Live data from Hacker News

Gone (Almost) Phishin'

ma.tt

61–70 of 93 posts

Re: Gone (Almost) Phishin'

#61
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

It is unfortunately normal for companies to impersonate scammers. We can teach people as much as we want about security against phishing. It won't matter because people have to break these rules constantly. Companies actively train people to fall for phishing by doing everything in their power to be indistinguishable from phishing themselves.

The worst are DHL, UPS, etc. customs payment mails. Even the real ones look like phishing mails and in some cases they don’t link the payment request to your account, so you cannot circumvent it by logging into your account and checking wether it is legit.

Re: Gone (Almost) Phishin'

#63

Earlier quoted context omitted.

Handy tip: all two-letter TLDs are country code TLDs. Doesn't matter if they're trendy in website names (.nu, .cc, .io, .co, .it, .at, .cx, youtu.be and so on) In fact, here we have the ma.tt website, where the ".tt" is Trinidad and Tobago. Is Matt Mullenweg from Trinidad? No!

Though not all country codes point to a country. See .eu, .ac .su as different examples of stuff that breaks the rules.

the .su domain was made when the soviet union was still around, so that doesn't really break the rules. I would prefer for top level domains to be eternal for a great multitude of reasons

Re: Gone (Almost) Phishin'

#64
I had two calls from "Apple Support" very very much like this in the past two weeks. Both times, their claim was that someone was trying to reset my Apple password and they were trying to protect me.

Both times, they asked me to go to a BS "apple-support" website and enter a six digit number they'd read out to me, where I'd see a transcript of this very phone call so I could then have full assurance that they were legit and working for Apple.

Uh huh.

And both times, when I asked them to just send me a quick email from their address at Apple (any address, even a generic inbox or support address) to assure me they worked for Apple ... pause ... [click]. Yeah.

Re: Gone (Almost) Phishin'

#65
post #46

Earlier quoted context omitted.

> I work with senior citizens and tried to explain how to parse the domain in the URL by looking for the first forward "/" after the "https://" and then scan backwards but they find that mental algorithm confusing and those instructions don't stick. Have you tried some analogy which will be personal to them? Like describing the URL as a family tree: “ com is the oldest ancestor, like you Mr Johnson. Then apple is you…

For a simpler example: “You ever watch MASH? Remember the main guy, Benjamin Franklin Pierce? He’s not the same guy as Benjamin Franklin, is he? You can tell because you don’t stop after the first part of the name you recognize. You have to go all the way to the end and look at the whole name. Well, same here!”

Agreed, I like that better. It even has the correlation with family names being at the end.

Re: Gone (Almost) Phishin'

#66
post #41

Earlier quoted context omitted.

Microsoft is really bad with this. Login might be live.com or microsoftonline.com or maybe onmicrosoft.com. I went to report a vulnerability to their security portal this week and it redirected me to b2clogin.com. OneDrive email attachments link to, I kid you not, 1drv.ms, or maybe it was 1drv.com… Not to mention, they use .ms as if it’s their personal TLD, but obviously anyone can register a .ms domain. It’s like th…

Until this moment I assumed .ms was a Microsoft TLD, but indeed it is not https://en.wikipedia.org/wiki/.ms

They also use .microsoft now (e.g. for the M365 admin portal).

Re: Gone (Almost) Phishin'

#67
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

> The other problem with that advice is people can't "whitelist" the legitimate domains to look for because they don't know ahead-of-time what they are. E.g.:

Yep, and there's even things like irs.gov which tells you how to know a site is official (https, and .gov), and then links you to id.me to login. (not sure what was wrong with login.gov, which SSA lets you use)

Re: Gone (Almost) Phishin'

#68
Don’t approve any password-reset prompts—those are the first part of the attack. Do not pass Go, just head directly to your Apple ID settings.

Why do I need to go to Settings? I get these occasionally and ignore them; what harm is there in that?

FWIW these were real bad for a while, but Apple seems to have gotten better at canning the spam. Maybe 1-2 per year?

Re: Gone (Almost) Phishin'

#69
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

Or the insanity of IRS services that use the "id.me" domain for a vendor with a Montenegro TLD.

Privacy issues aside, white-labeling the service and infrastructure behind *.irs.gov should be a mandatory requirement.

Re: Gone (Almost) Phishin'

#70
post #52
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

> senior citizens and tried to explain how to parse the domain Why would you want end users, senior citizens or not, to mentally parse URLs? The rule is: If the bank, or paypal, or your landlord, or anyone else really emails you that you have to complete some information to your account or pay the latest bill or whatever, you GO TO THEIR WEBSITE and login normally. If it is important they will have the same informati…

Man it's like we live in two different realities and yours is a textbook. dozens of times I've been sent links to download a pdf or fill out a form that is not linked from the main site anywhere. I know because I check - I hate clicking links in emails because of tracking if nothing else
Post reply on HN