13 ms·
QR code scammers hitting on-street parking in Texas cities
- jakear 5y agoGiven this is going through traditional payment infrastructure it should be easy enough to follow the money, no?
- post_break 5y agoYou could wash this fast with gift cards like microsoft support scammers. What's funny though is the amount is so low. Maybe at the most $5-10 a person. I can't imagine you getting a large sum of money through this before being shut down.
- colinmhayes 5y agoI assume everyone is paying with credit cards, so I don't see how gift cards would help. The scammers probably live in a country with lax law enforcement with regards to hacking, so they can just deposit the money into their account when the credit card company sends it.
- post_break 5y agoYou get money from the payment processor then cash out into gift cards. It's a lot harder to track a gift card vs it going to a bank account. You then churn the gift card into cash at a discount rate using a gift card reselling website.
- colinmhayes 5y agoCan you buy gift cards without depositing the money into an account you control? Once it's in the account just buy crypto or whatever. I thought the gift card scams happen because credit card companies refuse to pay out to companies that get accused of scamming.
- aspenmayer 5y agoThere are sites and apps that sell gift cards for crypto, and converting fiat to crypto is already pretty easy.
- Too 5y agoScammer never deposit the money into any account, they put the credit card nr straight into the payment-form to buy gift-card.
- NortySpock 5y agoYeah, and you can follow the money all the way to the crypto wallet where it was converted to something harder to track or harder to revert transactions on...
- jakear 5y agoSure, but that still introduces at least one nameable real world entity that can officials can convince to stop processing transactions.
- heywire 5y agoAre they even processing a payment, or are they just capturing your account number to sell?
- jakear 5y agoGood point. I hate web3 as much as the next HN’er but “buy things and engage in recurring subscriptions via easily-canceled smart contracts without giving your full account details to a random third party” is a compelling proposition.
- notdang 5y agoyes, they're processing the payment and it goes through Stripe.
- er4hn 5y agoThere's a meta question here of the feedback loop. If I pay via coins / credit card the parking meter will tell me "Okay, you have XY minutes left." If I pay via the app, does the meter update as well? If I pay via the scam app... presumably there is no feedback loop, though people may not realize this. As a second order effect, wouldn't it make sense to investigate the domain and find the owners? Assuming they are paying some other party to put these stickers up the owners of the domain are the real problem. Telling residents to educate each other feels similar to the trope of you are a "victim of identity theft" when Equifax loses your personal details.
- dcdc123 5y agoI imagine they are using pay stations rather than meters. If that is the case I don't think people would ever look at it after paying via app.
- post_break 5y agoIt goes off your license plate. They scan it as they go. There is no meter.
- ents 5y agoMy cities app tells you time remaining and will send a notification, all via App.
- JoblessWonder 5y agoThe scam website is passportlab.xyz (Thanks for including the URL in the news article I guess?) Looks like it is registered with Google Domains. They use magic.link to send a URL. They are using Stripe to process payments. Any one of these could lead to the perpetrator. (It looks like Stripe might have shut them down already though.)
- post_break 5y agoI'm really surprised this hasn't happened sooner. Parking along the seawall in galveston used to be free. Now you pay with a smart meter. I saw it coming a mile away because all the smart meters had QR codes to download the app. Only takes a smart person to build a web app that looks similar, with a paypal link, ask what meter you're at, send an email that you're good for X minutes, etc.
- cortesoft 5y ago> with a paypal link Getting the money would be hard, and you would be easy to track. They would probably be better off just collecting the credit card info and selling it.
- post_break 5y agoSomeone found their stripe api key. All they would have to do is buy gift cards using the funds to wash it.
- Nextgrid 5y agoI'd be very surprised if a Stripe API key can be used to easily extract funds. I don't think you can directly buy gift cards/vouchers, and adding a new bank account is probably possible but would require manual verification which would blow up the attempt before it succeeds.
- post_break 5y agoSorry I should have been more clear. They are using stripe to process these payments, someone found their api key and reported them as fraud just now. They were using stripe with a bank account.
