[HN Gopher] I'm a security engineer and I still almost got scammed
___________________________________________________________________
I'm a security engineer and I still almost got scammed
Author : trauco
Score : 194 points
Date : 2022-04-21 13:11 UTC (9 hours ago)
(HTM) web link (robertheaton.com)
(TXT) w3m dump (robertheaton.com)
| staticassertion wrote:
| Here's the thing. Phones fucking suck. Anyone can call anyone,
| and that's insane. It's like the phone book, it's a dated concept
| that just does not scale.
|
| Phone numbers as a proxy for "who is calling me" is terrible.
| Numbers change, numbers can be spoofed, numbers can be stolen.
| All identification that happens via a phone is fundamentally
| _bad_ and it is only getting worse.
|
| The trick is, don't use phones. Really. Block every number that
| isn't someone you know, for starters. If someone calls you and
| it's a bank ask them to contact you via email, and only use the
| phone to confirm what has already been discussed via email - for
| example, if you are performing a wire transfer, initiate that via
| email, and if you confirm information via the phone never _offer_
| any information, just validate what they say.
|
| This issue is so common and pervasive that, as the author
| demonstrates, we just assume _everything is horribly broken_ and
| when something is suspicious we just think "well, everything's
| horrible, so why wouldn't this be horrible?".
|
| "Silly but plausible" - this is the cost of security theater. I
| have to jump through hilariously stupid loops sometimes.
|
| But ultimately I blame phones being used as proxies for identity.
| KSPAtlas wrote:
| Can this be a case of survivorship bias, but flipped?
| Toreno96 wrote:
| The article references another one of the author's articles:
| https://robertheaton.com/2019/06/24/i-was-7-words-away-from-...
|
| I find it quite amusing that the scam used the domain
| `people.ds.cam.ac.uk`, which contains `s.cam`.
| [deleted]
| mongol wrote:
| I once was called by my bank on a Sunday. They told me someone
| had found my credit card at a parking payment machine where I
| parked approximately 10 minutes earlier. That was a legit and
| reasonably urgent call. I could go and get it from the couple
| that found it at a nearby cafe.
| vasco wrote:
| If your card is stolen and you become a victim of fraud, and they
| manage to take money from your account, and your bank already
| knows its fraud, there's no urgency on your end.
|
| You'll get your money back. I'd go as far as saying that if the
| bank genuinely wants you to decide fast, it's not to protect you.
| It's to protect itself. Shenanigans about "do it fast or they'll
| take more" are bullshit always. The bank is on the hook, not you.
| So never do things in a rush, take your time to verify yourself
| that money indeed disappeared. There. is. no. urgency.
|
| Sense of urgency is one of the best ways to make people do bad
| decisions. Salespeople use it, scammers use it. Nobody who is
| trying to be helpful will come with a story "that needs to be
| fixed now!!!".
|
| If you still want to be safe, and you use a debit card, have 2
| accounts. One with the bulk of your money without a card
| associated with it. One with the card associated with it and no
| more than whatever you spend in a week. If you use a credit card,
| it totally doesn't matter, it's the banks money, not yours that
| they'd steal.
|
| So whenever you find yourself in a situation where someone wants
| you to decide something fast that you didn't know about and isn't
| a direct threat to your life, don't do it. Think about it first.
|
| It's impossible to keep up with all the scams, but if you stop to
| think and never take rash decisions you don't have to. Slow is
| safe.
| sidewndr46 wrote:
| If someone wipes out my bank account and I can't pay any bills,
| am I liable for those charges? What about the associated late
| charges? What about when service is terminated to my home?
|
| If someone takes money from my account, it is absolutely
| urgent.
| hawkesnest wrote:
| This is the primary reason why I stopped using my bank card
| for anything but the ATM at said bank. A scammer wiping out
| my checking account is more than an inconvenience, even if
| the bank only needed a day or so to replenish the account.
|
| Now I use a "proper" credit card for anything. If a crook
| manages to run up a tab on that thing I still have all my
| cash for whatever scrapes may come along.
| kube-system wrote:
| Yep. In the US, you are not liable for any fraudulent
| transactions reported within 60 days. You can easily wait until
| you get your next statement.
| Zircom wrote:
| That's assuming the bank actually finds the transaction(s)
| were fraudulent when they do their "investigation". If they
| disagree with you and decide it wasn't fraudulent for
| whatever reason it's quite often a giant pain to argue with
| them and get it sorted out.
| kube-system wrote:
| I'm saying that if a bank calls you and _they already
| suspect that a transaction is fraudulent_ , you don't have
| to answer the phone right away.
| kingcharles wrote:
| Exactly this. I bought something online. The company
| shipped it, but FedEx screwed up and sent it back to the
| merchant. The merchant never responded to me after that and
| then went bankrupt. I called my bank (Square) and they said
| it wasn't fraud as the package had been "delivered". I
| pointed out it had been delivered back to the merchant, and
| they said that still counted as delivered in their support
| script. They told me the only way to fix it was to call
| FedEx and somehow scam them into changing the status of the
| package online. I tried to get them to change their support
| script but they decided it was easier just to terminate my
| account instead.
| mannykannot wrote:
| There was a relatively recent case of Bank of America
| deciding eight months later that it wasn't a fraud and
| clawing back their provisional refund. It turns out that
| the original card was intercepted in the mail and they
| simply issued a duplicate without preventing the use of the
| first, but it took the victim's attorneys to get the
| evidence from the bank, connect the dots and figure out
| this happened.
| jasinjames wrote:
| I'd love to read about this. Could you link an article?
| mannykannot wrote:
| https://www.nj.com/news/2022/03/bank-warns-customer-
| of-1200-...
|
| I got some details wrong; in particular, the initial
| dispute denial was after two months (with the Consumer
| Financial Protection Bureau agreeing with the bank after
| another two months), and the resolution followed NJ
| Advance Media contacting BofA.
| zeroonetwothree wrote:
| The burden of proof is on the merchant. If they don't have
| a signed receipt or video evidence they probably can't win
| (so any online purchases are doomed). I've never failed a
| dispute in around 25 times, including several in the range
| of $2k+
| kingcharles wrote:
| No it's not. It's on you to persuade the bank it was
| fraudulent. If the bank doesn't believe it is fraudulent
| then they won't claw the money back from the merchant.
| Source: personal experience.
| kube-system wrote:
| The bank is required by law to provide you the evidence
| supporting their decision -- if you request it.
|
| 12 CFR SS 1026.13 (f)(2)
|
| https://www.law.cornell.edu/cfr/text/12/1026.13
| kingcharles wrote:
| Thank you, I will use this. I'm about to contact their
| head of legal.
