4 ms·
Forwarded this to my boss because I’m not sure how to handle this. There are many - maybe hundreds of cash real estate transactions happening in my state daily.
by mlacks 7y ago
Forwarded this to my boss because I’m not sure how to handle this. There are many - maybe hundreds of cash real estate transactions happening in my state daily.
I think perhaps in the signature line of our email, we need to implore that last minute or unexpected changes to the original plan- especially involving wire transfers - be verified over the phone.
- btrettel 7y agoI wonder whether asking for verification over the phone would lead to SIM swaps. Though faking someone's voice would be more difficult.
- thephyber 7y agoDoesn't matter. The second channel is what creates the additional layer of security. Eventually SIM swap attacks may get more common and a third channel (or two better channels than email + phone system) may be necessary.
- alexcnwy 7y agoFaking someone's voice isn't as difficult as you'd think: https://github.com/andabi/deep-voice-conversion https://github.com/andabi/deep-voice-conversion https://www.theverge.com/2019/9/5/20851248/deepfakes-ai-fake-audio-phone-calls-thieves-trick-companies-stealing-money https://www.theverge.com/2019/9/5/20851248/deepfakes-ai-fake...
- Bnshsysjab 7y agoCryptographic signatures would solve this if implemented correctly, but I know zero people that utilise it and I work in infosec.
- sowbug 7y agoAnd even if they did, people (being human) would still fall for fake change-of-public-key announcements.
- Bnshsysjab 7y agoOnly if the behaviour reflects current functions. I imagine signatures similar to DKIM would work if they were more integrated into mail clients. Browsers could sign emails when using webmail, it would be a functional change to browser behaviour but could end up pretty generic (eg signing for email, forum posts, maybe even credential signatures etc.
- ignoramous 7y agoAm I right when I say this is where a solution like https://keybase.io https://keybase.io helps with its cryptographically verified identities and messages?
- Bnshsysjab 7y agoI don’t use keybase but I’m pretty sure it’s a central location. If it is, and yits manual it will work in theory, but in practice only crypto nerds will verify manually so the entire thing would need to be automated.