[HN Gopher] I'm a security engineer and I still almost got scammed
       ___________________________________________________________________
        
       I'm a security engineer and I still almost got scammed
        
       Author : trauco
       Score  : 194 points
       Date   : 2022-04-21 13:11 UTC (9 hours ago)
        
 (HTM) web link (robertheaton.com)
 (TXT) w3m dump (robertheaton.com)
        
       | staticassertion wrote:
       | Here's the thing. Phones fucking suck. Anyone can call anyone,
       | and that's insane. It's like the phone book, it's a dated concept
       | that just does not scale.
       | 
       | Phone numbers as a proxy for "who is calling me" is terrible.
       | Numbers change, numbers can be spoofed, numbers can be stolen.
       | All identification that happens via a phone is fundamentally
       | _bad_ and it is only getting worse.
       | 
       | The trick is, don't use phones. Really. Block every number that
       | isn't someone you know, for starters. If someone calls you and
       | it's a bank ask them to contact you via email, and only use the
       | phone to confirm what has already been discussed via email - for
       | example, if you are performing a wire transfer, initiate that via
       | email, and if you confirm information via the phone never _offer_
       | any information, just validate what they say.
       | 
       | This issue is so common and pervasive that, as the author
       | demonstrates, we just assume _everything is horribly broken_ and
       | when something is suspicious we just think  "well, everything's
       | horrible, so why wouldn't this be horrible?".
       | 
       | "Silly but plausible" - this is the cost of security theater. I
       | have to jump through hilariously stupid loops sometimes.
       | 
       | But ultimately I blame phones being used as proxies for identity.
        
       | KSPAtlas wrote:
       | Can this be a case of survivorship bias, but flipped?
        
       | Toreno96 wrote:
       | The article references another one of the author's articles:
       | https://robertheaton.com/2019/06/24/i-was-7-words-away-from-...
       | 
       | I find it quite amusing that the scam used the domain
       | `people.ds.cam.ac.uk`, which contains `s.cam`.
        
       | [deleted]
        
       | mongol wrote:
       | I once was called by my bank on a Sunday. They told me someone
       | had found my credit card at a parking payment machine where I
       | parked approximately 10 minutes earlier. That was a legit and
       | reasonably urgent call. I could go and get it from the couple
       | that found it at a nearby cafe.
        
       | vasco wrote:
       | If your card is stolen and you become a victim of fraud, and they
       | manage to take money from your account, and your bank already
       | knows its fraud, there's no urgency on your end.
       | 
       | You'll get your money back. I'd go as far as saying that if the
       | bank genuinely wants you to decide fast, it's not to protect you.
       | It's to protect itself. Shenanigans about "do it fast or they'll
       | take more" are bullshit always. The bank is on the hook, not you.
       | So never do things in a rush, take your time to verify yourself
       | that money indeed disappeared. There. is. no. urgency.
       | 
       | Sense of urgency is one of the best ways to make people do bad
       | decisions. Salespeople use it, scammers use it. Nobody who is
       | trying to be helpful will come with a story "that needs to be
       | fixed now!!!".
       | 
       | If you still want to be safe, and you use a debit card, have 2
       | accounts. One with the bulk of your money without a card
       | associated with it. One with the card associated with it and no
       | more than whatever you spend in a week. If you use a credit card,
       | it totally doesn't matter, it's the banks money, not yours that
       | they'd steal.
       | 
       | So whenever you find yourself in a situation where someone wants
       | you to decide something fast that you didn't know about and isn't
       | a direct threat to your life, don't do it. Think about it first.
       | 
       | It's impossible to keep up with all the scams, but if you stop to
       | think and never take rash decisions you don't have to. Slow is
       | safe.
        
         | sidewndr46 wrote:
         | If someone wipes out my bank account and I can't pay any bills,
         | am I liable for those charges? What about the associated late
         | charges? What about when service is terminated to my home?
         | 
         | If someone takes money from my account, it is absolutely
         | urgent.
        
           | hawkesnest wrote:
           | This is the primary reason why I stopped using my bank card
           | for anything but the ATM at said bank. A scammer wiping out
           | my checking account is more than an inconvenience, even if
           | the bank only needed a day or so to replenish the account.
           | 
           | Now I use a "proper" credit card for anything. If a crook
           | manages to run up a tab on that thing I still have all my
           | cash for whatever scrapes may come along.
        
