Live data from Hacker News

USPS jumps to first place as most imitated brand in phishing attacks

guard.io

61–70 of 74 posts

Re: USPS jumps to first place as most imitated brand in phishing attacks

#61
post #58

Earlier quoted context omitted.

because you don't shoot the messenger... I don't think it should be the task of the mail delivery service to decide what you should receive

Sadly USPS is frequently the perpetrator. https://www.usps.com/business/every-door-direct-mail.htm I’ve tried every opt-out I can find and it still doesn’t stop.

It's been 20 years now, but I tried opting out of a prolific grocery coupon mass mailer. But the carrier was so used to everyone getting them that I just got the ones addressed to my neighbor.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#62
post #29

Earlier quoted context omitted.

Why not both? USPS is most prolific and polluting spam purveyor in the world.

Yeah one of the biggest (if not the biggest) sources of paper that I throw away is junk mail. I throw away bags of it every month, 98% of it unopened. The environmental impact of the paper, the printing, the fuel burned to deliver it, must dwarf the impact of the single-use plastic bags I get at the supermarket.

They get to send each house 30 lbs of crap per year at tremendous discount, but if you want to send a Christmas card to Grandma, you have to pay full price.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#63
post #30

Earlier quoted context omitted.

That's incredibly expensive. Bulk mail can't be returned for free.

> Bulk mail can't be returned for free True. It’s surprisingly effective, though. Another route is to fish around for their return envelope and send them a pretty leaf or whatnot, but that could just spur them into paying more attention to you.

I used to gather up the credit card application forms for Brand A and mail them to Brand B in their prepaid envelope. I did so many times that Citi finally send me an intimidating letter from their fraud department asking me to stop. I didn't, of course, but they eventually phased out the prepaid envelopes altogether.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#64
post #57

Earlier quoted context omitted.

> I write "return to sender" on the envelope and drop it into a post box. It doesn't cost anything This technically only works for first-class mail. Bulk mail doesn’t have return services.

Yep, as a last resort I tried doing this with an apparently unstoppable catalog and got about a month before the postal worker scrawled a nastygram back on one threatening delivery embargo.

> threatening delivery embargo

...win-win?

Re: USPS jumps to first place as most imitated brand in phishing attacks

#65

Earlier quoted context omitted.

> Bulk mail can't be returned for free True. It’s surprisingly effective, though. Another route is to fish around for their return envelope and send them a pretty leaf or whatnot, but that could just spur them into paying more attention to you.

I used to gather up the credit card application forms for Brand A and mail them to Brand B in their prepaid envelope. I did so many times that Citi finally send me an intimidating letter from their fraud department asking me to stop. I didn't, of course, but they eventually phased out the prepaid envelopes altogether.

Oh, I'm doing that. I previously confined myself to leaves, cat treats and bar-napkin drawings.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#66
post #25

Earlier quoted context omitted.

It's because US cell phone networks refuse to implement basic authentication, and because USA population has the most excess money to steal.

> It's because US cell phone networks refuse to implement basic authentication, Like other countries. > and because USA population has the most excess money to steal. No, it doesn't. Many other countries have a lot more wealth in their general population. There are many people in the US with higher salaries than other places however don't think they have the most excess money to steal. I think everyone is missing a m…

US is 15th in median wealth and it's population exceeds the 14 countries ahead combined. That's a big target.

https://en.wikipedia.org/wiki/List_of_countries_by_wealth_pe...

Your question seems like a false dichotomy.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#67
post #59
post #35

Earlier quoted context omitted.

> Advocate for apps and hardware keys all you want, don't dump on an extemely valuable technology, please. The worst possible situation would be for someone to "take your advice" and refuse to use any 2FA at all. It was your interpretation that I advise people to not use any 2FA at all. I won't honor the request to not dump on SMS, as I am perfectly happy to dump on an "extremely valuable technology" on technical dem…

> It was your interpretation that I advise people to not use any 2FA at all. No, to be clear, it's the obvious interpretation of a non-expert user, which is why your advice is so dangerous. They don't have a yubikey, don't understand how the apps work, and are faced with a decision to either enable SMS 2FA or not. And you're telling them not to, so they won't . And we'll all suffer. Again, work the other side of the…

> They don't have a yubikey, don't understand how the apps work...

But they almost certainly do have a phone, any vaguely modern phone is also a valid hardware credential - and given how much time people spend using a phone it might even be more practical for them.

I would argue that the problem is we've made the inconvenience symbolic - people see me sign in at work (with a Yubico Security Key 2 typically) and assume that's some sort of get out or workaround rather than, in reality, the much more secure option that my employer was too cheap to provide. They intuit that the thing they're doing is annoying and takes more effort so logically it must be more secure not less, right ?

Re: USPS jumps to first place as most imitated brand in phishing attacks

#68
post #59

Earlier quoted context omitted.

> It was your interpretation that I advise people to not use any 2FA at all. No, to be clear, it's the obvious interpretation of a non-expert user, which is why your advice is so dangerous. They don't have a yubikey, don't understand how the apps work, and are faced with a decision to either enable SMS 2FA or not. And you're telling them not to, so they won't . And we'll all suffer. Again, work the other side of the…

> They don't have a yubikey, don't understand how the apps work... But they almost certainly do have a phone, any vaguely modern phone is also a valid hardware credential - and given how much time people spend using a phone it might even be more practical for them. I would argue that the problem is we've made the inconvenience symbolic - people see me sign in at work (with a Yubico Security Key 2 typically) and assum…

Once more, I'm not saying that SMS 2FA is the best choice. I'm saying it's a vastly better choice than "1FA", and that telling people not to use it is hurting and not helping.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#69
post #68

Earlier quoted context omitted.

> They don't have a yubikey, don't understand how the apps work... But they almost certainly do have a phone, any vaguely modern phone is also a valid hardware credential - and given how much time people spend using a phone it might even be more practical for them. I would argue that the problem is we've made the inconvenience symbolic - people see me sign in at work (with a Yubico Security Key 2 typically) and assum…

Once more, I'm not saying that SMS 2FA is the best choice. I'm saying it's a vastly better choice than "1FA", and that telling people not to use it is hurting and not helping.

As I stated above because it can cause people to believe they're doing the right thing when they aren't I am actualy not convinced it's necessarily better than nothing.

Re: USPS jumps to first place as most imitated brand in phishing attacks

#70

I heard about this scam a couple months ago, but finally got a text myself last week. I didn't click the link for obvious reasons, but looking only at the text itself, it was hard to tell if they were mimicking USPS or UPS. The domain they were using was just some random string like "USPUSU" or something like that.

I usually click the links because I'm curious about how the scams work, and then cut and paste the url to my laptop as I hate mobile browsers.

There are usually quite a few give aways:

Iffy url, not the same as the real one though semi plausible often - say app-usps.com

Usually no personal info like your name / address

The one that finalizes it is that of fields like tracking number or credit card no they usually take anything without checking, like "rubbish12345".

At that point I usually get bored with it.

Post reply on HN