14 ms·
I'm a security engineer and I still almost got scammed
- softwarebeware 4y agoThis was a great read. I think the biggest takeaway I had was how some banks and credit card companies themselves are not doing a great job at building trustworthy systems. That leads consumers into treating things that seem gray, like confirmation code texts coming from unknown numbers, as credible.
- paxys 4y agoI'm not a security engineer, but here's the easiest way to prevent 99% of scams – never pick up the phone. If it is urgent they can leave a voice mail, and you can call back by looking up the official number.
- nokya 4y agoIf one of my SEs came to me with this story, I'd be quite worried as his manager. The post he wrote seems to be more therapeutic than instructive...
- 46Bit 4y ago> The internet tells me that caller IDs are easy to spoof, which I didn’t know I really think that security engineers should know this.
- fortran77 4y agoI thought this was a new, subtle, clever scam. It wasn't. I was very surprised he's a "security engineer." Still, I'm glad he's not embarrassed to share his story, to help others be more aware.
- ecf 4y agoModern security engineering is a lot like marketing where people “work” by bouncing around between tools that provide “actionable insights”. I immediately tune out when anyone describes themselves as a security engineer.
- usrn 4y agoToo many "security engineers" trust telcos way too much.
- ransom1538 4y agoAnddd.. if you are into anti-scam https://aff.419eater.com/ https://aff.419eater.com/
- rhexs 4y agoI think the only qualification for "security engineer" these days is changing your LinkedIn job description to "security engineer". Unlike SWEs, there isn't really any sort of standard leetcode bar for them, which is both a pro and a con. Lot of snake oil in the field at the moment.
- nonameiguess 4y agoThat seems the opposite of true. They have pretty standardized certifications in the field. CISSP is much more consistent and predictable and known than random sampling of leetcode questions. Of course, you don't need to score 100% on the exam to pass it, and not being familiar with the content of the exam, I'm not vouching for it or anything. But it is effectively the equivalent of something like a CPA or CFA that Software Engineering has no analog of.
- qzx_pierri 4y agoAs someone who recently left a security job at a very prestigious and well known organization.. The person you're replying to isn't wrong. Certifications only prove that you took the time to memorize a set of concepts. > CISSP is much more consistent and predictable and known than random sampling of leetcode questions Even the CISSP is just a test of memorization - The ISC2 cert prep book is 10 miles long, but only about 5 feet deep (if that makes any sense). Being a good security engineer comes with experience and knowledge of basic scams such as caller ID spoofing (something I did to my friends as a bored 6th grader). Being a good security engineer is having a keen eye for small changes and being skeptical about EVERYTHING. Any security engineer worth their salt would never discuss anything containing PII on an inbound phone call.
- antonvs 4y ago> Any security engineer worth their salt would never discuss anything containing PII on an inbound phone call. Yeah. Clearly "security" means something different to him than it does to us.
- nobody9999 4y ago
- AnIdiotOnTheNet 4y agoA corollary to Sturgeon's Law: 90% of any given field is shit at their job. I've met a lot of "Security Engineers" and I can assure you the pattern holds. Then again, even the other 10% of any given field that is actually good at what they do still fucks up occasionally, so maybe we needn't judge too harshly.
- HL33tibCe7 4y agoI don't think it's fair to claim that the author is "shit at his job" because he doesn't know some (rather unintuitive and unexpected) trivia about how phone ID works. There are plenty of different roles in security engineering, many of which would never need to be concerned about this.
- carlmr 4y agoAlso I think just his openness in admitting a mistake he could hide in shame is a sign that he understands his job. While this is more psychology than technology, that's very important in social engineering.
- giaour 4y agoEveryone in the US with a cell phone is getting inundated these days with spam texts and calls with fake caller ID. It's almost inconceivable that someone with an American cell phone wouldn't know that phone ID is a lie, which is I think where some of the incredulity from other commenters is coming from. But I believe the author is from the UK, where the spam situation might not be so dire?