         | kube-system wrote:
         | Yep. In the US, you are not liable for any fraudulent
         | transactions reported within 60 days. You can easily wait until
         | you get your next statement.
        
           | Zircom wrote:
           | That's assuming the bank actually finds the transaction(s)
           | were fraudulent when they do their "investigation". If they
           | disagree with you and decide it wasn't fraudulent for
           | whatever reason it's quite often a giant pain to argue with
           | them and get it sorted out.
        
             | kube-system wrote:
             | I'm saying that if a bank calls you and _they already
             | suspect that a transaction is fraudulent_ , you don't have
             | to answer the phone right away.
        
             | kingcharles wrote:
             | Exactly this. I bought something online. The company
             | shipped it, but FedEx screwed up and sent it back to the
             | merchant. The merchant never responded to me after that and
             | then went bankrupt. I called my bank (Square) and they said
             | it wasn't fraud as the package had been "delivered". I
             | pointed out it had been delivered back to the merchant, and
             | they said that still counted as delivered in their support
             | script. They told me the only way to fix it was to call
             | FedEx and somehow scam them into changing the status of the
             | package online. I tried to get them to change their support
             | script but they decided it was easier just to terminate my
             | account instead.
        
             | mannykannot wrote:
             | There was a relatively recent case of Bank of America
             | deciding eight months later that it wasn't a fraud and
             | clawing back their provisional refund. It turns out that
             | the original card was intercepted in the mail and they
             | simply issued a duplicate without preventing the use of the
             | first, but it took the victim's attorneys to get the
             | evidence from the bank, connect the dots and figure out
             | this happened.
        
               | jasinjames wrote:
               | I'd love to read about this. Could you link an article?
        
               | mannykannot wrote:
               | https://www.nj.com/news/2022/03/bank-warns-customer-
               | of-1200-...
               | 
               | I got some details wrong; in particular, the initial
               | dispute denial was after two months (with the Consumer
               | Financial Protection Bureau agreeing with the bank after
               | another two months), and the resolution followed NJ
               | Advance Media contacting BofA.
        
             | zeroonetwothree wrote:
             | The burden of proof is on the merchant. If they don't have
             | a signed receipt or video evidence they probably can't win
             | (so any online purchases are doomed). I've never failed a
             | dispute in around 25 times, including several in the range
             | of $2k+
        
               | kingcharles wrote:
               | No it's not. It's on you to persuade the bank it was
               | fraudulent. If the bank doesn't believe it is fraudulent
               | then they won't claw the money back from the merchant.
               | Source: personal experience.
        
               | kube-system wrote:
               | The bank is required by law to provide you the evidence
               | supporting their decision -- if you request it.
               | 
               | 12 CFR SS 1026.13 (f)(2)
               | 
               | https://www.law.cornell.edu/cfr/text/12/1026.13
        
               | kingcharles wrote:
               | Thank you, I will use this. I'm about to contact their
               | head of legal.
        
               | [deleted]
        
             | merlincorey wrote:
             | This exact scam happened to a coworker's wife and the bank
             | refused to consider it fraud since she "authorized" it by
             | giving the confirmation code for Apple Pay to the attacker.
        
               | staticassertion wrote:
               | This is one of the nice things with credit cards. I've
               | never had an issue with a chargeback, and in the case
               | where a card was stolen the charges were just reversed.
        
               | kube-system wrote:
               | I find it interesting that this is the level of detail
               | discussed with the bank. Our family has had 3 instances
               | of unauthorized charges over the years, and the most
               | we've ever done was to sign a form that basically says
               | "we didn't make these charges"
               | 
               | Did they volunteer these details or were they asked? This
               | is just conjecture, but sometimes when people volunteer
               | too much information to front-line support you can get
               | erratic responses if they latch on to superficial parts
               | of the story rather than the underlying message.
               | 
               | i.e. support just hears "I gave someone access", and they
               | close the ticket under "customer authorized someone else
               | to purchase", because they're following a decision tree,
               | not analyzing the root cause of a security incident.
        