| [deleted]
| merlincorey wrote:
| This exact scam happened to a coworker's wife and the bank
| refused to consider it fraud since she "authorized" it by
| giving the confirmation code for Apple Pay to the attacker.
| staticassertion wrote:
| This is one of the nice things with credit cards. I've
| never had an issue with a chargeback, and in the case
| where a card was stolen the charges were just reversed.
| kube-system wrote:
| I find it interesting that this is the level of detail
| discussed with the bank. Our family has had 3 instances
| of unauthorized charges over the years, and the most
| we've ever done was to sign a form that basically says
| "we didn't make these charges"
|
| Did they volunteer these details or were they asked? This
| is just conjecture, but sometimes when people volunteer
| too much information to front-line support you can get
| erratic responses if they latch on to superficial parts
| of the story rather than the underlying message.
|
| i.e. support just hears "I gave someone access", and they
| close the ticket under "customer authorized someone else
| to purchase", because they're following a decision tree,
| not analyzing the root cause of a security incident.
| turtlebits wrote:
| In general, banking customer service sucks. I try to buy
| everything on my AMEX. Their service is excellent. I've
| never had to fill out a dispute form or give them any
| kind of proof when disputing a transaction, just a short
| call and they take care of it.
| manapause wrote:
| I had a friend who had their bank account cleaned out by a wire
| transfer of 200K in the same week he is trying to close on a
| house.
|
| The bank executed on their promises of no disruption to his
| transfers; they told him he did not have to worry and the
| customer service was so terrific, he said he was going to stay
| with the bank.
|
| "Did you ask if there were other accounts at the bank that had
| been accessed in this way?"
|
| "A wire transfer to an international location went through with
| no red flags and 0 notifications?"
|
| "Can you ask your security department to produce a report of
| their investigation into the matter?"
|
| Nobody asks those questions.
| skeeter2020 wrote:
| I'm well aware of the (lack of true) financial implications but
| I still get the urgency and need to speed up because of the
| violation and shock that someone is impersonating me RIGHT NOW!
| It feels similar to a physical threat, or enough so that our
| bodies react the same way. It is really hard to develop control
| unless you're exposed to this situation, so I like your strict
| yet general rule to (a) classify the situation, (b) slow down.
| Even enough time for 10 deep breaths is likely enough to get
| you centered and thinking clearly.
| toraway1234 wrote:
| lr1970 wrote:
| Virtually identical story of the scam with ApplePay was here 3
| weeks ago. The victim was a scam prevention expert:
|
| https://news.ycombinator.com/item?id=30869427
|
| EDIT: silly typos
| softwarebeware wrote:
| This was a great read. I think the biggest takeaway I had was how
| some banks and credit card companies themselves are not doing a
| great job at building trustworthy systems. That leads consumers
| into treating things that seem gray, like confirmation code texts
| coming from unknown numbers, as credible.
| smbv wrote:
| Dupe: https://news.ycombinator.com/item?id=31100336
| ed25519FUUU wrote:
| The problem is definitely still the security of banks. They
| regularly call YOU and tell you that you have to verify yourself.
| It's an incredibly stupid system.
| xyst wrote:
| In this day and age, how do people still fall for this? This
| isn't the old days where you would get a physical paper statement
| in the mail every 30 days and rely on your bank to call you for
| potentially fraudulent purchases.
|
| You have instant access to your financial information. You can
| easily see "pending" and "posted" charges on your credit accounts
| without a third party.
| alias_neo wrote:
| > Nothing the bank might want to talk about could be urgent
| enough to interrupt an unseasonably sunny March afternoon.
|
| Wrong. Some banks, and with certain account types, the bank will
| absolutely make a courtesy call to you if something unusual is
| happening.
|
| I had a call from my bank while spending a few hundred on
| cocktails in Bali (I'm from London), I hadn't used my card yet on
| that trip as I'd taken cash.
|
| They also called me to check a payment into my account with an
| "unusual" reference; a joke from a friend returning the money he
| owed for a holiday I paid for, but which made it look like he was
| paying me for "special services".
|
| They called me to query a payment at a home furniture store for a
| couple thousand pounds in a city ~300 miles from where I live
| only hours after I'd used the card near home; I'd driven to this
| particular store to check out the furniture.
|
| If you're not sure, the _real_ bank will suggest you hang up and
| call their number found on your card or their website (or in your
| contacts list, where I keep it) and will never pressure you to
| answer or provide them information, and they'll NEVER, EVER ask
| you to read a security code out to them sent to your phone, or
| using your banking app.
|
| EDIT: To further clarify; my particular bank's app, has, on
| rotation, a series of warnings, displayed each time I log in,
| saying things like "BEWARE; if someone [calls/texts/etc]
| asking/telling you to do [XYZ] ...", e.g. to get this code or
| that code, or do something else in this app, you're being
| scammed, "WE WILL NEVER ASK YOU FOR [XYZ]...".
| jrochkind1 wrote:
| I'm not at all confident that the real bank will never actually
| ask for you to verbally read a security code texted to you.
| This is how little I trust bank's security practices.
|
| Here's a comment from a similar post last month, where the
| commenter believes the legit bank asked for a verbal
| confirmation of security code:
| https://news.ycombinator.com/item?id=30875233
|
| (I suppose it's possible the commenter was actually interacting
| with a scammer there and still doesn't realize it?)
| IG_Semmelweiss wrote:
| I agree with you. I think there might be a distinction btw
| inbound and outbound.
|
| I think reading any code during inbound call is red flag for
| fraud. However, more than once _i_ took the initiative to
| call ccs to unblock a large / international charges. The
| only way for the bank to verify my identity is for me to read
| the code.
|
| So it is not true that you NEVER read ever. Maybe for inbound
| this should be true. But not outbound
| alias_neo wrote:
| > I told him, the 2FA message literally says to never give
| this number out to anyone
|
| He was 100% being scammed.
| mint2 wrote:
| If you called in to Amex using the number on the card for
| certain things like fraud, for a while they would then text
| you a code in a message that says:
|
| "Amex Fraud Free Msg: Your requested code is: xxxx. We
| won't call to ask for it. Don't share it. Call ######## if
| you didn't request it. Reply STOP to opt out."
|
| You wouldn't be the requesting this text and code, the
| person on the phone would. And it says don't share it.
| Maybe I was hoodwinked but it seemed really legit although
| in principle I refused to give it.
|
| It seems so scammy, but I'd called the number on the back
| of the card.
| bombcar wrote:
| Banks are dumb, really dumb, and they don't align. I have
| personally _called_ the number on the card, and been asked
| to verify the phone by repeating a number they would send,
| which came with the standard "nobody will ask for this
| number".