- dwighttk 4y agoHuh. I get a bunch of spam calls I ignore, but I don’t know how I’d know that any of the caller ID is fake
- giaour 4y agoThe recent surge in spam texts that show as having been sent by the recipient[0] has driven this point home for a lot of mobile phone users. For me, the fact that caller ID is fake was made evident when a spammer used my number as their origin ID for a wave of spam calls and texts, and I got ~100 voice mails and texts the next day kindly asking me to eat shit and die. Verizon support said that there was nothing they could do, that it was happening left and right, and that I was in no way legally or financially responsible for any of the messages purporting to be from me. This was in 2020, and the unreliability of long code origin ID numbers has come up frequently in my work as a security engineer for the past few years. [0]: https://www.nytimes.com/2022/03/30/business/spam-texts-verizon.html https://www.nytimes.com/2022/03/30/business/spam-texts-veriz...
- lr4444lr 4y agoWhat's weird is, this is the sort of thing that many (not all) average people know because it materially happens to them. It doesn't even rise to the level of elementary professional knowledge that you'd expect of all but only of professionals.
- duxup 4y agoI'm imagining this guy giving advice to someone that includes validating by caller id or something ... scary.
- leephillips 4y agoAfter encountering everything from a taxi driver in NYC who didn’t know where Grand Central Station was, to a recently hired physics professor with a PhD (Univ. Cal. Davis) who didn’t know what a partial derivative was, someone having a particular job title means zero to me. It just means that someone, for some reason, is paying the person to do <job title>. But this guy didn’t do too badly, after all.
- tremon 4y agoa taxi driver in NYC who didn’t know where Grand Central Station was You mean the post office?
- leephillips 4y agoNo, I mean the largest train station in the world, the central rail hub of the city, a famous landmark and tourist attraction. The official name is Grand Central Terminal, but nobody calls it that (usually just “Grand Central”).
- DFHippie 4y agoI was curious about the "largest train station in the world" claim. I figured there would be bigger ones by now in India, say, or China. Sure enough, there are different metrics by which different stations can claim to be the largest. Nagoya Station in Japan, for instance, is the largest in floor area. Shinjuku Station, also in Japan, is the busiest by daily traffic. The Gare Du Nord in Paris is the second busiest by this metric. Apparently Grand Central is the biggest in platform capacity. Anyway, back to the point.
- leephillips 4y agoWhat about volume? Grand Central has a high ceiling.
- softwarebeware 4y agoThis is why I love Hacker News lol
- csharpminor 4y agoOne thing that many people don’t know is that SMS caller IDs are also being spoofed more frequently. In the article the author mentions noticing that the authentication code came from a number the bank didn’t ever use. Sophisticated scammers can spoof your bank’s phone number and send a message that appears in a thread alongside other legitimate SMS from the bank. This is harder to do than caller ID spoofing, but has become more prevalent recently.
- jeroenhd 4y agoIt all depends on what kind of security engineer this person is. The author writes about computer network attacks, tracking, and privacy violations. If their expertise is in preventing web application attacks, detecting fraudulent operations in the inter-bank payment systems or in finding signs of compromise in a corporate network, there's no reason for them to know about the intricacies of SIP and SS7 and the many faults of the international/US phone network when it comes to trust and abuse. Really, "security engineer" is as vague a term as "programmer". Web programmers are programmers yet they don't necessarily understand the layout of virtual memory or the way the kernel interacts with userland programs, something many other programmers would consider essential for their jobs. A kernel programmer couldn't give two hoots about how Chrome's CSS engine works, but the vast majority of modern programmers probably do. I've had lectures in university on natural language processing and data structures that were slowed down because the lecturer couldn't get the beamer to work right with his Macbook. You can't expect someone to know everything, even if it's in their apparent area of expertise. I'd go so far as to say that any security engineer worth their salt will admit that they too are vulnerable to being scammed under the right circumstances and that anyone pretending to be unscammable is severely overestimating their abilities.
- lupire 4y agoRegardless of your professional training, everyone gets spam calls from spoofed caller ID (that copy your phone area code and exchange) every week.
- wildrhythms 4y agoWhat utopian world does a security researcher live in where spam calls and spoofed numbers don't exist on a daily basis?
- jeroenhd 4y agoI've never had a spam call in my entire life, maybe he just has a non-American phone number?