               | turtlebits wrote:
               | In general, banking customer service sucks. I try to buy
               | everything on my AMEX. Their service is excellent. I've
               | never had to fill out a dispute form or give them any
               | kind of proof when disputing a transaction, just a short
               | call and they take care of it.
        
         | manapause wrote:
         | I had a friend who had their bank account cleaned out by a wire
         | transfer of 200K in the same week he is trying to close on a
         | house.
         | 
         | The bank executed on their promises of no disruption to his
         | transfers; they told him he did not have to worry and the
         | customer service was so terrific, he said he was going to stay
         | with the bank.
         | 
         | "Did you ask if there were other accounts at the bank that had
         | been accessed in this way?"
         | 
         | "A wire transfer to an international location went through with
         | no red flags and 0 notifications?"
         | 
         | "Can you ask your security department to produce a report of
         | their investigation into the matter?"
         | 
         | Nobody asks those questions.
        
         | skeeter2020 wrote:
         | I'm well aware of the (lack of true) financial implications but
         | I still get the urgency and need to speed up because of the
         | violation and shock that someone is impersonating me RIGHT NOW!
         | It feels similar to a physical threat, or enough so that our
         | bodies react the same way. It is really hard to develop control
         | unless you're exposed to this situation, so I like your strict
         | yet general rule to (a) classify the situation, (b) slow down.
         | Even enough time for 10 deep breaths is likely enough to get
         | you centered and thinking clearly.
        
         | toraway1234 wrote:
        
       | lr1970 wrote:
       | Virtually identical story of the scam with ApplePay was here 3
       | weeks ago. The victim was a scam prevention expert:
       | 
       | https://news.ycombinator.com/item?id=30869427
       | 
       | EDIT: silly typos
        
       | softwarebeware wrote:
       | This was a great read. I think the biggest takeaway I had was how
       | some banks and credit card companies themselves are not doing a
       | great job at building trustworthy systems. That leads consumers
       | into treating things that seem gray, like confirmation code texts
       | coming from unknown numbers, as credible.
        
       | smbv wrote:
       | Dupe: https://news.ycombinator.com/item?id=31100336
        
       | ed25519FUUU wrote:
       | The problem is definitely still the security of banks. They
       | regularly call YOU and tell you that you have to verify yourself.
       | It's an incredibly stupid system.
        
       | xyst wrote:
       | In this day and age, how do people still fall for this? This
       | isn't the old days where you would get a physical paper statement
       | in the mail every 30 days and rely on your bank to call you for
       | potentially fraudulent purchases.
       | 
       | You have instant access to your financial information. You can
       | easily see "pending" and "posted" charges on your credit accounts
       | without a third party.
        
       | alias_neo wrote:
       | > Nothing the bank might want to talk about could be urgent
       | enough to interrupt an unseasonably sunny March afternoon.
       | 
       | Wrong. Some banks, and with certain account types, the bank will
       | absolutely make a courtesy call to you if something unusual is
       | happening.
       | 
       | I had a call from my bank while spending a few hundred on
       | cocktails in Bali (I'm from London), I hadn't used my card yet on
       | that trip as I'd taken cash.
       | 
       | They also called me to check a payment into my account with an
       | "unusual" reference; a joke from a friend returning the money he
       | owed for a holiday I paid for, but which made it look like he was
       | paying me for "special services".
       | 
       | They called me to query a payment at a home furniture store for a
       | couple thousand pounds in a city ~300 miles from where I live
       | only hours after I'd used the card near home; I'd driven to this
       | particular store to check out the furniture.
       | 
       | If you're not sure, the _real_ bank will suggest you hang up and
       | call their number found on your card or their website (or in your
       | contacts list, where I keep it) and will never pressure you to
       | answer or provide them information, and they'll NEVER, EVER ask
       | you to read a security code out to them sent to your phone, or
       | using your banking app.
       | 
       | EDIT: To further clarify; my particular bank's app, has, on
       | rotation, a series of warnings, displayed each time I log in,
       | saying things like "BEWARE; if someone [calls/texts/etc]
       | asking/telling you to do [XYZ] ...", e.g. to get this code or
       | that code, or do something else in this app, you're being
       | scammed, "WE WILL NEVER ASK YOU FOR [XYZ]...".
        