|
| I presume because I initiated the call they think it's ok,
| but it's still silly.
| jrochkind1 wrote:
| And still doesn't realize it some time later? (I guess we
| don't know how much time later).
|
| That would be stunning in it's own way! What a world.
| kergonath wrote:
| > I had a call from my bank while spending a few hundred on
| cocktails in Bali (I'm from London), I hadn't used my card yet
| on that trip as I'd taken cash.
|
| Mine dit that as well a couple of times (Santander UK; my
| account was nothing special though I do travel internationally
| several times a year; it was a mistake every time and I never
| had any fraud with this card). The first time I took it, but
| now I would say that I cannot, end the discussion, and then
| call them to their known number. Also, I've never had a human
| ask me to read numbers from a text message. They (well, another
| bank, but still) do occasionally ask me to unlock their app
| using either biometrics or a PIN; they can see it in real time
| and that can only be done on a single pre-approved device.
| cowvin wrote:
| Yeah, you can tell a lot by the attitude of the caller. A
| person once called my wife telling us about a potential
| fraudulent transaction on one of our credit cards. She was a
| bit worried so she came over and got me. The person started
| asking her about whether she made a purchase at this time, etc.
| I jumped in and told her to stop talking to the guy and call
| the credit card company back. The person chuckled and said
| "okay, sounds good."
|
| We called the credit card company and there was indeed a
| fraudulent purchase, so yeah the real companies don't pressure
| you into unsafe things.
| jve wrote:
| Uh, I'v got similar calls.
|
| Here you can watch video for taking down one of these call
| centers by police, not so long ago:
| https://www.delfi.lv/news/national/criminal/video-latvija-ai...
| nonrandomstring wrote:
| We already covered this, but advice distilled from earlier
| comments bears repeating;
|
| One special class of vulnerable targets is _security experts_ ,
| and _top ranks_. I remind my students that "pride comes before a
| fall" and nobody is immune. While doing some training for <BIG
| INTERNATIONAL BANK> someone told me they call it the "cocks
| problem". It's the handful of 7 figure salary high flyers that
| get regularly pwned and cause grief for everybody else, because
| they are "too cocky". Lowly secretaries and desk staff are much
| harder marks. The more training you give to people who think
| they're above it the worse they get. It has to be pitched as
| participatory advice, as an invitation to co-create a secure
| practice.
|
| We saw this cavalier attitude just the other day with Boris
| Johnson [0]. I bet Johnson was told time and again to use
| equipment that had been checked by his security detail. And I
| still cringe thinking of this one [1].
|
| I suggest there's no correlation between domain knowledge and
| behavioural invulnerability. Good security posture is a mind-set.
| I also think it's a very strange combination of contradictory
| qualities (or attitudes you can be trained to adopt) that are
| hard to describe, such as high conscientiousness and humility
| mixed with utterly cynical disrespect for "authority", high
| openness but brutally meticulous self-checking and introspection.
| And definitely, never call yourself an 'expert'.
|
| [0] https://news.ycombinator.com/item?id=31075558
|
| [1] https://www.arrse.co.uk/community/threads/77-bde-twitter-
| fee...
| resoluteteeth wrote:
| It sort of reminds me of this: https://driving.ca/auto-
| news/news/why-advanced-driver-traini...
|
| I guess the common factor is that the most important thing is
| to be careful and follow the proper procedure to not get caught
| in a problematic situation in the first place, not to be
| overconfident and assume you are safe because you can handle
| any situation with your knowledge or skills.
| nonrandomstring wrote:
| > procedure to not get caught in a problematic situation in
| the first place
|
| Totally. I saw this Krav Maga instructor say:
|
| "Now. I'm going to tell you one of the most effective self
| defence moves known in any martial art... run away!"
| karmakaze wrote:
| The same shows here:
|
| > security engineers need to design systems that are resilient
| to them
|
| The problem here, to a security engineer, is that we need
| better systems. I suspect they mean the hardware and software
| systems, although the 'system' includes the participants. The
| problem and solution space should strongly include people as it
| just was clearly demonstrated.
|
| Could be an occupational hazard, having seen so many insecure
| and poorly designed system to have low opinions of them. Having
| low expectation of security practices sets a lower bar for
| acceptance of what's authentic. I can't say if I would be
| caught in similar circumstances without being in the moment.
| The two things I hope I'd do is see the tx in my own history
| and not tell a human a code. These are for machines to verify.
| I recall when everyone switched their system so PINs could be
| entered for machine verification and the human returning after.
| A machine sent code should also be checked by a machine.
|
| A practice that does bother me greatly is how many different
| domain names are used by a company. Only subdomains should be
| used for any kind of official interaction (or perhaps period).
| jrochkind1 wrote:
| Part of this comes indeed from not trusting the banks -- like, I
| know the banks do irrational insecure things, and I also don't
| trust that if I don't do _exactly what they say_ they will
| actually cover me in case of fraud (which we know does happen, a
| lot, now).
|
| Like, let's say I insisted on hanging up and calling the number
| on the back of my phone -- are there any cases that would be
| disastrous for me, would end up in me losing money, and I really
| _should_ have stayed on the phone with the person who called me,
| who really was a non-fraudulent representative?
|
| I'm not confident there are not.
| wccrawford wrote:
| I think you mean "back of your card".
|
| I honestly believe that there are no cases for that on a
| _credit card_. On a debit card, that might be different. This
| is why I never use my debit card for purchases.
| paxys wrote:
| I'm not a security engineer, but here's the easiest way to
| prevent 99% of scams - never pick up the phone. If it is urgent
| they can leave a voice mail, and you can call back by looking up
| the official number.
| [deleted]
| cameronh90 wrote:
| I almost got scammed by a SMS that woke me up.
|
| Local couriers often send links by SMS when an international
| package needs customs duty paid, and they often shorten URLs due
| to SMS limits. So they might send a URL like couri.er/1ea6dz.
| Often the payment sites look a little dodgy too, frequently just
| an un-themed Worldpay form.
|
| Unfortunately I was expecting an international package and an SMS
| woke me up saying delivery would happen today provided I pay the
| customs duty. I luckily had gained my senses enough by the time
| the page had loaded to double check everything, but it could have
| got me.
|
| When the legit request to pay customs duty came through, it
| didn't look all that different...
| lamontcg wrote:
| "Yeah, I *69'd you. I never pick up my phone." -- Tyler Durden,
| Fight Club.
|
| I'd also logon to the bank website first to look at recent
| transactions myself so that I "do my own research" before talking
| to a person at the bank.
