14 ms·
OP here. Just a couple of the things I learned since I posted the Twitter thread: - The caller spoofed the phone number of the bank. The bank was not in my con
by digitallawyer 7y ago
OP here. Just a couple of the things I learned since I posted the Twitter thread:
- The caller spoofed the phone number of the bank. The bank was not in my contacts, so I did not notice. Someone else in the thread noted that they did have the bank's phone number stored, which upped the credibility of the call to them.
- The caller called me twice in rapid succession (First ignore the call from a number you do not know. Then they call back again immediately: "maybe this is urgent / important"). Another person in the thread, who fell for the scam, noted this same pattern.
- It is better if banks include a security warning / specific reason the code is sent with the password reset pins and similar credentials. My bank did not. Another twitter user noted being subject to the scam, and just glancing over the warning copy. So it helps, but it is not perfect. Especially pre-coffee.
- My bank no longer allows me to reset my password without calling them (thanks bank).
When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-) Makes you wonder what this will look like when these scams evolve another couple of generations in terms of complexity ...
- dcolkitt 7y agoInteresting thanks for the write-up. One thing that I've frequently heard is that in any type of fraud call you should always hang up right at the beginning and call the bank back. Seems like no matter how sophisticated the attackers, this defense will always foil anything along the same lines of what happened to you. The only way I can see this countermeasure failing is if the scammers can somehow manage to intercept inbound calls to the bank's customer service number.
- digitallawyer 7y agoThere seems to be broad consensus amongst the commenters that this is the most reliable defense against this kind of attack. Makes sense. If they are able to intercept my outbound calls, it's probably an entirely different level of sophistication and targeting.
- Moru 7y agoYes, this has been the recommendation for a long while. Always call back on the official number you got elsewhere, not the caller ID number. Sometimes the one calling you is already suggesting you to do this just to verify. Especially bank and police I noticed.
- peteretep 7y agoI read about a landline attack that would keep the line open when you put the receiver down, play a dial tone, and then wait until you’d entered a number before putting you back on with the scammer
- tialaramex 7y agoAnalogue telephones are creating (or at least in modern times simulating) a circuit, which doesn't close until the caller hangs up. But almost everybody today has a digital phone, any kind of mobile telephone or desk VoIP phone is digital, "hanging up" ends the call because the telephone itself decided to do that, everything is just packets. So this trick won't be effective against most people today. Likewise "dialling" today is an out-of-band digital step rather than a bunch of pulses or tones sent in-band that an attacker can just ignore.
- digitallawyer 7y agoLearned about this too today. With the scammers playing the dial tone sound to trick the victim... Clever.
- tomxor 7y ago> I read about a landline attack that would keep the line open when you put the receiver down I experienced this once, but not as a scam, I think there must have been some kind of fault at the exchange... the other end was a mobile phone and they didn't end the call, just putting the phone back in their pocket - the landline wouldn't disconnect, whatever signal was send, even disconnecting the phone entirely and plunging it back in. I didn't understand how exactly, but it made it pretty clear the (landline) telephone is not in control of the connection.
- fauigerzigerk 7y agoI agree. The same goes for email obviously. But some financial institutions are actively luring customers into doing the wrong thing. Paypal really stands out on this one. They are regularly sending me emails with a link to their login page to view my recent transactions (regardless of whether or not there are any transactions). This is clearly negligent.
- Loughla 7y agoOkay, so it's not just me. I've never clicked on what are apparently real paypal emails, because I have legitimately always assumed they were phishing e-mails that made it past my spam filter. They're real. They're really real paypal e-mails. Wow.
- fauigerzigerk 7y agoI believe them to be genuine, but if you need incontrovertible proof, Paypal has you covered! :-) All messages contain the following "clarification": "How do I know this is not a Spoof email? Spoof or 'phishing' emails tend to have generic greetings such as "Dear PayPal member". Emails from PayPal will always contain your full name." So unless the bad guys can get their hands on a database full of names and email addresses, we're safe. And Paypal can honestly claim that "the security of our customers is very important to us!".
