>I work in tech. I design authentication experiences. I know you’re not supposed to share verification codes! To Me this quote says so much about the crypto space more than anything. Also not shocked it was crypto theft.
What does it say about crypto space?
Scammed out of $130K via fake Google call, spoofed Google email and auth sync
641–650 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#642Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#643Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#644Earlier quoted context omitted.
In cryptocurrency, you can use a multi-signature account to define your own security setup. For example, even a 2-of-2 setup with a trusted authority like a bank is straight-forward improvement in security over the conventional bank system. You can go further, for example consider a 3-of-5 setup with 2 keys in security deposit boxes, 1 key on a laptop, 1 key on a phone, and 1 key on a hardware token. You can set the…
But no one will require that. When you do, no new money will flow into crypto and the music stops. And no one in crypto wants that. So you want there to be as low of a barrier of entry as possible, which is how we get here... Especially when transactions can't be traced
If some idiot leaves all of their funds on an exchange like this, and it gets hacked, then good. That's how the market evolves and money moves out of the hands of the incompetent and into the competent.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#645A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
Some services even say that when they are indeed codes you are _supposed_ to read back to them. Which clearly helps further train people to ignore that language.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#646I don't answer calls from numbers I don't know, period. (In fact I routinely have my phone in Do Not Disturb mode so only a few numbers, the ones I have in my favorites, will make the phone ring at all.) If it's urgent enough to the caller (either because they're legit or because they're a scammer and are trying particularly hard), they'll leave a voice mail. (I've had plenty of fraudulent voice mails.) If they claim…
I understand the dangers of answering scam calls, don't explain it to me but you're assuming that "bank security" (or the like) will never call you to alert you to a scam, or that you will recognize their number. maybe they don't, you may know that, but I sure don't.
I'm assuming no such thing. I have indeed gotten calls and texts from my bank and my credit card companies alerting me to fraudulent transactions, that were legit calls and not scams.
But I didn't answer those calls or texts directly, or try to figure out whether the number that was calling me or texting me was the right one. What I did was to call a number that I already know, independently, leads to my bank, or to my credit card company's fraud department. Or I independently logged into the bank's or credit card company's website to see if there were any alerts. And if there were, I acted on them.
I described this in my earlier post: "If they claim to be from some company I have a relationship with, I check independently to see if something's up."
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#647I don't answer calls from numbers I don't know, period. (In fact I routinely have my phone in Do Not Disturb mode so only a few numbers, the ones I have in my favorites, will make the phone ring at all.) If it's urgent enough to the caller (either because they're legit or because they're a scammer and are trying particularly hard), they'll leave a voice mail. (I've had plenty of fraudulent voice mails.) If they claim…
Bank or government use to call me about important stuff (when I messed up tax report, because of my mortgage, etc.), so not answering is not always a good idea. And nobody use voice mail in EU, it seems to be an US thing.
Sure it is. Just because you get a call about an issue that turns out to be legit, doesn't mean you need to resolve that issue by answering the call.
I describe upthread what I've done when I've received calls or texts from my bank or credit card companies about issues.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#648Earlier quoted context omitted.
Depending on which country you're in and which bank you're with, chargebacks are nothing like as straightforward as they used to be. I just completed yet another one, which involved 2 separate phone calls totalling over an hour (so probably not worth it on a $/hour basis), accepting the risk that if Visa rejects the claim I'm liable for a further $50 charge (this is new), and generally 3 months of hassle until I got…
For the record what kind of chargeback are you initiating, and why does it have to go through visa rather than the bank who issued you the card? Unauthorized card-not-present transaction initiated by a third party? Some cbs are harder than others to get ruled in your favor, but the one where a criminal takes your card and uses it without your knowledge is by far the easiest one to get awarded. It involves one call to…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#649Earlier quoted context omitted.
Depending on which country you're in and which bank you're with, chargebacks are nothing like as straightforward as they used to be. I just completed yet another one, which involved 2 separate phone calls totalling over an hour (so probably not worth it on a $/hour basis), accepting the risk that if Visa rejects the claim I'm liable for a further $50 charge (this is new), and generally 3 months of hassle until I got…
For the record what kind of chargeback are you initiating, and why does it have to go through visa rather than the bank who issued you the card? Unauthorized card-not-present transaction initiated by a third party? Some cbs are harder than others to get ruled in your favor, but the one where a criminal takes your card and uses it without your knowledge is by far the easiest one to get awarded. It involves one call to…
It’s possible that my current bank is particularly bad at this, as they are bad at everything else. I have had the runaround with merchant error and stolen card number chargebacks with other banks though.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#650Earlier quoted context omitted.
This is why 2FA isn't all it's cracked up to be. Strong passwords kept in your head are less brittle than managing something you can lose. If you have a real support channel (like employer IT) to deal with loss it's workable. Online services with no support is just asking for trouble.
2FA can be all it's cracked up to be. A Yubikey you have to physically possess, and physically touch, to login to a site is completely immune to this. Yes, you need to buy hardware, yes you need 1 or more backup yubikeys in a bank safe somewhere in case your primary one breaks, but it is actually safe. Strong passwords in your head are bad because they're even more phish-able. Like, with FIDO2, my yubikey will not lo…
Sure, have a second one at home that can be Fedexed to you.