|
| Most often the fraud check is something like an apple hardware
| purchase that I made months ago which only just went through
| after I got the front of the waiting list. I'd want to debug that
| stuff myself first. If I'm out doing something and a text/VM
| comes in while I'm on thumbs I'll happily wait until later that
| night to debug the problem. Like the top thread here says,
| there's no urgency.
|
| Really helps to be an introvert where you very actively don't
| want to call someone up and chat on the phone about shit, so you
| first seek to avoid having to talk to anyone in person, and then
| have all the information you can acquire ready first to keep the
| phone call as short as possible.
| vegai_ wrote:
| When I get off work, I want to think about silly computer
| problems as little as possible. Perhaps the same applies to
| security engineers.
| nottorp wrote:
| US Banks are so bad that this scenario would be believable? Any
| security problem where I am would get fixed either via resets on
| pre established channels or via a visit to the actual bank with
| ID verification.
| 46Bit wrote:
| > The internet tells me that caller IDs are easy to spoof, which
| I didn't know
|
| I really think that security engineers should know this.
| fortran77 wrote:
| I thought this was a new, subtle, clever scam. It wasn't. I was
| very surprised he's a "security engineer."
|
| Still, I'm glad he's not embarrassed to share his story, to
| help others be more aware.
| lr4444lr wrote:
| What's weird is, this is the sort of thing that many (not all)
| average people know because it materially happens to them. It
| doesn't even rise to the level of elementary professional
| knowledge that you'd expect of all but only of professionals.
| leephillips wrote:
| After encountering everything from a taxi driver in NYC who
| didn't know where Grand Central Station was, to a recently
| hired physics professor with a PhD (Univ. Cal. Davis) who
| didn't know what a partial derivative was, someone having a
| particular job title means zero to me. It just means that
| someone, for some reason, is paying the person to do <job
| title>. But this guy didn't do too badly, after all.
| tremon wrote:
| _a taxi driver in NYC who didn't know where Grand Central
| Station was_
|
| You mean the post office?
| leephillips wrote:
| No, I mean the largest train station in the world, the
| central rail hub of the city, a famous landmark and tourist
| attraction. The official name is Grand Central Terminal,
| but nobody calls it that (usually just "Grand Central").
| DFHippie wrote:
| I was curious about the "largest train station in the
| world" claim. I figured there would be bigger ones by now
| in India, say, or China. Sure enough, there are different
| metrics by which different stations can claim to be the
| largest. Nagoya Station in Japan, for instance, is the
| largest in floor area. Shinjuku Station, also in Japan,
| is the busiest by daily traffic. The Gare Du Nord in
| Paris is the second busiest by this metric. Apparently
| Grand Central is the biggest in platform capacity.
|
| Anyway, back to the point.
| leephillips wrote:
| What about volume? Grand Central has a high ceiling.
| softwarebeware wrote:
| This is why I love Hacker News lol
| rhexs wrote:
| I think the only qualification for "security engineer" these
| days is changing your LinkedIn job description to "security
| engineer". Unlike SWEs, there isn't really any sort of standard
| leetcode bar for them, which is both a pro and a con.
|
| Lot of snake oil in the field at the moment.
| nonameiguess wrote:
| That seems the opposite of true. They have pretty
| standardized certifications in the field. CISSP is much more
| consistent and predictable and known than random sampling of
| leetcode questions. Of course, you don't need to score 100%
| on the exam to pass it, and not being familiar with the
| content of the exam, I'm not vouching for it or anything. But
| it is effectively the equivalent of something like a CPA or
| CFA that Software Engineering has no analog of.
| giaour wrote:
| If you spend time working in a field that _requires_ a
| CISSP (like most info sec roles in the US government), you
| will meet plenty of people who crammed for a test but are
| otherwise completely incompetent.
|
| I would not recommend viewing the CISSP as anything other
| than an attestation that someone can memorize a few
| concepts for a test.
| qzx_pierri wrote:
| As someone who recently left a security job at a very
| prestigious and well known organization.. The person you're
| replying to isn't wrong. Certifications only prove that you
| took the time to memorize a set of concepts.
|
| > CISSP is much more consistent and predictable and known
| than random sampling of leetcode questions
|
| Even the CISSP is just a test of memorization - The ISC2
| cert prep book is 10 miles long, but only about 5 feet deep
| (if that makes any sense).
|
| Being a good security engineer comes with experience and
| knowledge of basic scams such as caller ID spoofing
| (something I did to my friends as a bored 6th grader).
| Being a good security engineer is having a keen eye for
| small changes and being skeptical about EVERYTHING.
|
| Any security engineer worth their salt would never discuss
| anything containing PII on an inbound phone call.
| antonvs wrote:
| > Any security engineer worth their salt would never
| discuss anything containing PII on an inbound phone call.
|
| Yeah. Clearly "security" means something different to him
| than it does to us.
| wglb wrote:
| There is much doubt about the correlation of CISSP
| certificate holders and good security engineers.
| staticassertion wrote:
| I've been a SWE and Seceng. Interviews are extremely similar
| and extremely easy in both cases. The bar for both is kind of
| a joke, and it's very much made up.
| briandear wrote:
| What the heck is a "standard leetcode bar?" Who does leetcode
| to prove their worth as an SWE?
|
| I know plenty of leetcode aces that couldn't work on a real
| world application if their lives depended on it. Leetcode
| might test the ability to write some academic algorithm from
| some college textbook, but it doesn't test real world.
|
| There is a reason many top companies don't use Leetcode or
| HackerRank: zero prediction of real world skill or systems
| thinking.
| neoCrimeLabs wrote:
| It's true, being a successful information security engineer
| requires a very diverse understanding of technology and
| psychology.
|
| Not one person understands all the technology in existence, and
| no one person ever will.
|
| Also engineers come in different levels of experience. Just
| because someone doesn't have experience in specific technology
| doesn't exclude them from being an engineer in a specific
| field.
| jeroenhd wrote:
| It all depends on what kind of security engineer this person
| is. The author writes about computer network attacks, tracking,
| and privacy violations. If their expertise is in preventing web
| application attacks, detecting fraudulent operations in the
| inter-bank payment systems or in finding signs of compromise in
| a corporate network, there's no reason for them to know about
| the intricacies of SIP and SS7 and the many faults of the
| international/US phone network when it comes to trust and
| abuse.
|
| Really, "security engineer" is as vague a term as "programmer".
| Web programmers are programmers yet they don't necessarily
| understand the layout of virtual memory or the way the kernel
| interacts with userland programs, something many other
| programmers would consider essential for their jobs. A kernel
| programmer couldn't give two hoots about how Chrome's CSS
| engine works, but the vast majority of modern programmers
| probably do.