         | jrochkind1 wrote:
         | I'm not at all confident that the real bank will never actually
         | ask for you to verbally read a security code texted to you.
         | This is how little I trust bank's security practices.
         | 
         | Here's a comment from a similar post last month, where the
         | commenter believes the legit bank asked for a verbal
         | confirmation of security code:
         | https://news.ycombinator.com/item?id=30875233
         | 
         | (I suppose it's possible the commenter was actually interacting
         | with a scammer there and still doesn't realize it?)
        
           | IG_Semmelweiss wrote:
           | I agree with you. I think there might be a distinction btw
           | inbound and outbound.
           | 
           | I think reading any code during inbound call is red flag for
           | fraud. However, more than once _i_ took the initiative to
           | call ccs to unblock a large  / international charges. The
           | only way for the bank to verify my identity is for me to read
           | the code.
           | 
           | So it is not true that you NEVER read ever. Maybe for inbound
           | this should be true. But not outbound
        
           | alias_neo wrote:
           | > I told him, the 2FA message literally says to never give
           | this number out to anyone
           | 
           | He was 100% being scammed.
        
             | mint2 wrote:
             | If you called in to Amex using the number on the card for
             | certain things like fraud, for a while they would then text
             | you a code in a message that says:
             | 
             | "Amex Fraud Free Msg: Your requested code is: xxxx. We
             | won't call to ask for it. Don't share it. Call ######## if
             | you didn't request it. Reply STOP to opt out."
             | 
             | You wouldn't be the requesting this text and code, the
             | person on the phone would. And it says don't share it.
             | Maybe I was hoodwinked but it seemed really legit although
             | in principle I refused to give it.
             | 
             | It seems so scammy, but I'd called the number on the back
             | of the card.
        
             | bombcar wrote:
             | Banks are dumb, really dumb, and they don't align. I have
             | personally _called_ the number on the card, and been asked
             | to verify the phone by repeating a number they would send,
             | which came with the standard  "nobody will ask for this
             | number".
             | 
             | I presume because I initiated the call they think it's ok,
             | but it's still silly.
        
             | jrochkind1 wrote:
             | And still doesn't realize it some time later? (I guess we
             | don't know how much time later).
             | 
             | That would be stunning in it's own way! What a world.
        
         | kergonath wrote:
         | > I had a call from my bank while spending a few hundred on
         | cocktails in Bali (I'm from London), I hadn't used my card yet
         | on that trip as I'd taken cash.
         | 
         | Mine dit that as well a couple of times (Santander UK; my
         | account was nothing special though I do travel internationally
         | several times a year; it was a mistake every time and I never
         | had any fraud with this card). The first time I took it, but
         | now I would say that I cannot, end the discussion, and then
         | call them to their known number. Also, I've never had a human
         | ask me to read numbers from a text message. They (well, another
         | bank, but still) do occasionally ask me to unlock their app
         | using either biometrics or a PIN; they can see it in real time
         | and that can only be done on a single pre-approved device.
        
         | cowvin wrote:
         | Yeah, you can tell a lot by the attitude of the caller. A
         | person once called my wife telling us about a potential
         | fraudulent transaction on one of our credit cards. She was a
         | bit worried so she came over and got me. The person started
         | asking her about whether she made a purchase at this time, etc.
         | I jumped in and told her to stop talking to the guy and call
         | the credit card company back. The person chuckled and said
         | "okay, sounds good."
         | 
         | We called the credit card company and there was indeed a
         | fraudulent purchase, so yeah the real companies don't pressure
         | you into unsafe things.
        
       | jve wrote:
       | Uh, I'v got similar calls.
       | 
       | Here you can watch video for taking down one of these call
       | centers by police, not so long ago:
       | https://www.delfi.lv/news/national/criminal/video-latvija-ai...
        
