Live data from Hacker News

The clever reason scammers can’t spell (2019)

itservices.wp.st-andrews.ac.uk

51–60 of 117 posts

Re: The clever reason scammers can’t spell (2019)

#51
This is bollocks. Speaking for Britain, and I think I can, there are hoards of would be victims to this kind of scam, particular of the current retirees generation, who are extremely vulnerable to having the wool pulled over their eyes about technical and internet security best practice matters, but for whom just so much as a poor turn of phrase or some unusually laid out punctuation is an absolute dead giveaway. If the scammers got their act together on this front they'd be mopping up huge swathes of these people, but they don't, because at the end of the day they don't speak English very well and don't have access to anyone who can.

Re: The clever reason scammers can’t spell (2019)

#53
post #3

I was wondering that recently. But I don't know -- I feel like they'd catch even the discerning people if they did a better job of it. Why don't they exactly replicate what a Google or Chase email looks like? I don't see how I wouldn't fall for that.

I get phone calls sometimes that are almost certainly legitimate, such as from my insurance company, and if they ask me to give them any information (like my address for "security purposes") I always refuse and tell them I can call back. The same is true with email. You should never be giving any information away, even if it appears to be a completely legit communication from your bank or whatever.

The exception (and a potential attack vector) is when a phone call or other live interaction ends in an email being sent as part of the process. There you have to weigh the risk I suppose; obviously i have replied to such emails. But i would never reply to a bulk email even if it came form my banks domain.

Re: The clever reason scammers can’t spell (2019)

#54
post #6

The article misses one of the most common misspelling reason: getting thru Bayesian filters. It has more to do with tech and less with psychology.

This is true but also... In my experience[1] a large majority of facebook-level romance scammers use the same copypasta messages when possible, because they actually are from (e.g.)Nigeria and really do have poor English. This is especially relevant to your point because facebook could EASILY be flagging people based on known pasta messages, for review or shadowbanning etc. They presumably don't do this because "not…

>> because they actually are from (e.g.)Nigeria and really do have poor English.

This isn't true. English is Nigeria's official language (all Education is in English) and people generally speak English well. Secondly, folks from Nigeria actually use the gist of the article as a flag for filtering out scam i.e. once they open an email with bad grammar, they automatically assume it's scam and ignore it.

Re: The clever reason scammers can’t spell (2019)

#55

Close to 20 years ago I got an email that in it's entirety said "I have a powful tool. I suspect youd like it", exactly as written. No links, no attachments, just plain text. I showed it to my then girlfriend and now wife and since then we have adopted "powful tool" as a term we apply to really great devices or machinery of impressive heritage or even some good software. Warms my heart.

I’ve also gotten mysterious scam emails that contain no information. What’s their purpose?

It's called "IP warming". When you send bulk emails, there are throttling limits and other things meant to decrease the ability of scammers. So to warm the IP up you have to send on it for awhile. These sorts of blank emails aren't the best way to do it, it's sloppy. But that's the goal.

Re: The clever reason scammers can’t spell (2019)

#56
post #51

This is bollocks. Speaking for Britain, and I think I can, there are hoards of would be victims to this kind of scam, particular of the current retirees generation, who are extremely vulnerable to having the wool pulled over their eyes about technical and internet security best practice matters, but for whom just so much as a poor turn of phrase or some unusually laid out punctuation is an absolute dead giveaway. If…

100%. This article is a popular “Reddit” theory I’ve seen float around for a while now and it’s just not true!

I’ve worked IT help desk before and have seen lots of phishing emails. If scammers tightened up their spelling and grammar skills a tiny bit they would catch many more victims effortlessly. The bar is insanely low. Most users could spot obvious phishing emails. But emails with even just a little more effort put into spelling and grammar were insanely successful. I worked at a University - I’ve seen professors, students, admin fall for these ones.

Why can’t they spell? Because most scammers are operating from the developing word and don’t have great English. That’s it. There’s no elaborate theories beyond that.

Re: The clever reason scammers can’t spell (2019)

#57
post #48

There's actually a building in Lagos where the Nigerian Prince scammers all work. Hugh Sinclair has seen it: https://www.youtube.com/watch?v=rhdZ2RfmiXo&list=PL4ugKP-T4L... I would think they do know exactly what they're doing. There's no reason to think it's just to get past email filters or just to skip the smart people. It's probably both, plus other reasons we haven't even thought of.

> skip the smart people I am not sure smart people are scammed less often than the average person. Perhaps smart people get sucked in by different scams (like buying altcoins, or complex speculation)?

[deleted]

Re: The clever reason scammers can’t spell (2019)

#58
post #51

This is bollocks. Speaking for Britain, and I think I can, there are hoards of would be victims to this kind of scam, particular of the current retirees generation, who are extremely vulnerable to having the wool pulled over their eyes about technical and internet security best practice matters, but for whom just so much as a poor turn of phrase or some unusually laid out punctuation is an absolute dead giveaway. If…

I think you're right in general, but I've seen some cases where it couldn't possibly be language barrier.

For instance I once saw one of those sex scam accounts on Facebook where the profile pic was some hot, obviously white woman, but the name was Vietnamese and all the posts were in the Thai alphabet. That to me seemed very deliberately designed to catch men who saw the big boobs and immediately switched off their brains. And obviously no one is incompetent enough to use the wrong alphabet by mistake.

Re: The clever reason scammers can’t spell (2019)

#59
post #56
post #51

This is bollocks. Speaking for Britain, and I think I can, there are hoards of would be victims to this kind of scam, particular of the current retirees generation, who are extremely vulnerable to having the wool pulled over their eyes about technical and internet security best practice matters, but for whom just so much as a poor turn of phrase or some unusually laid out punctuation is an absolute dead giveaway. If…

100%. This article is a popular “Reddit” theory I’ve seen float around for a while now and it’s just not true! I’ve worked IT help desk before and have seen lots of phishing emails. If scammers tightened up their spelling and grammar skills a tiny bit they would catch many more victims effortlessly. The bar is insanely low. Most users could spot obvious phishing emails. But emails with even just a little more effort…

I think all of the obvious scam emails are part of what makes the higher effort scams so much more effective. People (myself included) are used to being easily able to spot the scams so aren't naturally wary when seeing emails that don't have those obvious indicators.

Re: The clever reason scammers can’t spell (2019)

#60
I don't see the value in articles like these that don't even attempt to convince you what they are saying is true. Sure, I've heard this claim 1,000,000 times on sites such as Hacker News and Reddit - but I've yet to find any reason to believe it.

In the spam e-mail I get, the misspellings are clearly there to get around spam filters. In fact, the e-mails I get look quite convincing, and just have two or three strategic misspellings. A lot of the text will be in the form of an image, and will be spelled and formatted perfectly. But instead of saying "garbagetime" it will say "garbagetim". And instead of saying "18+" it will say "19+".

Looking at one spam e-mail I received recently, I see it even has an "unsubscribe" button, which leads to a vaguely convincing but - after some investigation - certainly non-functional unsubscribe page. That's a lot of effort to go to if you're trying to filter out vaguely clever people.

Maybe there really is a whole other genre of spam e-mail that simple doesn't get sent to me, or is caught by my spam filter. But this article gives me no reason to suspect this to be the case. And for various reasons it seems unlikely.

Post reply on HN