- dogman144 4y agoNot that I disagree, but I think the majority of sec engs do not deal with telephony or related fraud directly. In companies where fraud with caller ID and responding to it matters, that's often tasked to a fraud team dealing with account takeovers or a user onboarding team that offloads verification to a vendor like Persona -> not a security engineering team. However, I think it's common knowledge that inbound identifiers like IPs, user agents can be faked and aren't great technical indicators to anchor detections on for longer than an active incident. That intuition should extend to caller ID IMO, if they didn't know it already.
- xyst 4y agoI know this because I have done it in the past to mess with my parents, family, and friends (ie, display 666-666-6666 on the caller id)
- staticassertion 4y agoSecurity engineers are basically expected to know everything. It's part of why I enjoy the work. But it's also impossible. "Understand the security implications of every nuanced technology decision" is not tractable, so we pick the ones we can and specialize. POTS is rarely of interest to a security organization. You have very few levers to pull even if you do consider it a threat, since it's just fundamentally an awful system, and you can't tell people "don't use telephones". At best you can train people, but your concern is probably phishing via email. Only a few people, at the company level, are at risk in terms of this sort of attack, compared to everyone being at risk (with regards to the company) from phishing emails. So a lot of people just don't really think about it. Security engineers might hand wavingly say "phone numbers can be spoofed" but I'd bet the percentage of seceng that know how that works is very small.
- neoCrimeLabs 4y agoIt's true, being a successful information security engineer requires a very diverse understanding of technology and psychology. Not one person understands all the technology in existence, and no one person ever will. Also engineers come in different levels of experience. Just because someone doesn't have experience in specific technology doesn't exclude them from being an engineer in a specific field.
- softwarebeware 4y agoIt was refreshing to read an honest post. If more people were willing to admit they don't know something, the world would be an infinitely better place.
- fullstop 4y ago> I’m not sure where the 2 missed calls from my bank’s real phone number came from. This sort of thing is incredibly easy to forge these days.
- senectus1 4y agoI've recently noticed that I reflexively answer my phone with "MyName speaking", it occurred to me that this is bad security practice. Any suggestion on how I should politely and professionally answer a call without giving away my identity?
- jrootabega 4y agoFirst name only isn't that bad, right?
- krageon 4y ago> Any suggestion on how I should politely and professionally answer a call without giving away my identity? I use "hello". It's pretty rude compared to how I was raised, but it's also the only way to not give scam calls the ammo they need to mess with me. So I can live with rude.
- ceejayoz 4y agoLet it go to voicemail, and have your voicemail greeting say "please send me an email instead".
- mattw2121 4y agoHello?
- mikequinlan 4y agoMany people nowadays just answer 'Hello'. I do that and if I don't get a response after a few seconds I hang up.
- vegetablepotpie 4y agoI’ve taken up the practice of just not answering the phone. Nothing good ever comes of it. If it’s important, they’ll leave a voice mail and I can call them back.
- wintermutestwin 4y agoYes, but then they do the same and it is endless phone tag which usually ends in "you can email me at blaa." The telephone is broken.
- anonsec123 4y agoJust being a security engineer doesn't instill you with a defensive or paranoid mindset. I work with security analysts who use TAILS to browse random websites and security engineers who torrent cracked software and install whatever they find directly on their baremetal PC/laptop.
- shkkmo 4y agoI would hope that a security engineer would keep up enough with news about security issues to be aware how easy it is to spoof numbers for calls and texts.
- BeefWellington 4y agoThere are people in all manner of jobs that are just working a job and don't have a significant interest in learning all they can about their area of employment. IME security has a lot of people who see it as a hot new thing but don't actually invest their time and attention into maintaining an appropriate level of awareness.
- shkkmo 4y agoPhone calls are one of the primary means of communication. If you aren't aware of how it can be compromised, you are not capable of adequately assessing security. It is not like the spoofibility of phone numbers is some security industry specific news. It gets talked about all the time outside of tech given the prevalence of spam calls.
- bennyp101 4y agoSeems like this is more a story type thing?
- vegai_ 4y agoWhen I get off work, I want to think about silly computer problems as little as possible. Perhaps the same applies to security engineers.
