Earlier quoted context omitted.
What happens if you say "yes"?
They have you acknowledging something at that point. Doesn't really matter what it is when they can take it out of context. Edit: Many of them are scammers, they don't play by the rules.
Scammed out of $130K via fake Google call, spoofed Google email and auth sync
591–600 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#592Earlier quoted context omitted.
The attacker doesn’t need to spoof anything, this is known as a homograph attack: https://en.m.wikipedia.org/wiki/IDN_homograph_attack https://www.xudongz.com/blog/2017/idn-phishing/
If it's a known attack, Google has a known defence in its apps?
Computing the the set of Unicode characters that would result in a homograph of a latin alphabet word is non trivial. Now do this for relevant/trusted domains, now put in place a mechanism to mark a domain as trustworthy that also minimises your liability.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#593Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#594A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#595Earlier quoted context omitted.
I find that when it’s legit a consistent thing happens, which smells of careful training: they instruct me to call the number on the back of the card, or on a bill.
Obvious next step to me is malicious bills sent to an address
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#596Earlier quoted context omitted.
If it's a known attack, Google has a known defence in its apps?
Something being known doesn’t mean a solution exist. Computing the the set of Unicode characters that would result in a homograph of a latin alphabet word is non trivial. Now do this for relevant/trusted domains, now put in place a mechanism to mark a domain as trustworthy that also minimises your liability.
But we aren't talking theory. In this case solutions exist, just not in this app?
Also, the triviality point is puzzling, are we only allowed to criticize professionals for trivial fails? (though using a different font is one of the trivial mitigations)
> that also minimises your liability.
How is that a factor, what is their liability now without any mechanism and will it increase if they add some?
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#597Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#598Earlier quoted context omitted.
I don’t trust anyone calling me who isn’t already in my contacts. Callers from legitimate businesses treat me like i’m questioning the moon landing when I tell them I’ll need to call them at an official number. Now try and convince your family to do the same (especially parents who are prime targets).
I've not once had a legitimate company not say "good for you in taking the extra security precaution of calling us back".
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#599A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#600Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…
> official phone number Great idea unless the attacker has SS7 access.