       | nonrandomstring wrote:
       | We already covered this, but advice distilled from earlier
       | comments bears repeating;
       | 
       | One special class of vulnerable targets is _security experts_ ,
       | and _top ranks_. I remind my students that  "pride comes before a
       | fall" and nobody is immune. While doing some training for <BIG
       | INTERNATIONAL BANK> someone told me they call it the "cocks
       | problem". It's the handful of 7 figure salary high flyers that
       | get regularly pwned and cause grief for everybody else, because
       | they are "too cocky". Lowly secretaries and desk staff are much
       | harder marks. The more training you give to people who think
       | they're above it the worse they get. It has to be pitched as
       | participatory advice, as an invitation to co-create a secure
       | practice.
       | 
       | We saw this cavalier attitude just the other day with Boris
       | Johnson [0]. I bet Johnson was told time and again to use
       | equipment that had been checked by his security detail. And I
       | still cringe thinking of this one [1].
       | 
       | I suggest there's no correlation between domain knowledge and
       | behavioural invulnerability. Good security posture is a mind-set.
       | I also think it's a very strange combination of contradictory
       | qualities (or attitudes you can be trained to adopt) that are
       | hard to describe, such as high conscientiousness and humility
       | mixed with utterly cynical disrespect for "authority", high
       | openness but brutally meticulous self-checking and introspection.
       | And definitely, never call yourself an 'expert'.
       | 
       | [0] https://news.ycombinator.com/item?id=31075558
       | 
       | [1] https://www.arrse.co.uk/community/threads/77-bde-twitter-
       | fee...
        
         | resoluteteeth wrote:
         | It sort of reminds me of this: https://driving.ca/auto-
         | news/news/why-advanced-driver-traini...
         | 
         | I guess the common factor is that the most important thing is
         | to be careful and follow the proper procedure to not get caught
         | in a problematic situation in the first place, not to be
         | overconfident and assume you are safe because you can handle
         | any situation with your knowledge or skills.
        
           | nonrandomstring wrote:
           | > procedure to not get caught in a problematic situation in
           | the first place
           | 
           | Totally. I saw this Krav Maga instructor say:
           | 
           | "Now. I'm going to tell you one of the most effective self
           | defence moves known in any martial art... run away!"
        
         | karmakaze wrote:
         | The same shows here:
         | 
         | > security engineers need to design systems that are resilient
         | to them
         | 
         | The problem here, to a security engineer, is that we need
         | better systems. I suspect they mean the hardware and software
         | systems, although the 'system' includes the participants. The
         | problem and solution space should strongly include people as it
         | just was clearly demonstrated.
         | 
         | Could be an occupational hazard, having seen so many insecure
         | and poorly designed system to have low opinions of them. Having
         | low expectation of security practices sets a lower bar for
         | acceptance of what's authentic. I can't say if I would be
         | caught in similar circumstances without being in the moment.
         | The two things I hope I'd do is see the tx in my own history
         | and not tell a human a code. These are for machines to verify.
         | I recall when everyone switched their system so PINs could be
         | entered for machine verification and the human returning after.
         | A machine sent code should also be checked by a machine.
         | 
         | A practice that does bother me greatly is how many different
         | domain names are used by a company. Only subdomains should be
         | used for any kind of official interaction (or perhaps period).
        
       | jrochkind1 wrote:
       | Part of this comes indeed from not trusting the banks -- like, I
       | know the banks do irrational insecure things, and I also don't
       | trust that if I don't do _exactly what they say_ they will
       | actually cover me in case of fraud (which we know does happen, a
       | lot, now).
       | 
       | Like, let's say I insisted on hanging up and calling the number
       | on the back of my phone -- are there any cases that would be
       | disastrous for me, would end up in me losing money, and I really
       | _should_ have stayed on the phone with the person who called me,
       | who really was a non-fraudulent representative?
       | 
       | I'm not confident there are not.
        
         | wccrawford wrote:
         | I think you mean "back of your card".
         | 
         | I honestly believe that there are no cases for that on a
         | _credit card_. On a debit card, that might be different. This
         | is why I never use my debit card for purchases.
        
       | paxys wrote:
       | I'm not a security engineer, but here's the easiest way to
       | prevent 99% of scams - never pick up the phone. If it is urgent
       | they can leave a voice mail, and you can call back by looking up
       | the official number.
        
       | [deleted]
        
       | cameronh90 wrote:
       | I almost got scammed by a SMS that woke me up.
       | 
       | Local couriers often send links by SMS when an international
       | package needs customs duty paid, and they often shorten URLs due
       | to SMS limits. So they might send a URL like couri.er/1ea6dz.
       | Often the payment sites look a little dodgy too, frequently just
       | an un-themed Worldpay form.
       | 
       | Unfortunately I was expecting an international package and an SMS
       | woke me up saying delivery would happen today provided I pay the
       | customs duty. I luckily had gained my senses enough by the time
       | the page had loaded to double check everything, but it could have
       | got me.
       | 
       | When the legit request to pay customs duty came through, it
       | didn't look all that different...
        