|
| I've had lectures in university on natural language processing
| and data structures that were slowed down because the lecturer
| couldn't get the beamer to work right with his Macbook. You
| can't expect someone to know _everything_ , even if it's in
| their apparent area of expertise.
|
| I'd go so far as to say that any security engineer worth their
| salt will admit that they too are vulnerable to being scammed
| under the right circumstances and that anyone pretending to be
| unscammable is severely overestimating their abilities.
| staticassertion wrote:
| Security engineers are basically expected to know everything.
| It's part of why I enjoy the work. But it's also impossible.
| "Understand the security implications of every nuanced
| technology decision" is not tractable, so we pick the ones we
| can and specialize.
|
| POTS is rarely of interest to a security organization. You have
| very few levers to pull even if you do consider it a threat,
| since it's just fundamentally an awful system, and you can't
| tell people "don't use telephones". At best you can train
| people, but your concern is probably phishing via email.
|
| Only a few people, at the company level, are at risk in terms
| of this sort of attack, compared to everyone being at risk
| (with regards to the company) from phishing emails.
|
| So a lot of people just don't really think about it. Security
| engineers might hand wavingly say "phone numbers can be
| spoofed" but I'd bet the percentage of seceng that know _how_
| that works is very small.
| softwarebeware wrote:
| It was refreshing to read an honest post. If more people were
| willing to admit they don't know something, the world would be
| an infinitely better place.
| xyst wrote:
| I know this because I have done it in the past to mess with my
| parents, family, and friends (ie, display 666-666-6666 on the
| caller id)
| dogman144 wrote:
| Not that I disagree, but I think the majority of sec engs do
| not deal with telephony or related fraud directly. In companies
| where fraud with caller ID and responding to it matters, that's
| often tasked to a fraud team dealing with account takeovers or
| a user onboarding team that offloads verification to a vendor
| like Persona -> not a security engineering team.
|
| However, I think it's common knowledge that inbound identifiers
| like IPs, user agents can be faked and aren't great technical
| indicators to anchor detections on for longer than an active
| incident. That intuition should extend to caller ID IMO, if
| they didn't know it already.
| duxup wrote:
| I'm imagining this guy giving advice to someone that includes
| validating by caller id or something ... scary.
| usrn wrote:
| Too many "security engineers" trust telcos _way_ too much.
| ransom1538 wrote:
| Anddd.. if you are into anti-scam https://aff.419eater.com/
| csharpminor wrote:
| One thing that many people don't know is that SMS caller IDs
| are also being spoofed more frequently. In the article the
| author mentions noticing that the authentication code came from
| a number the bank didn't ever use.
|
| Sophisticated scammers can spoof your bank's phone number and
| send a message that appears in a thread alongside other
| legitimate SMS from the bank.
|
| This is harder to do than caller ID spoofing, but has become
| more prevalent recently.
| AnIdiotOnTheNet wrote:
| A corollary to Sturgeon's Law: 90% of any given field is shit
| at their job. I've met a lot of "Security Engineers" and I can
| assure you the pattern holds.
|
| Then again, even the other 10% of any given field that is
| actually good at what they do still fucks up occasionally, so
| maybe we needn't judge too harshly.
| HL33tibCe7 wrote:
| I don't think it's fair to claim that the author is "shit at
| his job" because he doesn't know some (rather unintuitive and
| unexpected) trivia about how phone ID works. There are plenty
| of different roles in security engineering, many of which
| would never need to be concerned about this.
| carlmr wrote:
| Also I think just his openness in admitting a mistake he
| could hide in shame is a sign that he understands his job.
|
| While this is more psychology than technology, that's very
| important in social engineering.
| giaour wrote:
| Everyone in the US with a cell phone is getting inundated
| these days with spam texts and calls with fake caller ID.
| It's almost inconceivable that someone with an American
| cell phone wouldn't know that phone ID is a lie, which is I
| think where some of the incredulity from other commenters
| is coming from. But I believe the author is from the UK,
| where the spam situation might not be so dire?
| dwighttk wrote:
| Huh. I get a bunch of spam calls I ignore, but I don't
| know how I'd know that any of the caller ID is fake
| giaour wrote:
| The recent surge in spam texts that show as having been
| sent by the recipient[0] has driven this point home for a
| lot of mobile phone users. For me, the fact that caller
| ID is fake was made evident when a spammer used _my_
| number as their origin ID for a wave of spam calls and
| texts, and I got ~100 voice mails and texts the next day
| kindly asking me to eat shit and die. Verizon support
| said that there was nothing they could do, that it was
| happening left and right, and that I was in no way
| legally or financially responsible for any of the
| messages purporting to be from me. This was in 2020, and
| the unreliability of long code origin ID numbers has come
| up frequently in my work as a security engineer for the
| past few years.
|
| [0]: https://www.nytimes.com/2022/03/30/business/spam-
| texts-veriz...
| dwighttk wrote:
| Hmm. Only get a few spam texts per... quarter. Never seen
| one from my own number
| staticassertion wrote:
| That's hilarious. You really think that everyone, or even
| many people, know that phone numbers can be spoofed?
| tlogan wrote:
| I think majority of older American is 100% aware of that.
|
| I do see how young adults are still not aware of that
| since they are not valuable target and their info is
| relatively unknown (no mortgage on their name, no car
| loans, cell phone number is not old, they never sign up
| for sweepstakes in Las Vegas, etc.)
| giaour wrote:
| Yes. There have been multiple front-page news articles in
| the NY Times in the past month about people getting spam
| texts from themselves. The fact that caller ID is
| unreliable is part of the public discourse today.
|
| FWIW, I had to answer the phone at my first office job in
| ~2005, and the office manual has a section on how caller
| ID was not trustworthy caller authentication. None of
| this is new, and it is odd that a self-described security
| engineer would blindly trust caller ID.
| staticassertion wrote:
| Awareness may have grown, but I'd put money on people at-
| large not knowing anything about caller ID spoofing, both
| in terms of its existence, and certainly in terms of its
| accessibility.
| dathinab wrote:
| More important:
|
| The job of security engineer is a very very wide spread one.
| Someone might be an expert wrt. detecting avoiding DDoS, RCE,
| encryption and/or signing that doesn't mean they are an
| expert in social engineering or phone security.
| briHass wrote:
| This is the second very similar report on HN where the end-goal
| was ApplePay. There must be something poorly done in their card
| linking/payment process that hackers are targetting. I don't use
| it, so I'm not familiar.