- dhosek 5y agoIf I were doing this, I would make a clone of the legitimate site, collect their info and pay for the parking on the real site, but save the credit card number for sale on the black market. I'd imagine one could find any number of sites where this could be hosted anonymously (or slip it into a hacked site's service). If you slap QR code stickers over legitimate ones it could be months before anyone noticed.
- mastazi 5y agoMaybe if they didn't have a "pay by app" scheme as seen in one of the pictures, people would be less likely to fall into this scheme. I'm not sure why government agencies should require people to download an app just to pay a parking fee instead of making things as frictionless as possible (I live in Australia, we have the same issue here)
- csydas 5y agoI think they just did the system backwards; the meter/parking placard should just have an etched and URL + branding for the app and the posts at parking spots should just be some UID for parking spots the system has registered. The main app/site should let you scan and auto-fill the data, but it'll wait for you to confirm you got it right. Scammers can still put fake stickers/posters/whatever up, but the QR scanner shouldn't trigger an action, it should just provide some static location data when it comes to some payment action. I think it's just a really poorly thought out system that didn't really research how other successful implementations of QR codes work.
- jjnoakes 5y agoMaybe I'm dense but couldn't an attacker just put a qr code sticker over every space that all pointed to their own space? Then everyone would be paying for the attacker's parking. I suppose this is harder to pull off with a lower benefit, and a higher chance of getting caught (i.e. fast acting law enforcement would know which car was in the free space). To mitigate this, you might need space numbers posted. This is easy to verify that each space is different. But at this point, why even have a QR code?
- mastazi 5y ago> should just have an etched and URL + branding for the app It should not be an app. Or there could be an app in addition to other methods of paying. Edit: the reason is accessibility and the fact that they are providing a public service https://news.ycombinator.com/item?id=29818536 https://news.ycombinator.com/item?id=29818536
- Ekaros 5y ago
- emptybottle 5y agoSome train parking lot systems would be vulnerable to this too. I've parked in lots where you enter the parking spot number and payment into a website. There is no physical confirmation, and it would be trivial to put a QR code on the parking information sign. Especially because typically people are walking into the station while paying, and not standing in front of the sign double checking the details. Insult to injury, the UI on the legit system is so bad and slow that scammers wouldn't even need to try to replicate what exists. Basically anything else would be an improvement.
- AlotOfReading 5y agoFrom a certain perspective, is this even morally wrong? The way these meters are always justified is that they help to shape behavior in urban areas and allocate limited space efficiently. It doesn't really matter who gets the money as long as people are paying. Moreover, if the city is in any way hurt by the loss of revenue there's already an inherent conflict of interest in city planning. Sure, scammers are bad, meter maids could incorrectly cite vehicles, and it's highly likely the scammers are doing more than just collecting the fees, but I don't find the basic premise that terrible.
- cma 5y agoIt is better for it to go to the common good than be burnt up in a sticker-over war that would eventually spill over into a violent territory war.
- megablast 5y agoIf they are charging a lot more for parking, this is a good. Parking is such a waste of space, and far too cheap.
- colinmhayes 5y agoHouston's got plenty of parking. Agree parking is generally too cheap, but their zoning laws went crazy with parking requirements and the spots aren't going away anytime soon.
- dahart 5y ago> Moreover, if the city is in any way hurt by the loss of revenue there's already an inherent conflict of interest in city planning. It’s strange to frame this as us vs them. Revenue lost by the city is coming out of your pocket. Don’t you have a vested interest in not having scammers drain your city’s income? I do. It definitely matters who gets the money, if you aren’t singularly focused on the behavioral results of drivers having to pay for parking. It’s also strange to use language suggesting the city couldn’t possibly be damaged by the loss of revenue. Enforcement efforts are trying to be net positive, cover their costs, and contribute any remainder to other public works.