- neogodless 4y agoThought perhaps this was posted previously, but it's just a very similar story. https://news.ycombinator.com/item?id=30869427 https://news.ycombinator.com/item?id=30869427 "I'm a scam prevention expert and I got scammed" (544 comments 20 days ago)
- erwincoumans 4y agoIt is too long-winded. Could the scam story be a scam itself?
- perydell 4y agoI also thought of this prior post. I believe it is the same scam and written up by someone also claiming to be a security researcher. It seems too on the nose to be a coincidence.
- post_break 4y agoYeah I thought this was the same repost. It's very similar.
- scott_s 4y agoBasically the same scenario as this HN submission: "I'm a scam prevention expert and I got scammed", https://news.ycombinator.com/item?id=30869427 https://news.ycombinator.com/item?id=30869427
- vasco 4y agoIf your card is stolen and you become a victim of fraud, and they manage to take money from your account, and your bank already knows its fraud, there's no urgency on your end. You'll get your money back. I'd go as far as saying that if the bank genuinely wants you to decide fast, it's not to protect you. It's to protect itself. Shenanigans about "do it fast or they'll take more" are bullshit always. The bank is on the hook, not you. So never do things in a rush, take your time to verify yourself that money indeed disappeared. There. is. no. urgency. Sense of urgency is one of the best ways to make people do bad decisions. Salespeople use it, scammers use it. Nobody who is trying to be helpful will come with a story "that needs to be fixed now!!!". If you still want to be safe, and you use a debit card, have 2 accounts. One with the bulk of your money without a card associated with it. One with the card associated with it and no more than whatever you spend in a week. If you use a credit card, it totally doesn't matter, it's the banks money, not yours that they'd steal. So whenever you find yourself in a situation where someone wants you to decide something fast that you didn't know about and isn't a direct threat to your life, don't do it. Think about it first. It's impossible to keep up with all the scams, but if you stop to think and never take rash decisions you don't have to. Slow is safe.
- skeeter2020 4y agoI'm well aware of the (lack of true) financial implications but I still get the urgency and need to speed up because of the violation and shock that someone is impersonating me RIGHT NOW! It feels similar to a physical threat, or enough so that our bodies react the same way. It is really hard to develop control unless you're exposed to this situation, so I like your strict yet general rule to (a) classify the situation, (b) slow down. Even enough time for 10 deep breaths is likely enough to get you centered and thinking clearly.
- toraway1234 4y ago
- kube-system 4y agoYep. In the US, you are not liable for any fraudulent transactions reported within 60 days. You can easily wait until you get your next statement.
- smbv 4y agoDupe: https://news.ycombinator.com/item?id=31100336 https://news.ycombinator.com/item?id=31100336
- alias_neo 4y ago> Nothing the bank might want to talk about could be urgent enough to interrupt an unseasonably sunny March afternoon. Wrong. Some banks, and with certain account types, the bank will absolutely make a courtesy call to you if something unusual is happening. I had a call from my bank while spending a few hundred on cocktails in Bali (I'm from London), I hadn't used my card yet on that trip as I'd taken cash. They also called me to check a payment into my account with an "unusual" reference; a joke from a friend returning the money he owed for a holiday I paid for, but which made it look like he was paying me for "special services". They called me to query a payment at a home furniture store for a couple thousand pounds in a city ~300 miles from where I live only hours after I'd used the card near home; I'd driven to this particular store to check out the furniture. If you're not sure, the _real_ bank will suggest you hang up and call their number found on your card or their website (or in your contacts list, where I keep it) and will never pressure you to answer or provide them information, and they'll NEVER, EVER ask you to read a security code out to them sent to your phone, or using your banking app. EDIT: To further clarify; my particular bank's app, has, on rotation, a series of warnings, displayed each time I log in, saying things like "BEWARE; if someone [calls/texts/etc] asking/telling you to do [XYZ] ...", e.g. to get this code or that code, or do something else in this app, you're being scammed, "WE WILL NEVER ASK YOU FOR [XYZ]...".