|
| Collectively, we software engineers that have security focus,
| have done a piss-poor job with 2FA. Users should've been trained
| from day-one that 2FA codes sent to their email or SMS should
| never, EVER, be repeated back to a human. All the additional text
| sent with the code should clearly and emphatically state that
| this number is between you and a website that you are reasonably
| certain represents a secured entity and that you explicitly
| requested during a login flow. It's like the combination to a
| safe: that code is between you and the dial on the safe, if it
| ever verbally leaves your mouth, you're doing something wrong.
|
| Any orgs that use 2FA codes to authenticate a user to a CSR are
| screwing it up for everyone. Don't do that: you should be able to
| mutually authenticate using shared knowledge that a hacker isn't
| likely to have (not an address, FFS), like the previous
| transactions thing the OP requested. 2FA codes are for computers
| only.
| rowls66 wrote:
| I don't know for sure, but I suspect, that the reason that
| ApplePay is being targeted is because other means of credit
| card fraud at point of sale have become much more difficult
| with chip cards. ApplePay itself is also quite secure, but the
| process of enrolling a card in ApplePay is probably the weakest
| link. The card chip does not provide any added security in the
| process. I think that most banks use PAN and card security code
| combined with one time password by email or mobile to verify
| the cardholder. If a fraudster can crack this nut, and get a
| card fraudulently enrolled into ApplePay on a phone, they can
| use the card at point of sale, and point of sale is the ideal
| fraud target since the fraudster can remain mostly anonymous,
| and walk out of the shop with the stollen goods.
| ant6n wrote:
| What pisses me off to no end in Europe is that some banking
| systems require, in order to do a credit card payment, to
| provide the online bank account password and online bank
| account 2fa generated transaction code -- requiring that both
| be entered as part of the payment process on any merchants
| website. It's so goddamn stupid I can't believe this exists.
| It's so easy to fake this and use some sort of man in the
| middle attack to transfer all money away from an account. Plus
| it teaches ppl that it's okay to enter one's online banking
| credentials one-time generated transaction codes into random
| websites selling u random crap for 3EUR...
|
| I don't understand security researchers. Is it all just a bunch
| of hooey they sell or what?
| eythian wrote:
| > It's so goddamn stupid I can't believe this exists. It's so
| easy to fake this and use some sort of man in the middle
| attack to transfer all money away from an account
|
| An MitM attack is significantly harder than "I have your CC
| number and I'll use it with no authentication", therefore it
| does increase the difficulty for fraud. Though I haven't seen
| a requirement to enter the bank's password, my one requires
| me to confirm the transaction by opening the credit card
| provider's app on my phone which isn't vulnerable in the way
| you're describing.
| sofixa wrote:
| Banks are supposed to do MFA. Some, apparently, are crap and
| require you to login while doing a payment, but most ask for
| a confirmation with an SMS code or the banks app, both of
| which contain who the payment is towards, and the amount.
| RadixDLT wrote:
| "security expert" should be taken with a grain of salt
| herf wrote:
| 2FA should never be vague - it should say "Don't give this code
| to anyone." People are getting scammed all the time this way.
| fullstop wrote:
| > I'm not sure where the 2 missed calls from my bank's real phone
| number came from.
|
| This sort of thing is incredibly easy to forge these days.
| neogodless wrote:
| Thought perhaps this was posted previously, but it's just a very
| similar story.
|
| https://news.ycombinator.com/item?id=30869427
|
| "I'm a scam prevention expert and I got scammed" (544 comments 20
| days ago)
| perydell wrote:
| I also thought of this prior post. I believe it is the same
| scam and written up by someone also claiming to be a security
| researcher. It seems too on the nose to be a coincidence.
| post_break wrote:
| Yeah I thought this was the same repost. It's very similar.
| erwincoumans wrote:
| It is too long-winded. Could the scam story be a scam itself?
| liendolucas wrote:
| Question: Why banks do not implement bait/decoy codes for people
| that are aware they are being part of a scam? Wouldn't this
| provide them at least more information about the scammer? With
| all the technology that's available, why is not possible to let
| the scammer believe that he/she is doing a real transaction but
| behind scenes they are being monitored/traced? I'm asking out of
| my ignorance on the subject.
| senectus1 wrote:
| I've recently noticed that I reflexively answer my phone with "
| _MyName_ speaking ", it occurred to me that this is bad security
| practice.
|
| Any suggestion on how I should politely and professionally answer
| a call without giving away my identity?
| xcyu wrote:
| Just stay silent until the other person speaks.
| mbauman wrote:
| This is my MO for unknown numbers these days (which I only
| answer when I have a reasonable expectation of getting a call
| from a new contact). Automated systems will just disconnect
| when they think they got a dead line. Humans will go, "uh,
| hello?"
| dvtrn wrote:
| I started doing this a few months ago, and the number of
| spam calls I've gotten from certain area codes that used to
| call me without fail at least three times a day has dropped
| _considerably_.
| bena wrote:
| I just go with "Hello?".
|
| I also don't mind confirming my name. But I try to never say
| "yes" or "no" when they ask if something is right, I respond
| with "That is correct" or "That is not correct". That may be me
| being too paranoid of people editing the conversation to make
| it look like I agreed to something I didn't.
|
| There was some point where I was getting a call that claimed to
| be a collection agency trying to collect on a DirectTV bill.
| I've never had DirectTV. They kept trying to get me to confirm
| an address, I kept informing them that I've never had DirectTV.
| They would usually hang up when I would press them on who their
| employer was. They often made the mistake of calling during my
| commute when I lived roughly an hour away from my place. So,
| you know, I had the time to kill.
| ceejayoz wrote:
| > But I try to never say "yes" or "no" when they ask if
| something is right, I respond with "That is correct" or "That
| is not correct". That may be me being too paranoid of people
| editing the conversation to make it look like I agreed to
| something I didn't.
|
| It's not overly paranoid. https://www.ag.state.mn.us/consumer
| /Publications/CanYouHearM...
|
| > The details of this scam vary, but it always begins with a
| call, usually from a telephone number that appears to be
| local. When the person answers the call, the scam artist
| tries to get the person to say "yes"--most often by asking,
| "Can you hear me?," "Is this the lady of the house?," or a
| similar question. By responding "yes," people notify robo-
| callers that their number is an active telephone number that
| can be sold to other telemarketers for a higher price. This
| then leads to more unwanted calls.
|
| > In some cases, the caller may record the person saying
| "yes." Scam artists may be able to use a recorded "yes" to
| claim that the person authorized charges to his or her credit
| card or account.
|
| Used to be used a whole bunch for
| https://en.wikipedia.org/wiki/Cramming_(fraud) back in the
| days when you could subscribe to things via your phone bill.
| bena wrote:
| Good to know, I guess. On some level.
|
| I've probably read something similar at some point, made
| the change, and forgot the source that made me wary of it.
