Live data from Hacker News

The golden age of scammers: AI-powered phishing

mailgun.com

71–80 of 143 posts

Re: The golden age of scammers: AI-powered phishing

#71
post #38

Hey, just going to say what I've been telling folks IRL, if you are reading this, and your parents and family members aren't tech savvy, you need to set them up with two factor authentication now. Because you know how to do that, and it's so much easier than helping them when they get hacked.

I set up 2fa codes through Google Authenticator with my family, and employees. That is to say I generate a QR code, we all scan it while we are in the room together and can use it at any time to check who we are really speaking to. This is in addition to a question/answer pair that we have had with my immediate family for years (duress question, duress answer, standard question, standard answer).

Interesting. So it's a bit like providing a public key, if they need to make sure they are talking with you they ask you to provide the TOTP and they control they have the same number on their side?

Re: The golden age of scammers: AI-powered phishing

#72

On YouTube, I saw a deepfake of Elon Musk asking people to scan a QR code and buy crypto.

On twitch this a daily occurrence... and not just elon, it's mrbeast, kaicenat, and ishowspeed as well. (That is, on top of all the other "free drops/skins" impersonation that twitch can't seem to shut down)

I can hardly dodge the propaganda that makes some names a compelling social basic knowledge expectation, like Mr Musk and the likes. It’s the very first time I read about mrbeast, kaicenat, and ishowspeed however.

Note that the admiration/detestation opinion might not be as socially mandatory. But probably it’s as optional as an agnostic position is tenable in a society full of theists looking for some heretics to burn on the one hand, and fanatical atheists eager to decapitate any devout on the other hand.

Re: The golden age of scammers: AI-powered phishing

#73
post #38

Earlier quoted context omitted.

I set up 2fa codes through Google Authenticator with my family, and employees. That is to say I generate a QR code, we all scan it while we are in the room together and can use it at any time to check who we are really speaking to. This is in addition to a question/answer pair that we have had with my immediate family for years (duress question, duress answer, standard question, standard answer).

Interesting. So it's a bit like providing a public key, if they need to make sure they are talking with you they ask you to provide the TOTP and they control they have the same number on their side?

Yeah that's right. So me, my 2 kids and my wife all have the same code, I have one with my brother and my dad (my mum is a bit too past it ... ) and one with my employees (I only have 2 ... ). It's like a way to prove you were all the same people in the room at the same time! I have a little script that produces a QR code, then I delete it and it will never exist again :) EDIT: my youngest daughter in particular really loves it. When I go on a run and get home without my key, and I knock on the door she grabs her iPad and opens the door a little crack and says "what's the code?"

Re: The golden age of scammers: AI-powered phishing

#74

Artificial Intelligence vs. Actually Indian

I was called by an Indian like ten years ago, trying to convince me to follow some script obviously made for Windows when at the time I already hadn’t a Windows box for quite some time. Fun moment, in that specific case. Probably the funniest thing here is that this call reached me despite the fact that I am French, living in France. And so I really wonder how they ended up calling me. I mean, chance I would understa…

It seems like the majority are from India but no surprise with a population that's technical and soon to exceed China's population.

CBC the Canadian nations news service has been trying to track scammers in India

https://www.cbc.ca/news/world/tech-support-scam-india-market...

Even Jim Browning and Kit Boga on YouTube two guys who scam the scammers it seems to be 100% people based in India.

Re: The golden age of scammers: AI-powered phishing

#75
I'm kind of amazed how slow 'AI phishing' has been to roll out.

The technology for customised text based attacks at scale has been available at least since Llama was open sourced. The tech for custom voice and image based attacks is basically there too with whisper / tortoise and stable diffusion - though clearly more expensive to render. I'm honestly not sure why social networks aren't being leveraged more to target and spoof individuals - especially elderly people.

