15 ms·
> The internet tells me that caller IDs are easy to spoof, which I didn’t know I really think that security engineers should know this.
by 46Bit 4y ago
> The internet tells me that caller IDs are easy to spoof, which I didn’t know
I really think that security engineers should know this.
- fortran77 4y agoI thought this was a new, subtle, clever scam. It wasn't. I was very surprised he's a "security engineer." Still, I'm glad he's not embarrassed to share his story, to help others be more aware.
- ecf 4y agoModern security engineering is a lot like marketing where people “work” by bouncing around between tools that provide “actionable insights”. I immediately tune out when anyone describes themselves as a security engineer.
- usrn 4y agoToo many "security engineers" trust telcos way too much.
- ransom1538 4y agoAnddd.. if you are into anti-scam https://aff.419eater.com/ https://aff.419eater.com/
- rhexs 4y agoI think the only qualification for "security engineer" these days is changing your LinkedIn job description to "security engineer". Unlike SWEs, there isn't really any sort of standard leetcode bar for them, which is both a pro and a con. Lot of snake oil in the field at the moment.
- nonameiguess 4y agoThat seems the opposite of true. They have pretty standardized certifications in the field. CISSP is much more consistent and predictable and known than random sampling of leetcode questions. Of course, you don't need to score 100% on the exam to pass it, and not being familiar with the content of the exam, I'm not vouching for it or anything. But it is effectively the equivalent of something like a CPA or CFA that Software Engineering has no analog of.
- qzx_pierri 4y agoAs someone who recently left a security job at a very prestigious and well known organization.. The person you're replying to isn't wrong. Certifications only prove that you took the time to memorize a set of concepts. > CISSP is much more consistent and predictable and known than random sampling of leetcode questions Even the CISSP is just a test of memorization - The ISC2 cert prep book is 10 miles long, but only about 5 feet deep (if that makes any sense). Being a good security engineer comes with experience and knowledge of basic scams such as caller ID spoofing (something I did to my friends as a bored 6th grader). Being a good security engineer is having a keen eye for small changes and being skeptical about EVERYTHING. Any security engineer worth their salt would never discuss anything containing PII on an inbound phone call.
- antonvs 4y ago> Any security engineer worth their salt would never discuss anything containing PII on an inbound phone call. Yeah. Clearly "security" means something different to him than it does to us.
- nobody9999 4y ago>Even the CISSP is just a test of memorization - The ISC2 cert prep book is 10 miles long, but only about 5 feet deep (if that makes any sense). Except passing the (broad, but shallow) test isn't the real reason why CISSP is a decent certification. Passing the exam is just the first part. You then need to document at least five years of professional infosec experience[0] and have one or more current CISSP holders recommend you[1]. Experience and the approval of your peers are much better predictors of value/knowledge than a test. That's not to say that every CISSP cert holder is a rock star, but it's a lot more than just passing a test. [0] https://www.isc2.org/Certifications/CISSP/experience-requirements https://www.isc2.org/Certifications/CISSP/experience-require... [1] https://www.isc2.org/Endorsement https://www.isc2.org/Endorsement
- wglb 4y agoThere is much doubt about the correlation of CISSP certificate holders and good security engineers.
- briandear 4y agoWhat the heck is a “standard leetcode bar?” Who does leetcode to prove their worth as an SWE? I know plenty of leetcode aces that couldn’t work on a real world application if their lives depended on it. Leetcode might test the ability to write some academic algorithm from some college textbook, but it doesn’t test real world. There is a reason many top companies don’t use Leetcode or HackerRank: zero prediction of real world skill or systems thinking.
- staticassertion 4y agoI've been a SWE and Seceng. Interviews are extremely similar and extremely easy in both cases. The bar for both is kind of a joke, and it's very much made up.
- AnIdiotOnTheNet 4y agoA corollary to Sturgeon's Law: 90% of any given field is shit at their job. I've met a lot of "Security Engineers" and I can assure you the pattern holds. Then again, even the other 10% of any given field that is actually good at what they do still fucks up occasionally, so maybe we needn't judge too harshly.
- HL33tibCe7 4y agoI don't think it's fair to claim that the author is "shit at his job" because he doesn't know some (rather unintuitive and unexpected) trivia about how phone ID works. There are plenty of different roles in security engineering, many of which would never need to be concerned about this.
- carlmr 4y agoAlso I think just his openness in admitting a mistake he could hide in shame is a sign that he understands his job. While this is more psychology than technology, that's very important in social engineering.
- giaour 4y agoEveryone in the US with a cell phone is getting inundated these days with spam texts and calls with fake caller ID. It's almost inconceivable that someone with an American cell phone wouldn't know that phone ID is a lie, which is I think where some of the incredulity from other commenters is coming from. But I believe the author is from the UK, where the spam situation might not be so dire?
- dwighttk 4y agoHuh. I get a bunch of spam calls I ignore, but I don’t know how I’d know that any of the caller ID is fake
- giaour 4y agoThe recent surge in spam texts that show as having been sent by the recipient[0] has driven this point home for a lot of mobile phone users. For me, the fact that caller ID is fake was made evident when a spammer used my number as their origin ID for a wave of spam calls and texts, and I got ~100 voice mails and texts the next day kindly asking me to eat shit and die. Verizon support said that there was nothing they could do, that it was happening left and right, and that I was in no way legally or financially responsible for any of the messages purporting to be from me. This was in 2020, and the unreliability of long code origin ID numbers has come up frequently in my work as a security engineer for the past few years. [0]: https://www.nytimes.com/2022/03/30/business/spam-texts-verizon.html https://www.nytimes.com/2022/03/30/business/spam-texts-veriz...