| Cutting the ends of the roast as it were.
| bombcar wrote:
| Roadkill Cafe, you kill it, we grill it, how can I help you?
| vlachen wrote:
| Drinkwine Mortuary, You stab 'em, we slab 'em!
| krageon wrote:
| > Any suggestion on how I should politely and professionally
| answer a call without giving away my identity?
|
| I use "hello". It's pretty rude compared to how I was raised,
| but it's also the only way to not give scam calls the ammo they
| need to mess with me. So I can live with rude.
| gre wrote:
| I'm hostile to anyone who calls me until they deserve
| otherwise. Just "hello", "mhmm", "mnnn" kind of grunts. Kind of
| sad but 95% of phone calls that I don't know are from
| scammers/telemarketers.
| Angostura wrote:
| Many years ago, I changed to simply using "Yes, hello?"
| mattw2121 wrote:
| Hello?
| ceejayoz wrote:
| Let it go to voicemail, and have your voicemail greeting say
| "please send me an email instead".
| jrootabega wrote:
| First name only isn't that bad, right?
| mikequinlan wrote:
| Many people nowadays just answer 'Hello'. I do that and if I
| don't get a response after a few seconds I hang up.
| vegetablepotpie wrote:
| I've taken up the practice of just not answering the phone.
| Nothing good ever comes of it.
|
| If it's important, they'll leave a voice mail and I can call
| them back.
| eks391 wrote:
| A direct answer to your question, and depending on the
| cultures of where you live, you could say something like
| Hello, whom do I have the pleasure of speaking with? But
| that's very southern, so I could see many people not feeling
| that. I say Howdy, what may I do for you today?... Which I
| now recognize is also southern... But there's a lot of things
| you could say that distract from identifying yourself.
|
| Along the topics others are replying with, I also don't
| answer calls usually, and have a call blocker so I'm only
| notified if someone from my contacts list is calling or if
| they are recognized by my network carrier as a verified
| business. Since businesses can also be spoofed, I still don't
| give any information and find out why they are calling, then
| politely hang up and call back myself, after first verifying
| the number in about to call is actually associated with the
| business.
| enlyth wrote:
| My apartment has almost no phone signal so I started leaving
| my phone on airplane mode. Best decision I've ever made, it's
| been like this for 6 months now without issues. With friends
| and family I call through facetime/whatsapp/etc. anyway.
|
| It also makes the battery last twice as long.
| leephillips wrote:
| Doesn't airplane mode also turn off the WiFi radio? Maybe
| it depends on the phone. But if it does, how can you use
| WhatsApp, etc.?
| BenjiWiebe wrote:
| You can turn WiFi back on.
| leephillips wrote:
| Haha. I actually knew that and have done it, but forgot
| that it was possible. Thanks.
| Timothycquinn wrote:
| Agreed - As a minimum if the caller has no caller ID I don't
| answer unless I'm expecting such a call. If I answer the
| phone and get a long pause or clicks before I'm talking to
| someone, I'm very dubious of who I'm talking to and get their
| name and phone number so I can do quick background check and
| call them back.
|
| With that said, I almost got duped by a good samaritan debit
| card scam about 20 years ago in Toronto.
| TillE wrote:
| Seriously, for the vast majority of people, the number of
| legitimately urgent calls from strangers is going to be
| vanishingly small. Why even bother answering?
|
| Credit card fraud is not urgent unless maybe you know your
| card has been deactivated. They can leave a quick message if
| your relative is in the hospital or whatever.
| wintermutestwin wrote:
| Yes, but then they do the same and it is endless phone tag
| which usually ends in "you can email me at blaa."
|
| The telephone is broken.
| daniel-cussen wrote:
| Today, for sure, the phone is dead. But it could come back.
| suprfsat wrote:
| "Hello" -- Thomas Edison
|
| "Ahoy" -- Alexander Graham Bell
| postsantum wrote:
| Drop the call and send an SMS saying "Busy now, please let me
| know when it would be best to call you back"
| bell-cot wrote:
| If I don't recognize the #, "Tech. Support, do you have a
| Contract # or Incident #?". Backed by a brusque "very busy
| professional, required to bill his hours" attitude. Human cold
| callers often identify with that - enough to either end the
| call fast, or to try no "hooks" to keep me on the line when I
| end it.
| wglb wrote:
| I've often answered calls from unknown numbers with "This is
| Security" in my most formal voice. Nowadays, I don't answer
| unknown numbers at all.
| koala_man wrote:
| > I got through to the bank, but they couldn't work out why they
| had called me.
|
| The bank said "we have no record of calling you" and it didn't
| stop there?
| scoot wrote:
| Similar to another recent post: "I'm a scam prevention expert and
| I got scammed"
|
| https://news.ycombinator.com/item?id=30869427
| causality0 wrote:
| _I made a note to check my account when I got home_
|
| It would take more than thirty seconds to go online and check the
| account?
|
| _"I'm calling about some suspicious transactions on your account
| ending in 1234. Is this a good time to talk?"_
|
| I don't know how it works there, but my bank's fraud alert call
| is automated and exactly the same every time.
|
| _"I'd like to enable enhanced security on your account, but I'll
| need to text you a confirmation code first. Is that OK?"_
|
| Do banks do that there? Mine won't make any kind of account
| changes unless I show up in person with ID.
|
| _Barry couldn't use my card to buy anything online because my
| bank sends me a one-time verification code whenever I use the
| card on a new website._
|
| This is great. All banks should do that.
| scott_s wrote:
| Basically the same scenario as this HN submission: "I'm a scam
| prevention expert and I got scammed",
| https://news.ycombinator.com/item?id=30869427
| staticassertion wrote:
| https://www.youtube.com/watch?v=YIWV5fSaUB8
|
| Jim Browning is an expert in this area and is sort of famous for
| his "scamming the scammers" videos where he hacks, tricks,
| annoys, or otherwise scams scammers.
|
| In the linked video he talks about how he was tricked into
| deleting his account. These things can happen to anyone, even
| experts.
| skeeter2020 wrote:
| I appreciate that the OP calls out his bias towards bank
| mismanagement and "the system". Scammers (like this one) are
| using the stereotype to run their scams. Are bank systems often
| disjointed bureaucracies and less than stellar examples of best
| practices? Absolutely, but scams are so common now I believe it's
| time that we accept them as the default conclusion until proven
| otherwise.
| bombcar wrote:
| You see this over and over again in the crypto space; scammers
| are very good at imitation the "group" and using that to their
| advantage.
| anonsec123 wrote:
| Just being a security engineer doesn't instill you with a
| defensive or paranoid mindset. I work with security analysts who
| use TAILS to browse random websites and security engineers who
| torrent cracked software and install whatever they find directly
| on their baremetal PC/laptop.