- jrochkind1 4y agoI'm not at all confident that the real bank will never actually ask for you to verbally read a security code texted to you. This is how little I trust bank's security practices. Here's a comment from a similar post last month, where the commenter believes the legit bank asked for a verbal confirmation of security code: https://news.ycombinator.com/item?id=30875233 https://news.ycombinator.com/item?id=30875233 (I suppose it's possible the commenter was actually interacting with a scammer there and still doesn't realize it?)
- alias_neo 4y ago> I told him, the 2FA message literally says to never give this number out to anyone He was 100% being scammed.
- jrochkind1 4y agoPart of this comes indeed from not trusting the banks -- like, I know the banks do irrational insecure things, and I also don't trust that if I don't do exactly what they say they will actually cover me in case of fraud (which we know does happen, a lot, now). Like, let's say I insisted on hanging up and calling the number on the back of my phone -- are there any cases that would be disastrous for me, would end up in me losing money, and I really should have stayed on the phone with the person who called me, who really was a non-fraudulent representative? I'm not confident there are not.
- wccrawford 4y agoI think you mean "back of your card". I honestly believe that there are no cases for that on a credit card. On a debit card, that might be different. This is why I never use my debit card for purchases.
- deleted 4y ago[deleted]
- briHass 4y agoThis is the second very similar report on HN where the end-goal was ApplePay. There must be something poorly done in their card linking/payment process that hackers are targetting. I don't use it, so I'm not familiar. Collectively, we software engineers that have security focus, have done a piss-poor job with 2FA. Users should've been trained from day-one that 2FA codes sent to their email or SMS should never, EVER, be repeated back to a human. All the additional text sent with the code should clearly and emphatically state that this number is between you and a website that you are reasonably certain represents a secured entity and that you explicitly requested during a login flow. It's like the combination to a safe: that code is between you and the dial on the safe, if it ever verbally leaves your mouth, you're doing something wrong. Any orgs that use 2FA codes to authenticate a user to a CSR are screwing it up for everyone. Don't do that: you should be able to mutually authenticate using shared knowledge that a hacker isn't likely to have (not an address, FFS), like the previous transactions thing the OP requested. 2FA codes are for computers only.
- ant6n 4y agoWhat pisses me off to no end in Europe is that some banking systems require, in order to do a credit card payment, to provide the online bank account password and online bank account 2fa generated transaction code — requiring that both be entered as part of the payment process on any merchants website. It’s so goddamn stupid I can’t believe this exists. It’s so easy to fake this and use some sort of man in the middle attack to transfer all money away from an account. Plus it teaches ppl that it’s okay to enter one’s online banking credentials one-time generated transaction codes into random websites selling u random crap for 3€… I don’t understand security researchers. Is it all just a bunch of hooey they sell or what?
- eythian 4y ago> It’s so goddamn stupid I can’t believe this exists. It’s so easy to fake this and use some sort of man in the middle attack to transfer all money away from an account An MitM attack is significantly harder than "I have your CC number and I'll use it with no authentication", therefore it does increase the difficulty for fraud. Though I haven't seen a requirement to enter the bank's password, my one requires me to confirm the transaction by opening the credit card provider's app on my phone which isn't vulnerable in the way you're describing.
- herf 4y ago2FA should never be vague - it should say "Don't give this code to anyone." People are getting scammed all the time this way.
- skeeter2020 4y agoI appreciate that the OP calls out his bias towards bank mismanagement and "the system". Scammers (like this one) are using the stereotype to run their scams. Are bank systems often disjointed bureaucracies and less than stellar examples of best practices? Absolutely, but scams are so common now I believe it's time that we accept them as the default conclusion until proven otherwise.
- bombcar 4y agoYou see this over and over again in the crypto space; scammers are very good at imitation the "group" and using that to their advantage.
- _8j50 4y agoI work with phishing content on a daily basis, ashamed to say I fell for a scam on a dating app once, but I was careful enough to use a burner credit card, cancelled it right away with no loss to myself. I don't think I can fend off a well planned scam or phish no matter how careful I am. At the end of the day I have to be a normal human being with predictable weaknesses and psychological vulnerabilities. Instead, I try to rely on security controls that don't rely on my psychological hardening.