- abdullahkhalids 7y agoIMHO this should be the law for financial and medical institutions tc. They should not be allowed to call and ask the receiver to provide verification information.
- jwr 7y agoIt doesn't need to be the law: I never provide any information to someone who calls me, unless I have a way of authenticating them.
- na85 7y agoYou're set, then. But the reason a law would be beneficial is it would condition everyone's parents and people who aren't as awesome as you to stop trusting callers and start calling a known-good number.
- angry_octet 7y agoIt is a pretty good idea, but only sufficient if you don't have much money. For large balances it might be worth someone's time to bribe your local telco worker or subvert your SS7/Diameter routing so that your calls route via an intermediary (i.e. make your phone a roaming number, route it's calls to an attacker controlled exchange in e.g. India). It is even simpler to listen in to your legitimate call and hear your phone banking password and secret Q&As. Calling via a landline or via an operator assisted call would make such tricks much more difficult. Some great papers on Diameter and telco security here: https://www.bell-labs.com/usr/silke.holtmanns https://www.bell-labs.com/usr/silke.holtmanns
- archi42 7y ago> It is better if [...anyone...] include a security warning / specific reason the code is sent with the password reset pins and similar credentials. I think anyone building such systems (either via e-mail or SMS or whatever) should at least remember THIS. Send something like this via SMS: > The password reset code you requested via our website is 12345. We will never ask you for this code except when you requested a password reset. 1. What is requested 2. How was it requested 3. Is it safe to pass this to some other human being Okay, 4. in better English ;) As opposed to: > Your caller verification code is 12345, please read this code to your banking agent to verify your identity. Also, ChipTAN is great: https://en.wikipedia.org/wiki/Transaction_authentication_number#ChipTAN_/_Sm@rt-TAN_/_CardTAN https://en.wikipedia.org/wiki/Transaction_authentication_num... If your bank would use this, it would be require extraordinary smart social engineering (or a really naive user).
- csunbird 7y agoHey, this is actually how it works in Turkey. All SMS messages for transaction purposes from banks have a disclaimer, which indicates whether to share the code with customer service representative or not. For example, for online transactions, the SMS includes a warning to not share the code with anyone, while SMS codes for telephone banking tells you to share the number with the representative.
- jedieaston 7y agoBofA gives a disclaimer when you have a 2FA code texted to you (still wish they supported TOTP, but whatever).
- iruoy 7y agoThe only text messages I get from my bank are descriptive confirmations of actions I did. At the end of every message it says to contact them by phone if you don't recognise the action. My bank uses a scanner to authorize pretty much all actions. It scans some sort of RGB QR code [0]. When scanned you'll see the IBAN you're sending the money to and the amount you're sending. I think that when the IBAN is in your contacts it shows the name instead of the IBAN. But most importantly it shows a descriptive message of what action you're verifying. I think the only actions that don't require the scanner are small transactions through their app and marking your card as broken/stolen in the app. [0] https://www.rabobank.nl/images/how_does_the_rabo_scanner_work_29686468.pdf https://www.rabobank.nl/images/how_does_the_rabo_scanner_wor...
- roel_v 7y agoSorry for OT, but I'm Belgian, a software developer, and have a law degree too - can I pick your mind on legal tech in Europe a bit? I can only find your twitter handle, do you have an email address I can reach you on?
- digitallawyer 7y agoHi Roel, Twitter DMs are open.
- rusk 7y agoIt should be noted that Caller ID spoofing is possible with pretty basic equipment. It's illegal in most countries but there's nothing technically preventing you from doing it. Which is crazy IMO.
- adwww 7y agoSMS number spoofing is even easier, and available via almost all programatic SMS services. Usually used to set the sender name.
- ryanlol 7y ago>It’s illegal in most countries Would love to see a citation for this.
- rusk 7y agoOf course it’s illegal! All developed countries have strict rules about how you can use Telecomms networks. Of course scam artists don’t care about these rules ... Its not hard to find out further information abour this. Check with your local Telecomms regulator, google or even the Wikipedia page!