| shkkmo wrote:
| I would hope that a security engineer would keep up enough with
| news about security issues to be aware how easy it is to spoof
| numbers for calls and texts.
| BeefWellington wrote:
| There are people in all manner of jobs that are just working
| a job and don't have a significant interest in learning all
| they can about their area of employment. IME security has a
| lot of people who see it as a hot new thing but don't
| actually invest their time and attention into maintaining an
| appropriate level of awareness.
| shkkmo wrote:
| Phone calls are one of the primary means of communication.
| If you aren't aware of how it can be compromised, you are
| not capable of adequately assessing security.
|
| It is not like the spoofibility of phone numbers is some
| security industry specific news. It gets talked about all
| the time outside of tech given the prevalence of spam
| calls.
| badrabbit wrote:
| I work with phishing content on a daily basis, ashamed to say I
| fell for a scam on a dating app once, but I was careful enough to
| use a burner credit card, cancelled it right away with no loss to
| myself. I don't think I can fend off a well planned scam or phish
| no matter how careful I am. At the end of the day I have to be a
| normal human being with predictable weaknesses and psychological
| vulnerabilities. Instead, I try to rely on security controls that
| don't rely on my psychological hardening.
| rmbyrro wrote:
| Any reasonable bank would freeze the card before even contacting
| you.
|
| If they want a confirmation, they'd rather use an automated
| method. Like send an SMS: "Did you spend $X on Merchant, Inc?
| Reply with Yes or No".
|
| They can't afford a human calling you for every fraud suspicion.
| SunlightEdge wrote:
| I have a dumb fraud story.
|
| A fraudster called me up (I knew it was a fraudster right away).
| I played along as he said there had been some fraudulent activity
| on my account - payments from random locations etc.etc.
|
| The crux was that he wanted to send me a verification code from
| PayPal. This is where I was dumb. I assumed it was from a fake
| PayPal messaging system and they knew the number already. When
| they asked me to repeat it back to them I pretended to be dumb
| and gave a fake number back, repeatedly. I at first thought they
| knew the number. It then hit me that they didn't know the number
| and were actually trying to break into my PayPal account. I was
| so dumb! Still no bad outcome other than me looking stupid.
| projektfu wrote:
| I got a call from a bank and they said they wanted to verify my
| identity. I said, all due respect but you called me. I need to
| verify your identity. They sounded offended but told me how to
| continue the discussion when I called back. It was a legitimate
| call.
|
| I was pretty annoyed that they didn't follow good identity
| practices by encouraging their customers to trust people who
| could be scamming them.
| marcus_holmes wrote:
| "all due respect" in this case being none.
| mnw21cam wrote:
| I used to get a call every two months from a service I actually
| use, to arrange their next delivery. The first thing they ask
| is for my date of birth and address so I can pass their
| security checks. Each time, there has been a _really_ awkward
| silence for a few seconds when my response is "Nope".
| bennyp101 wrote:
| Seems like this is more a story type thing?
| awinter-py wrote:
| > A lot of the credit that I gave Barry came from my lack of
| faith in my bank's systems and security. ... Insecure business
| practices often don't stand out as a sign of a con; they just
| look like another boneheaded but authentic policy.
|
| ^ _THIS_. your bank is training you to get phished. your health
| insurance, by leaving fake-urgent voicemails that require
| miserable phone tree navigation when you call back, and by having
| a million different numbers which resolve to 'scam or at least
| spam' aggregator sites when you google them, is teaching you to
| get phished.
|
| my health insurance has a process which involves calling me and
| asking for a bunch of personal information. I called them back at
| a known number to ask if this was their number and _they didn 't
| know_. I called three agents and they gave me three different
| answers. One said it was a 'system error that will be resolved in
| 24 hours'. Another said it was fake, don't trust it. A third
| _called the number_ while I was on hold and assessed it as
| 'probably fine'.
|
| teach someone to get phished and they're phished for the rest of
| their life
|
| never accept inbound calls
| testudovictoria wrote:
| Part of the problem with this is the horrible business
| practices and policies in place. In a way, it is urgent that
| you get back to your health insurance rep or your car insurance
| rep or whatever private business that's selling you a
| government mandated service. That phone rep knows that you only
| have 15 more days to finish your insurance claim, or you've
| gone past the deadline. Then when you call back, the rep can't
| do anything. Terrible business policy doesn't allow them to.
| Something like this happened to me.
|
| I had an issue once with a claim. It was an ongoing ordeal with
| lots of small meetings and documentation. It was eventually
| denied. However, I had a rebuttal window. Unfortunately for me,
| it came during a stressful period of work. I made the initial
| call to my rep. No call back. I was buried under work, and the
| 5 day rebuttal window (how absurdly short) blew by without me
| realizing it. Turns out the rep was on vacation, and after my
| case was closed, there was no reason for them to return my
| call.
|
| These issues are never a matter of urgency that should be dealt
| with in that instance. However, don't let your window of
| opportunity close due to an adversarial business policy.
| sidewndr46 wrote:
| I had some healthcare provider just never bill me. 9 months
| later they called and then asked to verify my identity....by
| having me give them my social security number. Over the phone.
| I declined.
| DFHippie wrote:
| > teach someone to get phished and they're phished for the rest
| of their life
|
| This is a keeper.
| higeorge13 wrote:
| ^this 100% I stopped accepting calls from unknown numbers,
| stopped reading messages from unknown numbers and every email
| from unknown contacts marked as spam. I don't care about their
| offers and crap. If they need anything important they know how
| to properly reach me directly and not through agents and random
| crap.
| evandale wrote:
| >A third called the number while I was on hold and assessed it
| as 'probably fine'
|
| This blows me away. Probably fine? That's the worst possible
| answer IMO.
| smm11 wrote:
| I got the same call, but it really was my bank!
|
| Hey, wait a second.
| furyofantares wrote:
| I firmly believe that anyone can get scammed if they're caught on
| a bad day and the scammers happen to get lucky with some details
| or approach that happens to match something the target is
| inclined to believe.
|
| I don't believe scams are typically designed to maximize success
| rate per scam; they're designed to cast a very wide net and get
| lucky on a few targets.
| dr_orpheus wrote:
| I believe I saw this exact same scam on another recent Hacker
| News article. Same premise of "I'm from the bank and you are a
| victim of fraud and I need to deactivate your Apple pay but I am
| actually activating my own Apply pay with your card"
|
| Also had a similar title along the lines of "I give presentations
| on scams and I still got scammed"
___________________________________________________________________
(page generated 2022-04-21 23:02 UTC)