- projektfu 4y agoI got a call from a bank and they said they wanted to verify my identity. I said, all due respect but you called me. I need to verify your identity. They sounded offended but told me how to continue the discussion when I called back. It was a legitimate call. I was pretty annoyed that they didn't follow good identity practices by encouraging their customers to trust people who could be scamming them.
- mnw21cam 4y agoI used to get a call every two months from a service I actually use, to arrange their next delivery. The first thing they ask is for my date of birth and address so I can pass their security checks. Each time, there has been a really awkward silence for a few seconds when my response is "Nope".
- marcus_holmes 4y ago"all due respect" in this case being none.
- ed25519FUUU 4y agoThe problem is definitely still the security of banks. They regularly call YOU and tell you that you have to verify yourself. It’s an incredibly stupid system.
- nonrandomstring 4y agoWe already covered this, but advice distilled from earlier comments bears repeating; One special class of vulnerable targets is security experts, and top ranks. I remind my students that "pride comes before a fall" and nobody is immune. While doing some training for <BIG INTERNATIONAL BANK> someone told me they call it the "cocks problem". It's the handful of 7 figure salary high flyers that get regularly pwned and cause grief for everybody else, because they are "too cocky". Lowly secretaries and desk staff are much harder marks. The more training you give to people who think they're above it the worse they get. It has to be pitched as participatory advice, as an invitation to co-create a secure practice. We saw this cavalier attitude just the other day with Boris Johnson [0]. I bet Johnson was told time and again to use equipment that had been checked by his security detail. And I still cringe thinking of this one [1]. I suggest there's no correlation between domain knowledge and behavioural invulnerability. Good security posture is a mind-set. I also think it's a very strange combination of contradictory qualities (or attitudes you can be trained to adopt) that are hard to describe, such as high conscientiousness and humility mixed with utterly cynical disrespect for "authority", high openness but brutally meticulous self-checking and introspection. And definitely, never call yourself an 'expert'. [0] https://news.ycombinator.com/item?id=31075558 https://news.ycombinator.com/item?id=31075558 [1] https://www.arrse.co.uk/community/threads/77-bde-twitter-feed-hacked.290788/ https://www.arrse.co.uk/community/threads/77-bde-twitter-fee...
- resoluteteeth 4y agoIt sort of reminds me of this: https://driving.ca/auto-news/news/why-advanced-driver-training-makes-teens-worse-drivers https://driving.ca/auto-news/news/why-advanced-driver-traini... I guess the common factor is that the most important thing is to be careful and follow the proper procedure to not get caught in a problematic situation in the first place, not to be overconfident and assume you are safe because you can handle any situation with your knowledge or skills.
- nonrandomstring 4y ago> procedure to not get caught in a problematic situation in the first place Totally. I saw this Krav Maga instructor say: "Now. I'm going to tell you one of the most effective self defence moves known in any martial art... run away!"
- liendolucas 4y agoQuestion: Why banks do not implement bait/decoy codes for people that are aware they are being part of a scam? Wouldn't this provide them at least more information about the scammer? With all the technology that's available, why is not possible to let the scammer believe that he/she is doing a real transaction but behind scenes they are being monitored/traced? I'm asking out of my ignorance on the subject.
- lupire 4y agoFar too much complexity and risk for the 1% of customers who might care. and for no benefit -- banks don't care about scammers.
- jve 4y agoUh, I'v got similar calls. Here you can watch video for taking down one of these call centers by police, not so long ago: https://www.delfi.lv/news/national/criminal/video-latvija-aiztur-82-viltus-brokerus-kas-katru-menesi-izkrapusi-3-miljonus-eiro.d?id=54192518 https://www.delfi.lv/news/national/criminal/video-latvija-ai...
- koala_man 4y ago> I got through to the bank, but they couldn’t work out why they had called me. The bank said "we have no record of calling you" and it didn't stop there?
- rmbyrro 4y agoAny reasonable bank would freeze the card before even contacting you. If they want a confirmation, they'd rather use an automated method. Like send an SMS: "Did you spend $X on Merchant, Inc? Reply with Yes or No". They can't afford a human calling you for every fraud suspicion.