- ryanlol 7y ago>Of course it’s illegal? Fraud tends to be illegal. That’s as far as I’m willing to believe your “of course”. I do not believe most countries have laws regarding caller ID spoofing. I know that in my country IMEI spoofing is (Bizarrely!) sort-of prohibited as forgery (as in IDs, documents or “anything of evidential/testimonial(?) value”), but can’t find anything regarding phone numbers. I know that in the US it’s only illegal to spoof your number for fraudulent purposes.
- rusk 7y ago> it’s only illegal to spoof your number for fraudulent purposes Seems like you’re gettig bogged down in semantics sir
- Roark66 7y ago>It is better if banks include a security warning / specific reason the code is sent with the password reset pins and similar credentials. My bank did not. Another twitter user noted being subject to the scam, and just glancing over the warning copy. So it helps, but it is not perfect. Especially pre-coffee. I'm seriously surprised there are banks that send SMS codes without a reason for the code. All banks I deal with always send the reason for the code. For example: "This is a new payee addition authorisation code. Last 4 digits of the payee's account number are XXXX, the code is: XXXXXX" or "This a transaction authorisation code for the amount of $XX.XX, to an account ending digits XXXX. The number is XXXXXXX." I would seriously reconsider giving your business to a bank that doesn't do that. Interestingly there was an EU regulation passed recently that sets certain standards requiring 2FA for certain operations performed by bank customers. Having set up the 2FA auth app on an elderly relative's android phone and having to set up a pin to unlock a device as this is one of the 2FA app requirements and then spending 2 hours explaining how to unlock the phone, how to use it with a tablet to log in, how to authorise payments etc I have mixed feelings. On one side, it is a pretty secure system that will lower the number of victims of fraud. On the other hand it is a massive inconvenience for elderly people. I like the SMS verification system if done right. I think 2FA is a bit of an overkill.
- wwn_se 7y ago2FA for banking is not overkill! You can make 2FA really easy if you want to, now that EU req. 2FA there will probably be more banks with reasonable solutions.
- hjnilsson 7y agoElderly are the most common subject of these attacks. So it is especially important to set strong protection for them. The inconvenience is regrettable but necessary.
- jen_h 7y agoI have seriously reconsidered giving my business to a bank that does do that: I'm not a fan of sending transaction amounts or account info via text. My bank does this (and over email!); their security posture is fairly decent otherwise, but why oh why send transaction amounts out into the world where they can be intercepted by anyone between here and there? Think about the useful information for an attacker in messages like that: Recent transaction details can help an attacker auth on a call, account numbers can do the same. And large transactions are catnip, alerting attackers to worthwhile victims.
- mxcrossb 7y agoThe best defense against a scam is familiarity. Thanks for sharing this, hopefully it protects someone else.
- dkersten 7y agoI've got a number of calls from my bank over the years (usually the Visa department asking about international charges) and my standard response has always been "I'm sorry, as a rule I do not discuss personal details with someone who called me, since I don't know who you are" and they typically respond with "no problem, please call the number on the back of your credit card". I still wish they wouldn't try to initiate a call (usually they launch straight away into verifying who I am, asking me a ton of personal details before I even know that they're legit... sigh) and would just ask me to call them back on an official number (not one they give me over the phone, obviously) instead. If that were standard practice, I think these kind of scams would be a lot easier to detect.
- deleted 7y ago[deleted]
- TheSpiceIsLife 7y agoI always say to them: I can not identify myself to you because I cannot authentic who you are. And explain to them that we, as a society, need to come up a way of authenticating inbound and outbound calls to ensure we are connect with who the other party claims to be because when you do this it conditions society in to responding and that’s how phishing attacks occur.
- VMG 7y agosociety could fix all sorts of problems if we had a public key infrastructure...
