Live data from Hacker News

Gone (Almost) Phishin'

ma.tt

51–60 of 93 posts

Re: Gone (Almost) Phishin'

#51
post #31

> Apple Support lives on apple.com and getsupport.apple.com, nowhere else. Meanwhile: “Microsoft support uses the following domains to send emails: microsoft.com microsoftsupport.com mail.support.microsoft.com office365support.com techsupport.microsoft.com” [1] [1] https://learn.microsoft.com/en-us/troubleshoot/azure/general...

Also, Microsoft regularly sends me legitimate emails regarding "Microsoft Rewards" that are absolutely indistinguishable from phishing, like "Total Prize Drop is here! Your chance to win 1,000,000 USD cash grand prize or one of three customizable Mercedes-Benz cars!", complete with links to login pages and everything. So like this one, just as mail: https://xcancel.com/bing/status/2034720189003231410 The first time I…

My Mexican telcom (Telcel) does this over SMS.

"Sign up for Uber Eats and win 50,000 MXN of credit https://bit.ly/1234"

What's funny is that they also send these over the same channel:

"Warning: Telcel will never call you nor ask you for your personal info!"

Gee, maybe stop priming your whole customer base to click on messages identical to spam?

Re: Gone (Almost) Phishin'

#52
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

> senior citizens and tried to explain how to parse the domain

Why would you want end users, senior citizens or not, to mentally parse URLs?

The rule is: If the bank, or paypal, or your landlord, or anyone else really emails you that you have to complete some information to your account or pay the latest bill or whatever, you GO TO THEIR WEBSITE and login normally. If it is important they will have the same information there.

The same rule also applied to unsolicited phonecalls, but it might be harder to follow: If your bank, or the police, or some other important person calls you and asks for information or for you to do something that feels the least bit off or hurried, you take their contact information, you look up whatever it is they want you to do and you CALL THEM BACK at the official telephone number of the bank or the police. You probably already have the number and if you don't it's on their web site. Do not call back on any other number.

People working the phone generally have much worse protocols than people working over email, so they may be less prepared for you to do this, but I have never heard of anything important that was emailed that wasn't also easily available when logged in to the website.

The only time it is appropriate to click a link in an email is when you are verifying your email address with them. Not for any other reason.

Re: Gone (Almost) Phishin'

#53
Having identifiers where anyone can initiate conversation is the problem. Modern messengers like Signal or SimpleX allow you to share one-time contact info, completely preventing anyone you don't allow to contact you.

Besides that, people should sign up with random email aliases just as much as they sign up with random passwords.

Here is a free crossplatform workflow: New, free Proton Mail[1]-->Free Bitwarden[2] account with single master password memorized[3]-->duck.com[4] alias pointing at Proton Mail-->Extract[5] duck.com api key to generate random duck.com alias for each site in Bitwarden-->Sign up for new service using new random email+password in seconds and never have to remember it and no spam.

Here is a simple crossplatform workflow: Paid proton suite[6]-->Single memorized master password[3]-->Generate random email alias and password for new services using proton pass.

If you use iCloud+ you can generate email aliases using a Raycast[7] extension or a browser extension[8] or inside of safari natively. There is also iCloud+ settings, but that is a pain to get to.

[1] https://proton.me/mail

[2] https://bitwarden.com/go/start-free

[3] https://strongphrase.net

[4] https://duckduckgo.com/email

[5] https://bitwarden.com/blog/how-to-use-the-bitwarden-forwarde...

[6] https://proton.me/mail/pricing

[7] https://www.raycast.com/svenhofman/hidemyemail

[8] https://chromewebstore.google.com/detail/icloud-hide-my-emai...