- Toreno96 4y agoThe article references another one of the author's articles: https://robertheaton.com/2019/06/24/i-was-7-words-away-from-being-spear-phished/ https://robertheaton.com/2019/06/24/i-was-7-words-away-from-... I find it quite amusing that the scam used the domain `people.ds.cam.ac.uk`, which contains `s.cam`.
- deleted 4y ago[deleted]
- scoot 4y agoSimilar to another recent post: "I'm a scam prevention expert and I got scammed" https://news.ycombinator.com/item?id=30869427 https://news.ycombinator.com/item?id=30869427
- nottorp 4y agoUS Banks are so bad that this scenario would be believable? Any security problem where I am would get fixed either via resets on pre established channels or via a visit to the actual bank with ID verification.
- awinter-py 4y ago> A lot of the credit that I gave Barry came from my lack of faith in my bank’s systems and security. ... Insecure business practices often don’t stand out as a sign of a con; they just look like another boneheaded but authentic policy. ^ THIS. your bank is training you to get phished. your health insurance, by leaving fake-urgent voicemails that require miserable phone tree navigation when you call back, and by having a million different numbers which resolve to 'scam or at least spam' aggregator sites when you google them, is teaching you to get phished. my health insurance has a process which involves calling me and asking for a bunch of personal information. I called them back at a known number to ask if this was their number and they didn't know. I called three agents and they gave me three different answers. One said it was a 'system error that will be resolved in 24 hours'. Another said it was fake, don't trust it. A third called the number while I was on hold and assessed it as 'probably fine'. teach someone to get phished and they're phished for the rest of their life never accept inbound calls
- kcplate 4y ago> never accept inbound calls I’ll sometimes accept them, but I will tell callers that I will reach out independently to the institution via a main number to continue the conversation Generally causes the old “the main number won’t be able to forward you to me…”.
- evandale 4y ago>A third called the number while I was on hold and assessed it as 'probably fine' This blows me away. Probably fine? That's the worst possible answer IMO.
- awinter-py 4y agoyeah it's not great. agent 3 said 'they're not asking for your insurance ID # so it's probably safe'
- DFHippie 4y ago> teach someone to get phished and they're phished for the rest of their life This is a keeper.
- xyst 4y agoIn this day and age, how do people still fall for this? This isn't the old days where you would get a physical paper statement in the mail every 30 days and rely on your bank to call you for potentially fraudulent purchases. You have instant access to your financial information. You can easily see "pending" and "posted" charges on your credit accounts without a third party.
- furyofantares 4y agoI firmly believe that anyone can get scammed if they're caught on a bad day and the scammers happen to get lucky with some details or approach that happens to match something the target is inclined to believe. I don't believe scams are typically designed to maximize success rate per scam; they're designed to cast a very wide net and get lucky on a few targets.
- staticassertion 4y agoHere's the thing. Phones fucking suck. Anyone can call anyone, and that's insane. It's like the phone book, it's a dated concept that just does not scale. Phone numbers as a proxy for "who is calling me" is terrible. Numbers change, numbers can be spoofed, numbers can be stolen. All identification that happens via a phone is fundamentally bad and it is only getting worse. The trick is, don't use phones. Really. Block every number that isn't someone you know, for starters. If someone calls you and it's a bank ask them to contact you via email, and only use the phone to confirm what has already been discussed via email - for example, if you are performing a wire transfer, initiate that via email, and if you confirm information via the phone never offer any information, just validate what they say. This issue is so common and pervasive that, as the author demonstrates, we just assume everything is horribly broken and when something is suspicious we just think "well, everything's horrible, so why wouldn't this be horrible?". "Silly but plausible" - this is the cost of security theater. I have to jump through hilariously stupid loops sometimes. But ultimately I blame phones being used as proxies for identity.
- staticassertion 4y agohttps://www.youtube.com/watch?v=YIWV5fSaUB8 https://www.youtube.com/watch?v=YIWV5fSaUB8 Jim Browning is an expert in this area and is sort of famous for his "scamming the scammers" videos where he hacks, tricks, annoys, or otherwise scams scammers. In the linked video he talks about how he was tricked into deleting his account. These things can happen to anyone, even experts.