- hanoz 5y agoI think the way QR codes have been used these last two years has left a lot of people with the impression that they're some kind of magical portal through the internet to some trustworthy source.
- ChrisMarshallNY 5y agoI agree. I made a comment about how ads are being "stickered."
- cozzyd 5y agoMy hobby: replacing QR codes for table menus at restaurants with rickrolls.
- bambax 5y agoThis is a great idea for pranks! Although real people who go to restaurants and don't spend their time on Reddit may not know what a rickroll is. It could be funnier to replace the menu with a slightly fake one and see what happens when people try to order things that don't exist (but could reasonably be thought to exist). Or outrageous items. Let's experiment.
- kerneloftruth 5y agoI love that -- thanks! I have a lot of sympathy for what motivated restaurants to adopt QR code menus, but as a patron I hate 'em. If this prank is done at scale it can help drive the restaurants back to real menus.
- cozzyd 5y agoTo be clear, this was a joke and I don't actually do this, though I'm also not a fan of qr menus (other than it's amusing watching tables of less tech savvy folk attempt to use them).
- frob 5y agoI've noticed a similar thing on rentable bikes in SF and NYC. People don't put the qr code over the existing bike one, but they put it near enough that your QR reader might pick it up by mistake and open up the order site for a pizza chain. Fortunately, when I'm using the bike app directly, these codes are ignored, but new users don't necessarily have the app yet.
- tzs 5y ago> Anyone who sees someone tampering with a pay station and is not a badged City of Houston employee should call 911. From the Houston police department's 911 information page [1]: > Call 9-1-1 to report a life or death emergency that requires an immediate response from police, fire, or ambulance personnel. ... > Do not use 9-1-1 for non-emergency situations -- this causes a delay in answering emergency calls. [1] https://www.houstontx.gov/police/contact/911.htm https://www.houstontx.gov/police/contact/911.htm
- Scoundreller 5y agoReminds me of when there was a police press release about 2 guys that broke into a parking garage and drove around the carts like an underground game of Mario Kart and stole one. Then I realized it was technically a government building and then it all made sense, because cars and bikes get stolen daily without a peep.
- 1123581321 5y agoNice. I am aware 911 should be used for some non-lethal but urgent situations now, but it was funny and frustrating figuring out which ones. For example, I’d call in a stalled car and get told by 911 to call non-emergency, and next time by non-emergency to call 911, in the same city. And non-emergency would sometimes tell me they dispatched someone and other times ask me what I thought should happen, again for the same problem. They must think they’re stuck with fools for constituents. :)
- monksy 5y ago> Anyone who sees someone tampering with a pay station and is not a badged City of Houston employee This is a crime in progress. That's why 911 is being recommended. (Yes this can vary from place ot place) 311 is about reporting that has happened non-crime related a time ago.. 911 is something that is/just happened. But yes, their messaging is terrible. I'm sure that they're just saying "don't call 911 because your sister is being a pain"
- MarvinYork 5y ago
- macNchz 5y agoThere's another QR-swapping scam running in NYC these days after the Citibike bike sharing system switched from typing a code at the dock to scanning a QR on the bike itself. People will take the barcode from one bike and put it on others, meaning when someone comes to unlock a bike, it actually unlocks the scammer's bike. By the time the victim realizes why the bike they're scanning won't unlock, the scammer has ridden away.
- LiquidSky 5y agoI thought you had to be within a certain distance of a dock to unlock. Are you saying the scammer is standing there at the dock waiting for a mark to come along and unknowingly unlock one for them?
- detaro 5y agoyes: https://apnews.com/article/lifestyle-nyc-state-wire-34d4ecd5dcd3821ddd6e9a308834a16b https://apnews.com/article/lifestyle-nyc-state-wire-34d4ecd5...
- spockz 5y agoHow does this even pay out? Do they use this “trick” to get a free ride and return the bike somewhere, do they steal the bike and keep it or do they sell it? Seems like a pretty handson and risky thing to do.
- kansface 5y agoI imagine they steal the bike.