- mschuster91 7y agoBanks have this in place already - EMV cards have powerful cryptoprocessors. In Germany we can use chipTAN, it's a small cheap reader for your card where you scan a six-binary-blinking screen that transmits the transaction data, then the card signs it and you get a six-digit TAN back. You can also manually enter the hash to be signed ("start code" is the technical term) and you get the TAN. Customer support could ask you to authenticate using the TAN already, the hurdle is that you would need to carry the reader at all times. Unrelated to banks, I believe it could be possible to extend SS7 signalling to not just transmit the caller ID but also a crypto signature/public key which the phone then can verify - or your phone provider could. Think of something like HSTS with a global database, if there is no match for the phone number the provider patches the call through, but if there is an entry, all providers can check for the public key transmitted by the caller and refuse to patch the call if it's missing or faked.
- tinus_hn 7y ago> My bank no longer allows me to reset my password without calling them (thanks bank). So how are they going to verify it’s you who is calling them?
- xorcist 7y agoIf the password reset procedure is over SMS, wouldn't any interception of that token have allowed the attackers to access your account and even initiate outgoing transfers? A scam phone call seems like a clumsy way of doing it. It also risks alerting the victim to what's going on. It surprises me that it is legal to conduct banking operations to the general public in this way. In many countries (including all of EU since SCA) that is not the case.
- dvdkhlng 7y agoJust realizing that a phishing-attack like this is nowadays impossible in the EU: proper two-factor authentication is mandatory now (Revised Directive on Payment Services, PSD2), even just for login. TAN-codes generated for transactions need to incorporate the data of the transaction (recipient and amount), so that a phished TAN cannot be used to authorize a different transaction. I think even a simple SMS TAN may not be allowed any more (could be MITM-abused to authorize a different than the intended transaction). Here is a summary of what customers and phishers have to face since september: https://wso2.com/library/articles/2019/06/strong-customer-authentication-and-dynamic-linking-for-psd2/ https://wso2.com/library/articles/2019/06/strong-customer-au...
- blfr 7y agoThe security part of PSD2 is starting to look like another cookie law. Banks of course didn't implement any proper 2FA like U2F but rather send you scrounging for the phone with their app every time you want to look up a transaction or an account number, something that didn't require second factor until the directive. In fact, because it makes checking recent transactions that much less convenient, it probably made me less safe because I do it much less often.
- kuschku 7y agoTOTP is in terms of usability not very different from PhotoTAN or ChipTAN, so I don't see how these methods aren't "proper 2FA". U2F is a useful method, but it's not common at all (even in IT most companies don't provide it, not even the website we're on right now, nor PayPal), and it's not understandable how this isn't "proper 2FA". In addition, the directive requiring the purpose of the code to be fixed and shown aside it, either in the app generating it, or in the push notification, is a very useful security aspect which most other 2FA solutions miss — even U2F can't differentiate between a login and a transaction authorization.
- blfr 7y agoI don't like TOTP. U2F, however, is both convenient and secure. You touch a dongle, you're in, and at the same time there is no way to get access to your account without physically stealing the dongle. It's a proper second factor to a password. Other solutions are either or. There is a benefit to confirming particular actions (with the info about the action) in the app but it's unnecessarily inconvenient for mere login. U2F isn't widely supported but I managed to secure virtually my entire high-value Internet presence with it. Google, OVH, Coinbase, and Stripe all support it. Let's be honest, for HN I wouldn't bother with any second factor. I have the password saved in the browser and that's more than enough.
- simias 7y agoIn your tweets you mention "And now... joyfully resetting all my passwords, filing a police report, getting additional fraud detection in place". What passwords are you talking about and why do you need to reset them? As far as I can tell no passwords have been compromised in the attack as you describe it. Or do you suspect that there's been an other, undisclosed breach that the scammer used to get your name and phone number? I suppose it's plausible but it seems like it wouldn't be too difficult to get that info.
- digitallawyer 7y agoShould have written that more clearly. More accurate verbiage would have been "changing all my banking credentials, and enabling all possible notifications". I have no reason to believe other credentials were compromised, and have unique pw in place for nearly everything.
- workthrowaway 7y agothanks for sharing and sorry it happened to you. sad to say but, i would be suspicious with if any interaction with a bank is going this easy and is this convenient...
