Live data from Hacker News

I was just subjected to the most credible phishing attempt I’ve experienced

twitter.com

71–80 of 360 posts

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#71
post #10

I keep getting astonished by how bad online banking security is in the UK and US. Here in scandiavia, we've had hardware tokens (or phone apps) to offer 2fa for ages. And you need a new token for every transaction. In addition to the password for logging in. When you reset your password, you get an email and an SMS saying that your password was reset. Last time I needed a new token issuer dongle, I had to actually vi…

> Last time I needed a new token issuer dongle, I had to actually visit the bank and sign stuff. I'm glad UK banks try to avoid physical dongles because having to go to the bank and sign stuff to get one is not always convenient, not to mention you need to carry around the dongle everywhere, and if you lose it while you're in vacation it's yet more troubles. Phone 2FA would be good but a bit pointless because the 2FA…

The phone 2fa app asks you to verify the action, and you input your PIN.

My banks hardware token also needs a PIN before it generates a one-time code.

Some bank tokens just give you the code when you press a button, though. Those, you have to worry if stolen.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#72
In EU, there is the (recent) implementation of a (new) directive, PSD2:

https://en.wikipedia.org/wiki/Payment_Services_Directive#Rev...

That carries with it the requirement of SCA:

https://en.wikipedia.org/wiki/Strong_customer_authentication

In practice (here in Italy) you have a client number (secret) a password/PIN (also secret) AND either a SMS to your mobile with a one time code or a Smartphone app (yikes!), there used to be hardware tokens generating one time authorization codes that have now been retired.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#73

The easiest way to avoid this entire class of attack, is to never be willing to answer any kind of question from someone who calls you. Always hang up, Google the customer support line for the business, then call them .

I've already taken the most effective security measures against this kind of attack, which is to never answer the phone.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#75
post #55

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

> It is better if [...anyone...] include a security warning / specific reason the code is sent with the password reset pins and similar credentials. I think anyone building such systems (either via e-mail or SMS or whatever) should at least remember THIS. Send something like this via SMS: > The password reset code you requested via our website is 12345. We will never ask you for this code except when you requested a…

Hey, this is actually how it works in Turkey. All SMS messages for transaction purposes from banks have a disclaimer, which indicates whether to share the code with customer service representative or not.

For example, for online transactions, the SMS includes a warning to not share the code with anyone, while SMS codes for telephone banking tells you to share the number with the representative.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#77
post #37

My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phish…

Good idea - but here in the UK there was a scam where they called you and THEN suggested you call the number on the back of the card. They then don't hang up, but play a dialling tone down the line until you dial the number. At which time they 'answer'. This only works on home phones, not mobile, but is worth considering, and warning your family/friends about.

I don't think this works any more. My parents always did this when kids did prank calls. Kept the phone open for hours blocking their line. Did not work last time I tested. Uncertain how long you have to wait before next call though.

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#78

My simple policy is I never give out any information if I'm cold-called. If they claim they're my bank, I say I'll call them back on the number printed on the card, and ask the caller which department I should be put through to. Legitimate callers have never objected to this approach, and it saves me any stress - same policy, no matter the caller, no exceptions, no need for me to try and figure out if I'm being phish…

The Twitter thread points out that you need to call from a different phone, else the scammer could leave the line open (even after you hang up!).

Re: I was just subjected to the most credible phishing attempt I’ve experienced

#80
post #69

OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them. - The caller called me twice in rapid succession (First ignore the call from a number you do not kno…

Sorry for OT, but I'm Belgian, a software developer, and have a law degree too - can I pick your mind on legal tech in Europe a bit? I can only find your twitter handle, do you have an email address I can reach you on?

Hi Roel, Twitter DMs are open.
Post reply on HN