Live data from Hacker News

Crates.io phishing attempt

fasterthanli.me

71–80 of 83 posts

Re: Crates.io phishing attempt

#71
post #67

Earlier quoted context omitted.

Phone number on the card? My latest card doesn't even have the card number itself, validity dates or CVV number on it anymore, just the bank logo, some background graphics and some words about how safe it is and that it was made with recyclable materials.

Have you checked the other side? My newest bank cards are very minimal on the front, but all the information was printed on the back.

That is the backside :) The front just have graphics and no text at all.

Re: Crates.io phishing attempt

#72
post #71

Earlier quoted context omitted.

Have you checked the other side? My newest bank cards are very minimal on the front, but all the information was printed on the back.

That is the backside :) The front just have graphics and no text at all.

Wow. That seems... less useful. Like, the huge embossed numbers weren't really necessary because the machines those are for no longer are popularly used so who cares (I have used one, but it was last decade and it did not feel like they'd have turned me away if it didn't work). But a CVV must still actually be useful to some fraction of your real customers, and likewise the expiry date.

Re: Crates.io phishing attempt

#73
post #33

If you get a message (text, email or call), it's best to not trust the contents of the message until you verify it by logging in or whatever yourself. If crates.io says you have a problem, close the email and go to crates.io yourself. If your bank calls you, hang up and log in or call their support number yourself. Don't trust anyone contacting you for sensitive stuff

Definitely. I get scammers calling me from a caller id that claims to be my bank asking about suspicious charges, and they know my name and have my account info, but they ask for my full credit card number to "verify" it. Yet, they give different suspicious charges every time you ask. The worst part is that when I call the bank to see if its legit, they are much less pleasant to deal with than the scammers...

I just realized that's an excellent opportunity for "reverse phishing:" you can mangle the first 4 digits of your card [or make one up wholesale] and if they say "thank you, sir" you know they are fake. The real bank will spot that mistake instantly since that prefix is per financial institution

Re: Crates.io phishing attempt

#74
post #44

Earlier quoted context omitted.

> If your bank calls you, hang up and log in or call their support number yourself. And don't trust the number you see on Google. Google is known to show scammers' phone numbers in featured snippets or in their new "AI Mode". Click on the link and make sure it's the correct site before trusting the number.

Call the number on the back of your card. You do still have a physical card, right? You don't just have a banking app? Apps can be... uhhh... wrong...

I do this religiously, and last time I got a fraud alert call for my Barclays-issued credit card, I called them back on the number on the card. They seemed amused and didn’t know what to do :(

Re: Crates.io phishing attempt

#75
post #71

Earlier quoted context omitted.

That is the backside :) The front just have graphics and no text at all.

Wow. That seems... less useful. Like, the huge embossed numbers weren't really necessary because the machines those are for no longer are popularly used so who cares (I have used one, but it was last decade and it did not feel like they'd have turned me away if it didn't work). But a CVV must still actually be useful to some fraction of your real customers, and likewise the expiry date.

> But a CVV must still actually be useful to some fraction of your real customers, and likewise the expiry date.

The CVV code of this card changes once every 10 minutes, so I understand them not printing that. Yet yeah, could have put the card number there with the dates, but I guess if the CVV already cannot be printed, why not just avoid all of it?

Regardless, doesn't really matter much anyways as I don't think I've used a proper card for months, everything around me supports NFC mobile payments since years back.

Re: Crates.io phishing attempt

#76
post #71

Earlier quoted context omitted.

Have you checked the other side? My newest bank cards are very minimal on the front, but all the information was printed on the back.

That is the backside :) The front just have graphics and no text at all.

Sounds like you need to call your bank and make a formal complaint about it

Re: Crates.io phishing attempt

#77

If you get a message (text, email or call), it's best to not trust the contents of the message until you verify it by logging in or whatever yourself. If crates.io says you have a problem, close the email and go to crates.io yourself. If your bank calls you, hang up and log in or call their support number yourself. Don't trust anyone contacting you for sensitive stuff

>> Don't trust anyone contacting you for sensitive stuff

For not sensitive either. If something is a good deal - they will not be calling me, it's me who should call to find and get the best deal.

Re: Crates.io phishing attempt

#78
post #37

Earlier quoted context omitted.

"Your WebAuthn key enrollment period has expired. Please log in to re-enroll a new key." Something similar to this was in the recent npmjs thing.

I can't find any trace of such a thing, do you have links? What would it even mean to "log in" if they reject my authenticator ? Logging in is what it's for.

You have to log in with your password, of course. And then re-enroll your authenticator.

Re: Crates.io phishing attempt

#79

Why does it seem like phishing is popular again? Maybe bad actors forgot how gullible humans were? I get phishing attempts nearly daily via email or sms and I honestly thought “Who would fall for this?” every time one came in. The only phishing I can see that would be extremely hard to detect are browser extension injections (either in extension window or page replacement) so the domain is legitimate.

Phishing is dumb and easy to detect by purpose. I's to filter victims who are an easy target.

Re: Crates.io phishing attempt

#80

Earlier quoted context omitted.

> People realized that past phishing attempts were quite badly constructed I seem to recall that the typos and grammar errors were intentional. This gets rid of skeptical people, and you're left with those who are extremely gullible and likely to fall for it.

This current spate of attacks might be _because_ of that, in fact. Enough people know that phishing attacks are obviously low quality, so when they see a well-constructed message they're less suspicious

Or it’s because LLMs don’t make spelling mistakes.
Post reply on HN