Live data from Hacker News

Gone (Almost) Phishin'

ma.tt

71–80 of 93 posts

Re: Gone (Almost) Phishin'

#71
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

> getsupport.apple.com.phish.xyz

I notice that a lot of scam texts use domains that start with a TLD followed by a hyphen, like:

  https://wa.gov-phish.fit/dol
  https://seattle.gov-phish.cc/dmv
(Real examples, with "phish" replacing a string of 3-4 random letters)

In some ways, it's a more convincing fake URL, since even if you're used to reading the domain right-to-left, your brain wants to start from the hyphen since it's a different character following a familiar TLD. But that type of domain also seems a lot easier for spam detection rules to catch.

Re: Gone (Almost) Phishin'

#72
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

> I work with senior citizens and tried to explain how to parse the domain in the URL by looking for the first forward "/" after the "https://" and then scan backwards but they find that mental algorithm confusing and those instructions don't stick.

Might try explaining it this way?

It works the same way as a postal address. The first part before `/` is the envelope: by analogy it runs streetaddress.city.country.

You can give a name to your house, or add an apartment to the front - but that doesn't change the most significant part.

Re: Gone (Almost) Phishin'

#73

Earlier quoted context omitted.

Though not all country codes point to a country. See .eu, .ac .su as different examples of stuff that breaks the rules.

the .su domain was made when the soviet union was still around, so that doesn't really break the rules. I would prefer for top level domains to be eternal for a great multitude of reasons

The possible annoyance with eternal country-code TLDs would be the dissolution of one country, and the creation (or renaming) of another country resulting in an eventual exhaustion of two-letter country codes. Eternity is a rather long duration.

Re: Gone (Almost) Phishin'

#74
No mention of password managers yet? One of the major benefits is the password manager can do a quick, simple, completely deterministic check on the domain before providing the password. That would have stopped this dead in its tracks without relying on the human just happening to notice.

I personally use bitwarden on my chrome profile across Windows Mac Linux and android and think it's great. Highly recommended.

Of course I tell this to family and friends and no one does it so I dunno...

Re: Gone (Almost) Phishin'

#76
Two years ago, over the course of two or three weeks, my girlfriend got several of these password reset requests popping up on her iOS devices. She uses a dedicated anonymous e-mail address for her Apple/iCloud account, which she never used for anything else on the Internet, making the event somewhat peculiar.

Re: Gone (Almost) Phishin'

#77
post #41

Earlier quoted context omitted.

Until this moment I assumed .ms was a Microsoft TLD, but indeed it is not https://en.wikipedia.org/wiki/.ms

Handy tip: all two-letter TLDs are country code TLDs. Doesn't matter if they're trendy in website names (.nu, .cc, .io, .co, .it, .at, .cx, youtu.be and so on) In fact, here we have the ma.tt website, where the ".tt" is Trinidad and Tobago. Is Matt Mullenweg from Trinidad? No!

It's kind of crazy that the IRS (among other United States government agencies) uses ID.me for account management. The .me domain belongs to Montenegro.

Re: Gone (Almost) Phishin'

#78

Phishing has gotten really good , lately. As he noted, they will often re-use legit templates from the actual corporation. The email will be 99.9% legit, with maybe only one link being dodgy. I don’t think they can pass DMARC, though. My wife was almost scammed, a few years ago. What tipped her off, was how extremely good the “tech support” was. Real tech support is generally someone on a scratchy line, with a heavy…

I interpreted the post as saying the support emails were legitimate, opened fraudulently (or at least some were) as pretext for the phishing phone call.

Re: Gone (Almost) Phishin'

#79

No mention of password managers yet? One of the major benefits is the password manager can do a quick, simple, completely deterministic check on the domain before providing the password. That would have stopped this dead in its tracks without relying on the human just happening to notice. I personally use bitwarden on my chrome profile across Windows Mac Linux and android and think it's great. Highly recommended. Of…

Same. I've managed to convince exactly one person how great password managers are; the others just let Chrome handle it. (It's always Chrome.)

Re: Gone (Almost) Phishin'

#80
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

Microsoft is really bad with this. Login might be live.com or microsoftonline.com or maybe onmicrosoft.com. I went to report a vulnerability to their security portal this week and it redirected me to b2clogin.com. OneDrive email attachments link to, I kid you not, 1drv.ms, or maybe it was 1drv.com… Not to mention, they use .ms as if it’s their personal TLD, but obviously anyone can register a .ms domain. It’s like th…

We’re talking about the company who owns npm, one of the most hacked package registries in recent history. Can’t say I’m shocked, but this is so bad
Post reply on HN