Live data from Hacker News

The clever reason scammers can’t spell (2019)

itservices.wp.st-andrews.ac.uk

61–70 of 117 posts

Re: The clever reason scammers can’t spell (2019)

#61
post #56
post #51

This is bollocks. Speaking for Britain, and I think I can, there are hoards of would be victims to this kind of scam, particular of the current retirees generation, who are extremely vulnerable to having the wool pulled over their eyes about technical and internet security best practice matters, but for whom just so much as a poor turn of phrase or some unusually laid out punctuation is an absolute dead giveaway. If…

100%. This article is a popular “Reddit” theory I’ve seen float around for a while now and it’s just not true! I’ve worked IT help desk before and have seen lots of phishing emails. If scammers tightened up their spelling and grammar skills a tiny bit they would catch many more victims effortlessly. The bar is insanely low. Most users could spot obvious phishing emails. But emails with even just a little more effort…

I am another data point that would agree with you on this. I would classify myself as a sophisticated computer user (if I don't say so myself), and I fell for a phishing page once. They recreated a pixel-perfect copy of the Steam login page in a fake browser window with a pretend address bar etc. I entered not only my creds, but also my 2FA code, before realising that it was not legit.

Got an email shortly afterwards about a login from Russia, however I was able to change my password and kick out all other sessions before any damage was done.

The worst part was that I was doing a favour to a Steam "friend" who asked me to vote for his clan in some kind of competition. I will give him the benefit of the doubt and assume it wasn't really him, but someone who had hacked his account, but either way, Steam support were utterly disinterested in doing anything about it when I reported it. As were Cloudflare. I checked on the site a few days later and the safe browsing list had flagged it, so at least those maintainers still seem to give a shit.

Re: The clever reason scammers can’t spell (2019)

#62
Let me guess two reasons:

1. to avoid keyword detection (reason I write to myself garbled sensitive notes online, so potential hacker with online translator won't be able to read them since it's highly unlikely he will be my maybe language speaker)

2. to filter out smart people avoid wasting time with them

edit: article says it's number 2

Re: The clever reason scammers can’t spell (2019)

#63
post #48

There's actually a building in Lagos where the Nigerian Prince scammers all work. Hugh Sinclair has seen it: https://www.youtube.com/watch?v=rhdZ2RfmiXo&list=PL4ugKP-T4L... I would think they do know exactly what they're doing. There's no reason to think it's just to get past email filters or just to skip the smart people. It's probably both, plus other reasons we haven't even thought of.

> skip the smart people I am not sure smart people are scammed less often than the average person. Perhaps smart people get sucked in by different scams (like buying altcoins, or complex speculation)?

The John Podesta - Hillary phishing leak is out there on Wikileaks. This doesn't fit into any category I've seen:

0) Podesta got a letter-perfect message from "Google" asking him to change his password.

1) Podesta asked his IT guy if it was legit.

2) The IT guy said, "Yes, it is, but please set up 2FA."

3) Podesta clicked on it, ignoring the 2FA part (I think he ignored it).

Re: The clever reason scammers can’t spell (2019)

#64
post #51

This is bollocks. Speaking for Britain, and I think I can, there are hoards of would be victims to this kind of scam, particular of the current retirees generation, who are extremely vulnerable to having the wool pulled over their eyes about technical and internet security best practice matters, but for whom just so much as a poor turn of phrase or some unusually laid out punctuation is an absolute dead giveaway. If…

>because at the end of the day they don't speak English very well and don't have access to anyone who can.

You believe they don't have access to fiverr or any of the numerous sites that will copy edit for a couple dollars of the thousands bucks they are scamming?

Re: The clever reason scammers can’t spell (2019)

#65
post #51

This is bollocks. Speaking for Britain, and I think I can, there are hoards of would be victims to this kind of scam, particular of the current retirees generation, who are extremely vulnerable to having the wool pulled over their eyes about technical and internet security best practice matters, but for whom just so much as a poor turn of phrase or some unusually laid out punctuation is an absolute dead giveaway. If…

Yeah, this sounds a lot like a just-so story. There is never any actual evidence given, and the story plays towards people’s desire to feel smarter than other people who would fall for a scam.

https://en.wikipedia.org/wiki/Just-so_story

Re: The clever reason scammers can’t spell (2019)

#66

Earlier quoted context omitted.

