Live data from Hacker News

The short tale of an online scam

duarteocarmo.com

51–60 of 98 posts

Re: The short tale of an online scam

#51
post #40

Earlier quoted context omitted.

There has also been a push by Google and others lately to "dumb down" the url bar to hide the full address from users. Not sure why but I assume the justification would be some misguided attempt at making it look nicer while the real reason is somehow ad related.

It isn't just Google. Multiple browsers have flirted with hiding it. There are various mindsets that lead to want to do that - one designer I know calls it a debugging tool that should never have been released in the first place. For others, it is clearly about controlling the user with various justifications. (I consider it a canary. Its removal will be a signal that the HugeCos are comfortable relegating the non-co…

This and the proliferation of gold-rush TLDs like the .icu mentioned in the article make me feel like we're pretty well all the way there. For all my fighting the good fight, I'm just one more voice in the wilderness, though, and everyone wants their magic boxes without caring what's going on inside them - until they get bitten.

Re: The short tale of an online scam

#52

Since most card transactions these days require strong authentication and this is done in Denmark via NemId, which requires second factor (either an app or a key card sent to individual's officially registered address), I wonder what their game plan is. They could use up all your codes and steal the key card from your mailbox, but otherwise I'm not sure... Maybe they wanted victims to pay for 'shipping' the item, but…

The phishing scenario in the article allows the malicious actor to impersonate the victim simultaneously, while asking the victim for any 2FA codes.

The attacker can be a man-in-the-middle and make the victim authorize a costly transaction (say $100), with the victim seeing a cost of $1.

These is an example video here: https://blog.cmpxchg8b.com/2020/07/you-dont-need-sms-2fa.htm...

Of course, the real transaction can be seen from the bank.

Re: The short tale of an online scam

#53

It's a fun story. For myself, I tend to avoid pissing off scammers. I just let the relationship wither on the vine. I had a friend that attacked a forum hacker, and the hacker responded by completely destroying a years-old online community. They probably used a bot to register a scammer login, but the attack got their attention. My friend would have been far better served by deleting the login, and fixing the holes i…

This morning at 5:30AM I got a call from a random HVAC service company. "Hi, [function_seven], this is Paul with ACME Heating and Cooling. You're requesting someone look at your system?"

I was barely awake, so I stammered, "huh? No I don't think so..."

Paul (Helpfully): "You filled a form out requesting this on our site?"

"No...?".

Then I started to wake up more and realize it was happening again. I must've pissed someone off somewhere a couple years ago, because I'm getting a lot of this. A hater is filling out online forms with my info. Every month I get a random call from a legitimate company responding to what I only assume is an item in their lead-gen pipeline. This morning was no different. The call came from a legit number for the HVAC company. I looked them up and they're highly-rated. But they're in Florida, I'm in California, so the 5:30am call time made sense.

Last month it was a therapist referral service in Ohio. They had my name, phone number, and email.

Elsewhere I'm constantly getting emails at an old gmail address for various shopping site "newsletters." From all over the world. A Spanish job search site in the UK. A sporting goods site in Colombia. Athletic wear from Ireland. In each case, the sites themselves are legit, but they don't do an email confirmation loop.

Should I keep Unsubscribing from these? Is there anything I can do to figure out who is doing this? I used to mess with scammers; I think I might regret that :)

Re: The short tale of an online scam

#54
post #40

Earlier quoted context omitted.

There has also been a push by Google and others lately to "dumb down" the url bar to hide the full address from users. Not sure why but I assume the justification would be some misguided attempt at making it look nicer while the real reason is somehow ad related.

It isn't just Google. Multiple browsers have flirted with hiding it. There are various mindsets that lead to want to do that - one designer I know calls it a debugging tool that should never have been released in the first place. For others, it is clearly about controlling the user with various justifications. (I consider it a canary. Its removal will be a signal that the HugeCos are comfortable relegating the non-co…

> one designer I know calls it a debugging tool that should never have been released in the first place

I've heard similar comments but I don't understand how people would be expected to navigate around the internet? Is the idea that Google's search input should replace it? So if I want to go to sec.gov I should search SEC and click the link (hopefully) provided at the top of the results rather than just go there directly? It just doesn't make sense to me.

Re: The short tale of an online scam

#55
> In an attempt to add some confusion to his operation, I decided to create a little script. This little script would send him about 5000 different combinations of the above parameters in a completely random fashion. Fun.

I've done this with college scammers requesting email + passwords, loads of fun. Would highly recommend as it turns an O(1) operation (db full of valid stolen credentials) back into O(n) (randomly guess which credentials you stole are valid).

Re: The short tale of an online scam

#56
post #8

Earlier quoted context omitted.

>Scammers really have stepped up their game Here's an innovative one. I got an sms impersonating my cell phone provider telling me they're going to change my plan. They'd decided which one is the best for me but I have until next month to chose one 'of the new plans' clicking on a bit.ly link. That links points to an Amazon affiliated link, and it's totally unrelated to my provider.

That is pretty decent for an affiliate scam.

Yeah imagine what a wonderful world we'd have if all that scammer creativity were put to work for a good cause.

Re: The short tale of an online scam

#57

It's a fun story. For myself, I tend to avoid pissing off scammers. I just let the relationship wither on the vine. I had a friend that attacked a forum hacker, and the hacker responded by completely destroying a years-old online community. They probably used a bot to register a scammer login, but the attack got their attention. My friend would have been far better served by deleting the login, and fixing the holes i…

This morning at 5:30AM I got a call from a random HVAC service company. "Hi, [function_seven], this is Paul with ACME Heating and Cooling. You're requesting someone look at your system?" I was barely awake, so I stammered, "huh? No I don't think so..." Paul (Helpfully): "You filled a form out requesting this on our site?" "No...?". Then I started to wake up more and realize it was happening again . I must've pissed s…

You will not be able to know who did this. It is similar to the dumb teen idea of a prank where they would put your phone number in an ad for a cheap pizza delivery service.

My wife had a similar problem and she changed her phone number.

Re: The short tale of an online scam

#58

>This little script would send him about 5000 different combinations of the above parameters in a completely random fashion. More work, but with potential to waste more of the scammer’s time, would be to fake up requests corrupted in a way that suggests your browser config exposes some subtle bug, say a race condition, in his scripts. Might keep him busy for days …

cardNumber=[object Object]

delightfully devilish!

Re: The short tale of an online scam

#59
post #49

Earlier quoted context omitted.

>They allow anonymous payments and they're slow to respond to takedown requests. things that might also be liked by non-scammers.

Non-scammers is a pretty broad set of people, most of whom are not interested in that. Who specifically do you have in mind?

people who set up websites that they don't want tracked back to them - historically speaking gay people might want to be anonymous in all sorts of scenarios and for all sorts of reasons.

I'm working helping out an artistic collective in which the various members are anonymous to various degrees. There may need to be anonymity in paying for services - this is an obvious necessity nowadays - for example the whole recent situation over the 'I sexually identify as an attack Helicopter' story https://en.wikipedia.org/wiki/I_Sexually_Identify_as_an_Atta...

so - off the top of my head:

often abused or oppressed minorities.

artists.

on edit: obv. slow to takedown is important for artists or controversial people as well.

Post reply on HN