Tailored attacks impersonating text or voice messages from close contacts and family members should be fairly common, and yet they're not. Robo-calls that carry out a two way conversation convincingly impersonating bank or police officials should be everywhere. Yet the only spam-calls I ever receive are from Indian call centres or static messages using decades old synthesised voice tech.

Re: The golden age of scammers: AI-powered phishing

#76
post #61

Earlier quoted context omitted.

The bad grammar is on purpose. I know of two possible reasons: * Bayesian poisoning https://en.wikipedia.org/wiki/Bayesian_poisoning * Weeding out poor mark candidates https://josephsteinberg.com/why-scammers-make-spelling-and-g...

I see this a lot, but it seems hard to verify. Has a scammer actually ever come out and say they deliberately use poor grammar? Would be interesting to compare scam emails/messages from scammers based in the US/UK/Australia with those in India or Nigeria, and see if the pattern holds up for both.

> I see this a lot, but it seems hard to verify.

Easy. As you say all you need to do is to compare and as I occasionally have a glimpse of the spam for some non-English language with a non-Latin script - it's the same.

Re: The golden age of scammers: AI-powered phishing

#77
post #59

> Is it your fate now to do due diligence on every email you receive? Always has been. Tbh the browser/email client makers are complicit in these phishing attempts for hiding the URLs and the actual email addresses. Put them back!

> Tbh the browser/email client makers are complicit in these phishing attempts for hiding the URLs and the actual email addresses. It's worse. Research "Scamicry". Big business now is so fake, such a grift, drenched in PR deception, and lacking integrity and trustworthiness, there isn't much space left between what is "legitimate" and what is a scam. If businesses like Google or Facebook hide URLs and email addresses…

I beat that drum so long it turned into beating my head against a wall.

The last two companies I worked for insisted that customer account security was the highest priority, but as soon as I said we needed to stop hiding links to our own website behind Hubspot tracking URLs so we don't train our customers to click links that look like gobbledygook garbage, the marketing team melted down and it became clear where user account security actually fell on the priority list.

I don't think it's always malicious, though. I think most people in most companies just don't realize the risk. Like, I had to explain to my doctor's office why I'm never going to "confirm my identity" by rattling off my DOB and address at the beginning of a call when they called me. I even think of those specific data points as public information anyway and I'm not going to participate in that nonsense. It had never occurred to them that this was risky behavior.

It did make me appreciate my parish priest's method, though. Every quarter or so, he reminds people from the pulpit that he will never email them asking for gift cards or anything of the sort. If the parish needs money for something, he promises he'll ask for it right from the pulpit!

Re: The golden age of scammers: AI-powered phishing

#78

Why don’t US phone carriers give their users the ability to block foreign calls terminating in the U.S., at the telephony signaling layer? In almost no case do I ever want to receive a phone call from a foreign country with a spoofed number. Nor do I think anyone in my family wants to either.

I've assumed these were VOIP calls, not actual telephony calls from other countries.

Re: The golden age of scammers: AI-powered phishing

#79
post #8

On YouTube, I saw a deepfake of Elon Musk asking people to scan a QR code and buy crypto.

When I typed my phone number in the box on "Musk" "investment" website my landline rang instantly after entering the last digit. It was definitely an onkeydown event. A friendly fast talking man in an extremely busy sounding (fake) call center asked me if I was $name_I_put_in_the_form. The voices in the background were people further down the sign up process. I said yes, then asked how he got my number. He said I jus…

Share your story with "Kit Boga" on YouTube. He would love to prank them.

Re: The golden age of scammers: AI-powered phishing

#80
post #59

> Is it your fate now to do due diligence on every email you receive? Always has been. Tbh the browser/email client makers are complicit in these phishing attempts for hiding the URLs and the actual email addresses. Put them back!

Also the URL "security scanner" things on corporate email systems. The user can't see the URL by hovering over it.

I was about to complain about this. I take security training to inspect URLs and then Microsoft safe link or whatever it's called gives me a twenty line long URL filled with random characters. I have to trust it works since they took my manual inspection ability away.
Post reply on HN