5 ms·
At least in the demo, the system didn't identify itself as a bot. It pretended (fairly convincingly) to just be a person, and seemed focused on interactions (ma
by apendleton 8y ago
At least in the demo, the system didn't identify itself as a bot. It pretended (fairly convincingly) to just be a person, and seemed focused on interactions (making a restaurant reservation, etc.) that don't involve someone recognizing your voice. In other words, I don't think the attack surface is any different than situations where you could just place the call yourself, save perhaps for the possibility of scaling it.
- menzoic 8y agoI don't think the scaling concern should be underestimated. Thats a big difference. Its mostly a numbers game.
- throwawayjava 8y agoIt's not just scaling, but also speed. If you sequentially attack a subpopulation (e.g., employees at a company, senior citizens) the eventually news about your attack will spread throughout that network (internal security alert, evening news+daily newspapers+AARP+...). If you attack the entire subpopulation in rapid succession over the course of days or even hours, educational countermeasures become much less effective.
- jbob2000 8y agoSo now I can script a bot to book restaurant reservations all over the city at busy times. Then nobody shows up for the reservations, the busy time has passed, and customers have moved on or gone home. Restaurants make or break on one or two nights in a month. A calculated social engineering attack like this could bring down hundreds of restaurants in a city, which would cause millions of dollars in lost taxes, and you see where this is going.
- freehunter 8y agoWas there something stopping you from doing that before? A lot of places you can even do it online.
- spydum 8y agoliterally effort. when you lower the attackers effort and cost to try an attack, the attempts generally go up.
- freehunter 8y agoI meant, you could build a bot that calls. We have the technology already, and the people on the other end probably won't notice. Plus the "do it over the Internet" thing where screen scraping and scripting is super easy.
- jbob2000 8y agoYes, the time commitment of having one person pickup the phone and place 100+ phone calls (and the suspicion on the other end when you call back with a new name but the same voice). You could write a screen scraper to book online through the various booking systems, but each booking system probably has its own restrictions on how many accounts you can have and how often they can book. You skip all of these protections when you phone your reservation in (arguably, the restaurant staff should be enforcing these protections when they pick up the phone, but restaurant staff are often overworked and apathetic).
- fudged71 8y agoThen the restaurants will just stop taking phone reservations. Either no reservations or online-only.
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- barake 8y agoSomeone has already done that: https://chicago.eater.com/2018/3/5/17078210/opentable-reserve-fake-reservation-scheme-no-shows-chicago-restaurants-valentines https://chicago.eater.com/2018/3/5/17078210/opentable-reserv...
- uptown 8y agoI agree it's a problem. The probably means of mitigation is for restaurants to take your credit card number when you book. Many already do this. I expect it to expand if false bookings become a problem.
- flokie 8y agoHow would you script "script a bot" - i think you're underestimating the effort. You'd have better luck trying to attack by mass booking manually.
- darepublic 8y agoTo be fair I think any mediocre dev could do that now simply with headless browser automation.
- busyant 8y agoYou adapt. Take valid CC info and charge cancellation fee.