier quoted context omitted.

> I'm sad to say it, but it's more dangerous than ever to be old or naive It will get orders of magnitude worse once all this can be fully automated by AI (including a completely realistic video or voice call by the grandson where he talks about killing the pregnant woman).

We may be able to get good AIs to fight the bad AIs? I guess in this case something that pops up saying maybe call the grandson back?

It seems much easier to build an AI that helps less bright people to scam others than one that helps them to not get scammed.

One needs to provide clear instructions for a single good scam when explicitly asked to do so, the other would need to provide good defenses to any number of scams and be more or less self-activated.

There's also the matter of risks entailed by having large swathes of the population increasingly under the direct supervision of artificial minds (controlled by who?).

I suspect something like this will happen though, and that one of the key uses of artificial intelligence will be as both an offensive and a defensive weapon for deceit and manipulation. Indeed the offensive part would seem to be a natural continuation of the enormous resources poured into ml-driven engagement maximization and the quest for sufficiently politically correct AIs. As an example ChatGTP is evidently explicitly designed to lie about some things, including its own capabilities. I'm not sure what, if anything, currently exists on the defensive front.

Post reply on HN