       | lamontcg wrote:
       | "Yeah, I *69'd you. I never pick up my phone." -- Tyler Durden,
       | Fight Club.
       | 
       | I'd also logon to the bank website first to look at recent
       | transactions myself so that I "do my own research" before talking
       | to a person at the bank.
       | 
       | Most often the fraud check is something like an apple hardware
       | purchase that I made months ago which only just went through
       | after I got the front of the waiting list. I'd want to debug that
       | stuff myself first. If I'm out doing something and a text/VM
       | comes in while I'm on thumbs I'll happily wait until later that
       | night to debug the problem. Like the top thread here says,
       | there's no urgency.
       | 
       | Really helps to be an introvert where you very actively don't
       | want to call someone up and chat on the phone about shit, so you
       | first seek to avoid having to talk to anyone in person, and then
       | have all the information you can acquire ready first to keep the
       | phone call as short as possible.
        
       | vegai_ wrote:
       | When I get off work, I want to think about silly computer
       | problems as little as possible. Perhaps the same applies to
       | security engineers.
        
       | nottorp wrote:
       | US Banks are so bad that this scenario would be believable? Any
       | security problem where I am would get fixed either via resets on
       | pre established channels or via a visit to the actual bank with
       | ID verification.
        
       | 46Bit wrote:
       | > The internet tells me that caller IDs are easy to spoof, which
       | I didn't know
       | 
       | I really think that security engineers should know this.
        
         | fortran77 wrote:
         | I thought this was a new, subtle, clever scam. It wasn't. I was
         | very surprised he's a "security engineer."
         | 
         | Still, I'm glad he's not embarrassed to share his story, to
         | help others be more aware.
        
         | lr4444lr wrote:
         | What's weird is, this is the sort of thing that many (not all)
         | average people know because it materially happens to them. It
         | doesn't even rise to the level of elementary professional
         | knowledge that you'd expect of all but only of professionals.
        
         | leephillips wrote:
         | After encountering everything from a taxi driver in NYC who
         | didn't know where Grand Central Station was, to a recently
         | hired physics professor with a PhD (Univ. Cal. Davis) who
         | didn't know what a partial derivative was, someone having a
         | particular job title means zero to me. It just means that
         | someone, for some reason, is paying the person to do <job
         | title>. But this guy didn't do too badly, after all.
        
           | tremon wrote:
           | _a taxi driver in NYC who didn't know where Grand Central
           | Station was_
           | 
           | You mean the post office?
        
             | leephillips wrote:
             | No, I mean the largest train station in the world, the
             | central rail hub of the city, a famous landmark and tourist
             | attraction. The official name is Grand Central Terminal,
             | but nobody calls it that (usually just "Grand Central").
        
               | DFHippie wrote:
               | I was curious about the "largest train station in the
               | world" claim. I figured there would be bigger ones by now
               | in India, say, or China. Sure enough, there are different
               | metrics by which different stations can claim to be the
               | largest. Nagoya Station in Japan, for instance, is the
               | largest in floor area. Shinjuku Station, also in Japan,
               | is the busiest by daily traffic. The Gare Du Nord in
               | Paris is the second busiest by this metric. Apparently
               | Grand Central is the biggest in platform capacity.
               | 
               | Anyway, back to the point.
        
               | leephillips wrote:
               | What about volume? Grand Central has a high ceiling.
        
               | softwarebeware wrote:
               | This is why I love Hacker News lol
        
         | rhexs wrote:
         | I think the only qualification for "security engineer" these
         | days is changing your LinkedIn job description to "security
         | engineer". Unlike SWEs, there isn't really any sort of standard
         | leetcode bar for them, which is both a pro and a con.
         | 
         | Lot of snake oil in the field at the moment.
        
           | nonameiguess wrote:
           | That seems the opposite of true. They have pretty
           | standardized certifications in the field. CISSP is much more
           | consistent and predictable and known than random sampling of
           | leetcode questions. Of course, you don't need to score 100%
           | on the exam to pass it, and not being familiar with the
           | content of the exam, I'm not vouching for it or anything. But
           | it is effectively the equivalent of something like a CPA or
           | CFA that Software Engineering has no analog of.
        