- gondo 7y ago"The caller called me twice in rapid succession" this is to bypass the "Do not disturb" functionality on iOS if you have "Repeated calls" enabled. https://cdn.cultofmac.com/wp-content/uploads/2014/04/Do-Not-Disturb.jpg https://cdn.cultofmac.com/wp-content/uploads/2014/04/Do-Not-...
- alanfalcon 7y agoI noticed a political robocall taking advantage of this just yesterday, and there went any possibility that I would vote for this person. Your robocall did not constitute an emergency _you asshole_.
- nothis 7y ago>When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-) Makes you wonder what this will look like when these scams evolve another couple of generations in terms of complexity ... I think this is a social skills moment. For those that claim it's "easy" to spot: This is not the right time for people to brag about how they would have totally spotted it. This is mostly for protecting people who (as most people in this world) don't have time to build up a solid understanding of all aspects of internet security. If you don't care about these people, as some sort of Darwinian schadenfreude, stfu. If you do, focus on their perspective, not your brilliant detective skills.
- AnIdiotOnTheNet 7y agoMost people claiming they would have spotted it are probably wrong anyway. They're reading the messages with the knowledge that they were sent by a scammer. Any idiot can identify these things in hindsight knowing what they're looking at. Without that context, with other things on their mind, it's much more likely they'd have been duped too.
- ghaff 7y agoAbsolutely. You're in the middle of something else. Your "bank" calls you. You're thinking "What the hell do they want and how can I deal with this as quickly as possible?" Etc. I like to think that I'd never fall for any of these scams and I'm sure I'm more conscious of the possibility than I would have been at one point. But I can't really swear that distracted me whose mind is 75% focused on some other task is as security-aware as I like to think I am.
- alistairSH 7y agoI'd wager >50% of those that claim "Ah ha! I'd spot it here!" would fail in real life. Arm-chair quarterbacking is easy. Spotting the scam in real life, when you're walking down the street or otherwise distracted with life? Much harder.
- iicc 7y ago> The caller called me twice in rapid succession (First ignore the call from a number you do not know. Then they call back again immediately: "maybe this is urgent / important"). This also gets past some Do Not Disturb modes.
- jb3689 7y agoStep one for me when I am giving sensitive information is always "let's end this call and let me call you". I had gotten an e-mail from my bank and I called the number in the e-mail without thinking to lookup the support number on my own first. The number was legit and it gave the fraud dept a chuckle but it very well could've been a fake number
- karmickoala 7y agoI've recently read about a similar attack, but in Brazil. Translated: https://translate.google.com/translate?sl=pt&tl=en&u=https%3A%2F%2Fthreadreaderapp.com%2Fthread%2F1179903474244444160.html https://translate.google.com/translate?sl=pt&tl=en&u=https%3... Original (Portuguese): https://threadreaderapp.com/thread/1179903474244444160.html https://threadreaderapp.com/thread/1179903474244444160.html Same approach, they also pretended to be from the bank calling about an irregular transaction. In this scam, it seems they hijacked her home phone line. She tried to call from her cell phone, then they called back to her home phone and said all communication should be from it, to ensure she was at a different location.
- dangerface 7y ago> When I read the thread now, it's obviously full of red flags. I was successfully manipulated, and whilst I'm certainly not as clever as all the people pointing out they would have caught this from sentence one, I believe I'm also not the lowest hanging fruit in terms of a target :-) I think it's soo easy to spot scams because 99% of them are so shit, poor spelling, talking nonsense. If scammers simply spell checked their scams I would fall for them all.
- jowsie 7y agoNot sure if still the case, but this used to be done specifically to weed out people who weren't quite gullible enough. https://www.telegraph.co.uk/technology/microsoft/9346371/Nigerian-scam-emails-deliberately-implausible.html https://www.telegraph.co.uk/technology/microsoft/9346371/Nig...
- beerandt 7y agoTo me, the biggest red flag is asking for any identifying info in a conversation they initiated, especially without them initially providing some sort of privledged information to you first. Unfortunately, some banks do this. (I'm looking at you, U.S. Bank.) It's like someone calling me and then asking me who they're speaking to. Really? You called me! (Assuming they're not returning a missed call, of course.) If (someone claiming to be) a bank calls/texts you, (and it's not immediately after a declined transaction) you always hang up and call the number you already have for the bank. Even if it is after a declined transaction, you still don't provide any info. If they ask if you attempted a $101.89 purchase at "big box store," you should simply respond yes/no, and provide no other info. If you didn't attempt that transaction, they especially don't need to confirm any other info.