- lr4444lr 4y agoWhat's weird is, this is the sort of thing that many (not all) average people know because it materially happens to them. It doesn't even rise to the level of elementary professional knowledge that you'd expect of all but only of professionals.
- duxup 4y agoI'm imagining this guy giving advice to someone that includes validating by caller id or something ... scary.
- leephillips 4y agoAfter encountering everything from a taxi driver in NYC who didn’t know where Grand Central Station was, to a recently hired physics professor with a PhD (Univ. Cal. Davis) who didn’t know what a partial derivative was, someone having a particular job title means zero to me. It just means that someone, for some reason, is paying the person to do <job title>. But this guy didn’t do too badly, after all.
- tremon 4y agoa taxi driver in NYC who didn’t know where Grand Central Station was You mean the post office?
- leephillips 4y agoNo, I mean the largest train station in the world, the central rail hub of the city, a famous landmark and tourist attraction. The official name is Grand Central Terminal, but nobody calls it that (usually just “Grand Central”).
- DFHippie 4y agoI was curious about the "largest train station in the world" claim. I figured there would be bigger ones by now in India, say, or China. Sure enough, there are different metrics by which different stations can claim to be the largest. Nagoya Station in Japan, for instance, is the largest in floor area. Shinjuku Station, also in Japan, is the busiest by daily traffic. The Gare Du Nord in Paris is the second busiest by this metric. Apparently Grand Central is the biggest in platform capacity. Anyway, back to the point.
- leephillips 4y agoWhat about volume? Grand Central has a high ceiling.
- softwarebeware 4y agoThis is why I love Hacker News lol
- csharpminor 4y agoOne thing that many people don’t know is that SMS caller IDs are also being spoofed more frequently. In the article the author mentions noticing that the authentication code came from a number the bank didn’t ever use. Sophisticated scammers can spoof your bank’s phone number and send a message that appears in a thread alongside other legitimate SMS from the bank. This is harder to do than caller ID spoofing, but has become more prevalent recently.
- jeroenhd 4y agoIt all depends on what kind of security engineer this person is. The author writes about computer network attacks, tracking, and privacy violations. If their expertise is in preventing web application attacks, detecting fraudulent operations in the inter-bank payment systems or in finding signs of compromise in a corporate network, there's no reason for them to know about the intricacies of SIP and SS7 and the many faults of the international/US phone network when it comes to trust and abuse. Really, "security engineer" is as vague a term as "programmer". Web programmers are programmers yet they don't necessarily understand the layout of virtual memory or the way the kernel interacts with userland programs, something many other programmers would consider essential for their jobs. A kernel programmer couldn't give two hoots about how Chrome's CSS engine works, but the vast majority of modern programmers probably do. I've had lectures in university on natural language processing and data structures that were slowed down because the lecturer couldn't get the beamer to work right with his Macbook. You can't expect someone to know everything, even if it's in their apparent area of expertise. I'd go so far as to say that any security engineer worth their salt will admit that they too are vulnerable to being scammed under the right circumstances and that anyone pretending to be unscammable is severely overestimating their abilities.
- lupire 4y agoRegardless of your professional training, everyone gets spam calls from spoofed caller ID (that copy your phone area code and exchange) every week.
- wildrhythms 4y agoWhat utopian world does a security researcher live in where spam calls and spoofed numbers don't exist on a daily basis?
- jeroenhd 4y agoI've never had a spam call in my entire life, maybe he just has a non-American phone number?
- dogman144 4y agoNot that I disagree, but I think the majority of sec engs do not deal with telephony or related fraud directly. In companies where fraud with caller ID and responding to it matters, that's often tasked to a fraud team dealing with account takeovers or a user onboarding team that offloads verification to a vendor like Persona -> not a security engineering team. However, I think it's common knowledge that inbound identifiers like IPs, user agents can be faked and aren't great technical indicators to anchor detections on for longer than an active incident. That intuition should extend to caller ID IMO, if they didn't know it already.
- xyst 4y agoI know this because I have done it in the past to mess with my parents, family, and friends (ie, display 666-666-6666 on the caller id)
- staticassertion 4y agoSecurity engineers are basically expected to know everything. It's part of why I enjoy the work. But it's also impossible. "Understand the security implications of every nuanced technology decision" is not tractable, so we pick the ones we can and specialize. POTS is rarely of interest to a security organization. You have very few levers to pull even if you do consider it a threat, since it's just fundamentally an awful system, and you can't tell people "don't use telephones". At best you can train people, but your concern is probably phishing via email. Only a few people, at the company level, are at risk in terms of this sort of attack, compared to everyone being at risk (with regards to the company) from phishing emails. So a lot of people just don't really think about it. Security engineers might hand wavingly say "phone numbers can be spoofed" but I'd bet the percentage of seceng that know how that works is very small.
- neoCrimeLabs 4y agoIt's true, being a successful information security engineer requires a very diverse understanding of technology and psychology. Not one person understands all the technology in existence, and no one person ever will. Also engineers come in different levels of experience. Just because someone doesn't have experience in specific technology doesn't exclude them from being an engineer in a specific field.
- softwarebeware 4y agoIt was refreshing to read an honest post. If more people were willing to admit they don't know something, the world would be an infinitely better place.