Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

641–650 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#641

>I work in tech. I design authentication experiences. I know you’re not supposed to share verification codes! To Me this quote says so much about the crypto space more than anything. Also not shocked it was crypto theft.

What does it say about crypto space?

Otherwise rational and educated people are willing to suspend disbelief about anything as long as it supports their crypto yacht dreams. In this case the concern that their yacht dreams were being lost. Which ironically caused their dream to be lost.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#642
post #511

Earlier quoted context omitted.

If you got hacked, you didn't do everything right

This is elitist nonsense. Maybe this user didn't do everything right but people are hacked regularly through zero fault of their own.

It's your responsibility to secure your own hardware

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#643

Earlier quoted context omitted.

If you got hacked, you didn't do everything right

How about https://xkcd.com/538/ ?

I'll take the $5 wrench and $10,000 hitman attack that I'm aware of instead of the $0 push-button attack that you don't discover until it's too late.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#644
post #602

Earlier quoted context omitted.

In cryptocurrency, you can use a multi-signature account to define your own security setup. For example, even a 2-of-2 setup with a trusted authority like a bank is straight-forward improvement in security over the conventional bank system. You can go further, for example consider a 3-of-5 setup with 2 keys in security deposit boxes, 1 key on a laptop, 1 key on a phone, and 1 key on a hardware token. You can set the…

But no one will require that. When you do, no new money will flow into crypto and the music stops. And no one in crypto wants that. So you want there to be as low of a barrier of entry as possible, which is how we get here... Especially when transactions can't be traced

It doesn't need to be required of anyone. People are responsible for their own funds and have their own security/effort profiles. The "right way" of doing things will be discovered through natural selection.

If some idiot leaves all of their funds on an exchange like this, and it gets hacked, then good. That's how the market evolves and money moves out of the hands of the incompetent and into the competent.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#645

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

>never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that!

Some services even say that when they are indeed codes you are _supposed_ to read back to them. Which clearly helps further train people to ignore that language.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#646
post #491

I don't answer calls from numbers I don't know, period. (In fact I routinely have my phone in Do Not Disturb mode so only a few numbers, the ones I have in my favorites, will make the phone ring at all.) If it's urgent enough to the caller (either because they're legit or because they're a scammer and are trying particularly hard), they'll leave a voice mail. (I've had plenty of fraudulent voice mails.) If they claim…

I understand the dangers of answering scam calls, don't explain it to me but you're assuming that "bank security" (or the like) will never call you to alert you to a scam, or that you will recognize their number. maybe they don't, you may know that, but I sure don't.

> you're assuming that "bank security" (or the like) will never call you to alert you to a scam, or that you will recognize their number

I'm assuming no such thing. I have indeed gotten calls and texts from my bank and my credit card companies alerting me to fraudulent transactions, that were legit calls and not scams.

But I didn't answer those calls or texts directly, or try to figure out whether the number that was calling me or texting me was the right one. What I did was to call a number that I already know, independently, leads to my bank, or to my credit card company's fraud department. Or I independently logged into the bank's or credit card company's website to see if there were any alerts. And if there were, I acted on them.

I described this in my earlier post: "If they claim to be from some company I have a relationship with, I check independently to see if something's up."

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#647
post #586
post #491

I don't answer calls from numbers I don't know, period. (In fact I routinely have my phone in Do Not Disturb mode so only a few numbers, the ones I have in my favorites, will make the phone ring at all.) If it's urgent enough to the caller (either because they're legit or because they're a scammer and are trying particularly hard), they'll leave a voice mail. (I've had plenty of fraudulent voice mails.) If they claim…

Bank or government use to call me about important stuff (when I messed up tax report, because of my mortgage, etc.), so not answering is not always a good idea. And nobody use voice mail in EU, it seems to be an US thing.

> not answering is not always a good idea.

Sure it is. Just because you get a call about an issue that turns out to be legit, doesn't mean you need to resolve that issue by answering the call.

I describe upthread what I've done when I've received calls or texts from my bank or credit card companies about issues.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#648
post #550

Earlier quoted context omitted.

Depending on which country you're in and which bank you're with, chargebacks are nothing like as straightforward as they used to be. I just completed yet another one, which involved 2 separate phone calls totalling over an hour (so probably not worth it on a $/hour basis), accepting the risk that if Visa rejects the claim I'm liable for a further $50 charge (this is new), and generally 3 months of hassle until I got…

For the record what kind of chargeback are you initiating, and why does it have to go through visa rather than the bank who issued you the card? Unauthorized card-not-present transaction initiated by a third party? Some cbs are harder than others to get ruled in your favor, but the one where a criminal takes your card and uses it without your knowledge is by far the easiest one to get awarded. It involves one call to…

The US makes chargebacks exceptionally easy. Non-Americans have a much less useful credit card system, which is why debit cards are more common in most of Europe.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#649
post #550

Earlier quoted context omitted.

Depending on which country you're in and which bank you're with, chargebacks are nothing like as straightforward as they used to be. I just completed yet another one, which involved 2 separate phone calls totalling over an hour (so probably not worth it on a $/hour basis), accepting the risk that if Visa rejects the claim I'm liable for a further $50 charge (this is new), and generally 3 months of hassle until I got…

For the record what kind of chargeback are you initiating, and why does it have to go through visa rather than the bank who issued you the card? Unauthorized card-not-present transaction initiated by a third party? Some cbs are harder than others to get ruled in your favor, but the one where a criminal takes your card and uses it without your knowledge is by far the easiest one to get awarded. It involves one call to…

Merchant fraud this time. Done through the (soon-to-be-ex) bank but they brought up the charge from Visa.

It’s possible that my current bank is particularly bad at this, as they are bad at everything else. I have had the runaround with merchant error and stolen card number chargebacks with other banks though.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#650

Earlier quoted context omitted.

This is why 2FA isn't all it's cracked up to be. Strong passwords kept in your head are less brittle than managing something you can lose. If you have a real support channel (like employer IT) to deal with loss it's workable. Online services with no support is just asking for trouble.

2FA can be all it's cracked up to be. A Yubikey you have to physically possess, and physically touch, to login to a site is completely immune to this. Yes, you need to buy hardware, yes you need 1 or more backup yubikeys in a bank safe somewhere in case your primary one breaks, but it is actually safe. Strong passwords in your head are bad because they're even more phish-able. Like, with FIDO2, my yubikey will not lo…

Yubikey is great. But I would be scared as f. to lose it when traveling abroad.

Sure, have a second one at home that can be Fedexed to you.

Post reply on HN