Re: Gone (Almost) Phishin'

#54
post #52
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

> senior citizens and tried to explain how to parse the domain Why would you want end users, senior citizens or not, to mentally parse URLs? The rule is: If the bank, or paypal, or your landlord, or anyone else really emails you that you have to complete some information to your account or pay the latest bill or whatever, you GO TO THEIR WEBSITE and login normally. If it is important they will have the same informati…

>The rule is: If the bank, or paypal, or your landlord, or anyone else really emails you that you have to complete some information to your account or pay the latest bill or whatever, you GO TO THEIR WEBSITE and login normally.

Yes, that is a "best practice" and good internet hygiene is to never click on email and text message urls but the reason they like clicking on legitimate email urls is convenience and usability. A helpful email link directly lands them on the relevant website page to do whatever they need to do. That's because the email url has a long string query parameters (id, etc) that automatically navigates to the correct webpage.

On the other hand, to do it the "best practice" way, it requires clicking around a confusing website menus and drilling several layers deep to find whatever issue the email is talking about.

A helpful email url link bypasses the hassle of learning whatever flavor-of-the-month confusing UI the website designer happened to to use.

Hang around old people and watch over the shoulder how they use computers and you become sympathetic to how the make it work for them.

E.g. An order status email has a URL link of a UPS tracking number to monitor shipping status. But don't click on that! Instead, copy the 1Z... number to the buffer. Then open a web browser and type in the ups.com url. Then paste the number into the text box. Those copy&paste mechanics not too difficult on desktop (Ctrl+C Ctrl-V) but it is much more difficult on mobile phones (double taps or long press and hold).

That was a simple example. The more complicated one is email from health and medical companies with confusing websites. They'd rather just click on the email url.

Re: Gone (Almost) Phishin'

#55

What's the end goal here? I know that after a phone has been stolen, attackers want to gain access to an Apple account to remove the activation lock. But in this case, no devices had been stolen yet. The most they could do would be to… remotely mark the devices as stolen? Then ask the victim to pay to unlock them?

Get into the account, change the phone number, and start charging the cards on file. Or look through iCloud data for passwords/contacts

Re: Gone (Almost) Phishin'

#56
post #41

Earlier quoted context omitted.

Until this moment I assumed .ms was a Microsoft TLD, but indeed it is not https://en.wikipedia.org/wiki/.ms

Handy tip: all two-letter TLDs are country code TLDs. Doesn't matter if they're trendy in website names (.nu, .cc, .io, .co, .it, .at, .cx, youtu.be and so on) In fact, here we have the ma.tt website, where the ".tt" is Trinidad and Tobago. Is Matt Mullenweg from Trinidad? No!

Though not all country codes point to a country. See .eu, .ac .su as different examples of stuff that breaks the rules.

Re: Gone (Almost) Phishin'

#57
Whenever I get some breathless email about security from my organization I send a phishing report for it even if I think it is real. All the messages about mandatory password resets and the like just increase the surface area for phishing. There should be a policy like "we will never send you an email about the security of your account" See

https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/201...

a policy that's been talked about for more than 10 years and that the industry is almost catching up to.

Re: Gone (Almost) Phishin'

#58
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

Bluesky's moderation email is moderation@blueskyweb.xyz which 100% looks like a phishing address.

https://bsky.app/profile/safety.bsky.app/post/3ljp6zi7tp227

Re: Gone (Almost) Phishin'

#59
post #14

Earlier quoted context omitted.

My dad googled “amex phone number” and called the first result. I spent most of a Saturday cleaning up after the scammers. I told him, next time call the number on the back of your card.

Any chance the first result was an ad? Those are definitely a popular phishing distribution mechanism, so getting your parents an adblocker could help

I just got a family member to install one after they Google'd a hotel name and accidentally clicked the first ad instead of the hotel site.

Re: Gone (Almost) Phishin'

#60
I've had some close calls already and with AI making it cheap to tailor scams to individuals it's probably only a matter of time.

For my parents in their 70s, even more so. No amount of reminding them to read URLs first is going to help.

So my question is: what are best practices to limit the blast radius when I (or they) inevitably click the wrong link?

Post reply on HN