- dr_orpheus 4y agoI believe I saw this exact same scam on another recent Hacker News article. Same premise of "I'm from the bank and you are a victim of fraud and I need to deactivate your Apple pay but I am actually activating my own Apply pay with your card" Also had a similar title along the lines of "I give presentations on scams and I still got scammed"
- cameronh90 4y agoI almost got scammed by a SMS that woke me up. Local couriers often send links by SMS when an international package needs customs duty paid, and they often shorten URLs due to SMS limits. So they might send a URL like couri.er/1ea6dz. Often the payment sites look a little dodgy too, frequently just an un-themed Worldpay form. Unfortunately I was expecting an international package and an SMS woke me up saying delivery would happen today provided I pay the customs duty. I luckily had gained my senses enough by the time the page had loaded to double check everything, but it could have got me. When the legit request to pay customs duty came through, it didn't look all that different...
- causality0 4y agoI made a note to check my account when I got home It would take more than thirty seconds to go online and check the account? “I’m calling about some suspicious transactions on your account ending in 1234. Is this a good time to talk?” I don't know how it works there, but my bank's fraud alert call is automated and exactly the same every time. “I’d like to enable enhanced security on your account, but I’ll need to text you a confirmation code first. Is that OK?” Do banks do that there? Mine won't make any kind of account changes unless I show up in person with ID. Barry couldn’t use my card to buy anything online because my bank sends me a one-time verification code whenever I use the card on a new website. This is great. All banks should do that.
- smm11 4y agoI got the same call, but it really was my bank! Hey, wait a second.
- mongol 4y agoI once was called by my bank on a Sunday. They told me someone had found my credit card at a parking payment machine where I parked approximately 10 minutes earlier. That was a legit and reasonably urgent call. I could go and get it from the couple that found it at a nearby café.
- lamontcg 4y ago"Yeah, I *69'd you. I never pick up my phone." -- Tyler Durden, Fight Club. I'd also logon to the bank website first to look at recent transactions myself so that I "do my own research" before talking to a person at the bank. Most often the fraud check is something like an apple hardware purchase that I made months ago which only just went through after I got the front of the waiting list. I'd want to debug that stuff myself first. If I'm out doing something and a text/VM comes in while I'm on thumbs I'll happily wait until later that night to debug the problem. Like the top thread here says, there's no urgency. Really helps to be an introvert where you very actively don't want to call someone up and chat on the phone about shit, so you first seek to avoid having to talk to anyone in person, and then have all the information you can acquire ready first to keep the phone call as short as possible.
- RadixDLT 4y ago"security expert" should be taken with a grain of salt
- lr1970 4y agoVirtually identical story of the scam with ApplePay was here 3 weeks ago. The victim was a scam prevention expert: https://news.ycombinator.com/item?id=30869427 https://news.ycombinator.com/item?id=30869427 EDIT: silly typos
- lupire 4y ago"expert" as in random blogger.
- KSPAtlas 4y agoCan this be a case of survivorship bias, but flipped?
- SunlightEdge 4y agoI have a dumb fraud story. A fraudster called me up (I knew it was a fraudster right away). I played along as he said there had been some fraudulent activity on my account - payments from random locations etc.etc. The crux was that he wanted to send me a verification code from PayPal. This is where I was dumb. I assumed it was from a fake PayPal messaging system and they knew the number already. When they asked me to repeat it back to them I pretended to be dumb and gave a fake number back, repeatedly. I at first thought they knew the number. It then hit me that they didn't know the number and were actually trying to break into my PayPal account. I was so dumb! Still no bad outcome other than me looking stupid.
- tpoacher 4y agoI do sympathise with how the whole "I dont want to call back and get placed in a queue with elevator music" was a big factor in the scam almost being successful here. "Hopefully" enough people get scammed at such organisations, such that having the ability to easily contact a human at the company becomes a valid selling point, and lack of it an actual pain point for the company, so that pointy-haired CEOs start to appreciate it again. I had to add my wife's name to our gas bill recently. There was no option to do this from the online system. I had to call 4-5 times to get this fixed. Each time I had to wait about 50 minutes before getting to a human at the other end.