- kevlawrence 7y agoHow do we know you are the OP?
- _bxg1 7y agoI got a similar call a few months back. They didn't ask for my PIN, but did ask for some other sensitive information. Fortunately I was able to verify afterward that it was legitimate by initiating a call to the bank using the number on their website (in case the original was spoofed), and they confirmed a record of the call in their system. But this was after I'd given them some information. Phone number spoofing has to stop. There is no excuse anymore.
- bpp 7y agoWith regard to the phone number spoofing: I recently had an actual call from American Express's security department marked by AT&T as "Fraud Risk," presumably because it's been spoofed in the past. It delayed the detection and resolution of the theft of my card number (not by much, but still...). It's criminal that we haven't better secured the Caller ID system.
- nradov 7y agoEvery financial institution has a mobile app now. They should just add a secure voice chat feature to the app instead of relying on phone calls.
- cwojno 7y agoCalling twice in rapid succession is an emergency feature for Android (possibly other) phones when in Do Not Distrub mode. It bypasses the DND when you call twice like that. Usually, only the numbers on your Starred list can call without getting blocked by DND. The recipient may believe they had starred the number because of this, making them more likely to pick up the call.
- 0xffff2 7y agoOn iOS you can choose whether to allow or block repeated calls, but as far as I can tell it's an all or nothing toggle. If it's enabled, anyone can get through by calling twice.
- paul7986 7y agoI would say Thanks for the call. I'm hanging up now to call my bank to verify this.
- ping_pong 7y agoThe biggest mistake was offering any information. You never offer information, you only confirm or deny things that they tell you. If they insist on things like member id, or email, you hang up, and call the bank yourself. We as a society need some form of standardized ISO 9001-level protocol where ALL companies handle security the same way. They all ask the same questions, they don't allow first-tier support access to passwords or changing password, only specialized tier-2 support has this power, etc. If all companies like banks, Amazon, Facebook, etc standardize their procedures in a way that leaks no information, or engage customers in a way that leaks no information, then it will make it harder to phish people because phisher will be forced to ask weird questions that customers will detect as weird. The problem right now is that some companies ask for last 4 digits of SSN, last 4 digits of credit card, some ask for email address, etc, etc. A phisher can put all those together so if you reduce the attack surface it makes it very very hard.
- undefined3840 7y agoThis is actually fairly common now, unfortunately. Many reports of Uber drivers being tricked into getting their account hacked using this method to obtain the 2FA pin sent via SMS so they can drain their balance or switch the bank account on file.
- mzanchi 7y agoI never give any information to anyone who calls me, apart from people I already know like friends and family. If they say they are from the bank I apologize and say that I will contact them independently via the number that is on my card. I don't even confirm my name. Some banks think I am being difficult, but I stick to this principle regardless.
- AnimalMuppet 7y agoI think it's more likely that some scammers think you're being difficult. Shouldn't that be standard procedure for a bank?
- dheera 7y agoSorry for the nitpick on grammar but "I was just subjected to the most credible phishing attempt I’ve experienced" Everyone has been subjected to the most credible phishing attempt they've experienced. Need to find another qualifier ;)
- deleted 7y ago[deleted]
- zamalek 7y agoPro-tip, perform mutual authentication: "Can you give a reference number (they will have a case number), and tell me where I can find your department's number on your website please. [Edit] I will call you back." I've never had a bank or other financial institution have a problem with this approach. I don't give myself the opportunity to be fooled, because all of us can be fooled, it's how I respond to every single call from a business.
- omnifischer 7y agoOnce I gave my member number, the attacker used the password reset flow to trigger a text message from the bank. --> They used this to gain access to the account. How did they to gain access from "password reset flow"? How could they tell your last transactions?