Live data from Hacker News

Crates.io phishing attempt

fasterthanli.me

81–83 of 83 posts

Re: Crates.io phishing attempt

#81
post #78

Earlier quoted context omitted.

I can't find any trace of such a thing, do you have links? What would it even mean to "log in" if they reject my authenticator ? Logging in is what it's for.

You have to log in with your password, of course. And then re-enroll your authenticator.

So, firstly, this won't actually help them which is why they won't try it. GitHub is aware that passwords are crap and since I have a Security Key it will ask to see my Security Key, "But I know tialaramex's password" doesn't help you.

But also you presented no evidence they can somehow detect their problem and try to ask for the password even if it would help them.

Re: Crates.io phishing attempt

#82
post #73
post #33

Earlier quoted context omitted.

Definitely. I get scammers calling me from a caller id that claims to be my bank asking about suspicious charges, and they know my name and have my account info, but they ask for my full credit card number to "verify" it. Yet, they give different suspicious charges every time you ask. The worst part is that when I call the bank to see if its legit, they are much less pleasant to deal with than the scammers...

I just realized that's an excellent opportunity for "reverse phishing:" you can mangle the first 4 digits of your card [or make one up wholesale] and if they say "thank you, sir" you know they are fake. The real bank will spot that mistake instantly since that prefix is per financial institution

They know about bank prefixes and will ask you to check the number again.
Post reply on HN