Is this why when I'm on Etsy, some obscure, niche item that I'm looking at will always say "13 people have this in their carts right now"? Etsy doesn't seem like the type to me, or maybe that code is just flawed

I’ve been suspicious of Etsy for years for this very reason. Either Etsy is scamming or the sellers are playing games.

You can test it yourself:

Become an Etsy seller and sell something what wouldn't be even show up in search

Observe if "N people have this in their carts right now" shows up

...

PROFIT

Re: The clever reason scammers can’t spell (2019)

#67
post #56

Earlier quoted context omitted.

100%. This article is a popular “Reddit” theory I’ve seen float around for a while now and it’s just not true! I’ve worked IT help desk before and have seen lots of phishing emails. If scammers tightened up their spelling and grammar skills a tiny bit they would catch many more victims effortlessly. The bar is insanely low. Most users could spot obvious phishing emails. But emails with even just a little more effort…

I am another data point that would agree with you on this. I would classify myself as a sophisticated computer user (if I don't say so myself), and I fell for a phishing page once. They recreated a pixel-perfect copy of the Steam login page in a fake browser window with a pretend address bar etc. I entered not only my creds, but also my 2FA code, before realising that it was not legit. Got an email shortly afterwards…

Yeah, actual credential phishing attacks can be sophisticated and well put together. The ones where they will make mistakes on purpose to weed people out are the ones where they are REALLY looking for a target to squeeze. They will keep some of these people on for extended periods of time and get loads of money from them.

I have a friend that got a message from a "girl" over the summer. It was like "Hello Dear Joseph, I would like to no if you can help me with to practice English. I find you profile today and I have a work visas starting in 90 days to come to your city for work and I am wanting to make new friends and practice my english!! Sorry if this bothered to you. ~~EMOJIS~~~ - Signed Brazilian Model.

So far I think he's 8 grand into helping her. I'm sure it's more now because that was like before Halloween and it's impossible to convince him that it's a scam.

Re: The clever reason scammers can’t spell (2019)

#68
post #4

this idea has been kicking around for a long time, and sounds nice, but is there any data to support it? A lot of the most visible misspelling seems designed to avoid spam filter detection.

This idea was made popular by the Microsoft paper that was linked in the article. https://www.microsoft.com/en-us/research/wp-content/uploads/...

However the paper itself doesn't present any evidence around the scammer's intention. Rather it presents a mathematical model under which it would make sense for a scammer to intentionally exclude a large swathe of victims, and it posited that misspellings is a way to achieve it.

Re: The clever reason scammers can’t spell (2019)

#69
post #6

The article misses one of the most common misspelling reason: getting thru Bayesian filters. It has more to do with tech and less with psychology.

This is true but also... In my experience[1] a large majority of facebook-level romance scammers use the same copypasta messages when possible, because they actually are from (e.g.)Nigeria and really do have poor English. This is especially relevant to your point because facebook could EASILY be flagging people based on known pasta messages, for review or shadowbanning etc. They presumably don't do this because "not…

source: ^ his brother is a Nigerian prince!

Re: The clever reason scammers can’t spell (2019)

#70
post #16
post #14

Earlier quoted context omitted.

Think of it this way: Savvy users who will become wise to the grift somewhere along the way are the ones they want to weed out. Early in the process ideally. Having totally convincing emails fails to weed out these savvy users - you get to discover who they are a bit further down the line, after you've invested some time. Since their time they can spend is finite, they want to only spend time on sure bets. This is wh…

You've just restated exactly what the article says, but yeah.

Yes, but there is a thing what many comments here misses: those email do work, so not only they filter out not-dumb people, they are running on a successful strategy.

Using a proper spelling would improve the conversion but also would add a lot more work for the scammer and therefore he can miss a real doofus who can be scammed, so the overall KPI (heh) would be lower.

Yes, it still the same, but with an additional key part.

Post reply on HN