- ChrisMarshallNY 5y agoI used to see these types of things, all the time, on the Long Island Railroad. The trains have these big posters, which are ads. They rotate, like, once a month, or so. Most of these ads have QR codes, to their sites. I often see that the QR code is a sticker, which means a scammer placed it over the real one.
- bellyfullofbac 5y agoI've thought of QR-encoding the URL to the Rick Roll video and "pranking" people trying to scan ads. Here come the righteous downvotes; to defend myself, I never went through with it, and they were ads to promote the city's iniative to invite the corrupt organization the International Olympic Committee so they could feast on our tax money.
- voakbasda 5y agoI think this would be a great way to educate the public about not trusting a QR code they find in public, without first double-checking it. Better than learning the hard way.
- flax 5y agoA couple of years ago, I was bored at REI while waiting for something and decided to actually scan the NFC on the packaging of some sealskinz gloves. To my surprise, the NFC tag was still writable. So, if you bought gloves at an REI in Bellevue Washington, and got rickrolled by the NFC packaging, that was me.
- mbg721 5y agoMoreover, why should there have to be a real one? A QR sticker that's placed reasonably neatly could blend in practically anywhere, now that people expect to see them.
- raymondh 5y agoCan anyone with an understanding of cash transfers work explain how this is possible? I cannot fathom how scammers get away with this. The police have the QR code, the URL, and the cash going out of one account into another. How is it possible that these people don't get caught and locked up immediately?
- kyletns 5y agoIf they set up payments through a provider outside the US I don't see how a local police force is going to be able to track those payments.
- Too 5y agoWouldn't that prompt the 3d-secure on payment? This would quickly raise some eyebrows.
- colinmhayes 5y agoThe website is probably in Russia I guess. Unless they catch someone putting the qr sticker on there's no link to the US.
- heywire 5y agoWhy wouldn’t they just capture the card number and sell it?
- bredren 5y agoDepending on the implementation, it could be they are doing that. And the stripe charges are just to keep the scheme going longer.
- Findecanor 5y agoIdentity theft. Accounts that receive money transfers for criminals have often been hijacked, or set up using hijacked credentials.
- Nextgrid 5y ago
- upofadown 5y agoIdentity management again... I guess you could have the city's public ID in your phone and then the city could just sign their QR codes ... or not in this case...
- peter303 5y agoA number of governments claim to have solved the problem in virtual licenses and vaccine passports. But I could guess ways to fake that too.
- joshellington 5y agoWow, they're using Stripe for payments. Here's their API key: pk_live_1vI9jQQVPUd9XXtXEXxRBMDL Just reported them through the generic Stripe contact form (all I could quickly find).
- bredren 5y agoMy first question was how they were collecting these "high risk" payments. In general, Stripe describes a 7-14 day payout schedule, but has shorter ones for many countries. Presumably it takes a fair amount of identity info to get to the 2 business day accelerated payout speed available to low-risk businesses in the US. https://stripe.com/docs/payouts#payout-schedule https://stripe.com/docs/payouts#payout-schedule
- Nextgrid 5y agoI would be really surprised if the scam is taken down in just 14 days (without the media's attention), so they're typically able to get a couple of payouts at least. Maybe this is just a single occurrence in a large scheme with lots more websites & separate payment providers.
- Nextgrid 5y agoIn these cases it might be better to commit it to a public GitHub repo which has real-time secret scanning and partnerships with a lot of providers to immediately invalidate detected secrets.
- site-packages1 5y agoI think this is the public one that's generally posted in the html for the client side stripe portion, not a secret.
- Doxin 5y agoYeah definitely. The public keys start with pk_, the private ones start with sk_.
- trevcanhuman 5y agoAnyone else thought the title said scanners instead of scammers? Was a little surprised when I reread the title.
- ejb999 5y agoI remember, many years ago, a story of someone who took a whole pile of blank deposit slips from the banks, and MICR encoded his account number along the bottom - when customers came in to make a deposit and the slip was scanned electronically, anything handwritten by the customer was over-ridden by the pre-printed account number - don't know how much they got away with, but clever none-the-less. If there is something to be exploited somewhere, someone will find it.
- JoblessWonder 5y agoThe scam website is passportlab.xyz (Thanks for including the URL in the news article... I guess?) Looks like it is registered with Google Domains. Hosted at 76.76.21.21 (vercel.com). They use magic.link to send a URL. They are using Stripe to process payments. Any one of these could lead to the perpetrator. But I doubt anyone will ever be arrested. (It looks like Stripe might have shut them down already though.)
- JoeAltmaier 5y agoThis is why we can't have nice things :( Maybe some indirect system would defeat this, where the real QR code only works if you have a cookie registered some other way - a phone app or something... and the fake one can't scrape that...
- shard 5y agoMy proposal would be to display the QR code on a screen, and generate a new QR code for every use.
- lucasverra 5y agoThat's at least 2 orders of magnitude more expensive. Maintaining a functioning screen on charge & online is no easy, even less outdoors
- xboxnolifes 5y agoMeters generally already have a screen for showing remaining time. And the meter would have to be online if you can pay from an app, unless the meter is now just a pole with a sticker and everything including remaining time in in the app (Which is not the case for these meters).
- shard 5y agoNow that meters are moving from purely mechanical to electronic devices, the extra cost of the display and connectivity can be reduced by having a central pay station for a row of parking spaces. I believe I've seen some form of central pay station on some streets.
- rocqua 5y agoThe problem is probably solvable if your customers already have the correct app. The issue is if your customers are using the QR code to install your app. A scammer can change that QR code and hijack the customer's entire experience.
- meatroll 5y agoI replace public QR codes with stickers to meatspin.com I did it for the lulz but now I think it may be a public service, getting people to blindly trust these things a little less
- vanous 5y agoYou should put the NSFW at least here on HN.
- caf 5y ago..and then people in the year 2092 will wonder "why is it a specific crime punishable by 3 years imprisonment to deface a parking meter?"
- iso1631 5y agoHopefully in the year 2092 parking meters won't exist
- diebeforei485 5y agoThis is a real issue with QR codes. Some apps have implemented better options, including - crucially - the ability to revoke (disable) a code. Snapchat had Snapcodes which had some of these features built in for privacy.
- disillusioned 5y agoNothing about that would solve this, though. The QR code standard is open, and these are just stickers produced that generate a link for any QR code reader. There's nothing to revoke, and no central power that sits in between to perform said revocation.
- RinTohsaka 5y agoRight. You'd have to revoke the URL the QR code points too, not the QR code itself.
- redleader55 5y agoI think there are several issues with the situation at hand: 1. The city should've provided a QR code payment solution along with an app to scan and vet those QR codes. 2. The parking app that includes a QR code scanner, only needs to interpret the information in the QR code (eg. location id + parking spot id), it doesn't need a full URL. In China QR codes are ubiquitous. You can find them on menus in restaurants, when paying a cabbie for the ride, or a guy in the fresh market for vegetables, you can even buy toilet paper in a public toilet in the middle of the night using a QR code. The reason why there is no QR code fraud is because the payment is done through 1-2 apps which are able to detect fraudulent QR codes.
- Too 5y agoNone of that would not help if scammer puts a sticker on top of all you just mentioned, that says: "To pay, scan this code with your camera app". It would only deter people who already have the app since before, which is already the case, i assume most people just enter the Parking zone number by reading it from afar or using GPS from app, not by walking up to the machine and scan it.
- dagmx 5y agoThis is one of the benefits of Apple's App Clip Codes (https://developer.apple.com/design/human-interface-guidelines/app-clips/overview/app-clip-codes/ https://developer.apple.com/design/human-interface-guideline...) They have to link back to an app on the app store, so they're more trustworthy. Obviously that can be construed as a down side as well, and the app store isn't immune to scams, but it does give one layer of effective gating