             | giaour wrote:
             | If you spend time working in a field that _requires_ a
             | CISSP (like most info sec roles in the US government), you
             | will meet plenty of people who crammed for a test but are
             | otherwise completely incompetent.
             | 
             | I would not recommend viewing the CISSP as anything other
             | than an attestation that someone can memorize a few
             | concepts for a test.
        
             | qzx_pierri wrote:
             | As someone who recently left a security job at a very
             | prestigious and well known organization.. The person you're
             | replying to isn't wrong. Certifications only prove that you
             | took the time to memorize a set of concepts.
             | 
             | > CISSP is much more consistent and predictable and known
             | than random sampling of leetcode questions
             | 
             | Even the CISSP is just a test of memorization - The ISC2
             | cert prep book is 10 miles long, but only about 5 feet deep
             | (if that makes any sense).
             | 
             | Being a good security engineer comes with experience and
             | knowledge of basic scams such as caller ID spoofing
             | (something I did to my friends as a bored 6th grader).
             | Being a good security engineer is having a keen eye for
             | small changes and being skeptical about EVERYTHING.
             | 
             | Any security engineer worth their salt would never discuss
             | anything containing PII on an inbound phone call.
        
               | antonvs wrote:
               | > Any security engineer worth their salt would never
               | discuss anything containing PII on an inbound phone call.
               | 
               | Yeah. Clearly "security" means something different to him
               | than it does to us.
        
             | wglb wrote:
             | There is much doubt about the correlation of CISSP
             | certificate holders and good security engineers.
        
           | staticassertion wrote:
           | I've been a SWE and Seceng. Interviews are extremely similar
           | and extremely easy in both cases. The bar for both is kind of
           | a joke, and it's very much made up.
        
           | briandear wrote:
           | What the heck is a "standard leetcode bar?" Who does leetcode
           | to prove their worth as an SWE?
           | 
           | I know plenty of leetcode aces that couldn't work on a real
           | world application if their lives depended on it. Leetcode
           | might test the ability to write some academic algorithm from
           | some college textbook, but it doesn't test real world.
           | 
           | There is a reason many top companies don't use Leetcode or
           | HackerRank: zero prediction of real world skill or systems
           | thinking.
        
         | neoCrimeLabs wrote:
         | It's true, being a successful information security engineer
         | requires a very diverse understanding of technology and
         | psychology.
         | 
         | Not one person understands all the technology in existence, and
         | no one person ever will.
         | 
         | Also engineers come in different levels of experience. Just
         | because someone doesn't have experience in specific technology
         | doesn't exclude them from being an engineer in a specific
         | field.
        
         | jeroenhd wrote:
         | It all depends on what kind of security engineer this person
         | is. The author writes about computer network attacks, tracking,
         | and privacy violations. If their expertise is in preventing web
         | application attacks, detecting fraudulent operations in the
         | inter-bank payment systems or in finding signs of compromise in
         | a corporate network, there's no reason for them to know about
         | the intricacies of SIP and SS7 and the many faults of the
         | international/US phone network when it comes to trust and
         | abuse.
         | 
         | Really, "security engineer" is as vague a term as "programmer".
         | Web programmers are programmers yet they don't necessarily
         | understand the layout of virtual memory or the way the kernel
         | interacts with userland programs, something many other
         | programmers would consider essential for their jobs. A kernel
         | programmer couldn't give two hoots about how Chrome's CSS
         | engine works, but the vast majority of modern programmers
         | probably do.
         | 
         | I've had lectures in university on natural language processing
         | and data structures that were slowed down because the lecturer
         | couldn't get the beamer to work right with his Macbook. You
         | can't expect someone to know _everything_ , even if it's in
         | their apparent area of expertise.
         | 
         | I'd go so far as to say that any security engineer worth their
         | salt will admit that they too are vulnerable to being scammed
         | under the right circumstances and that anyone pretending to be
         | unscammable is severely overestimating their abilities.
        
         | staticassertion wrote:
         | Security engineers are basically expected to know everything.
         | It's part of why I enjoy the work. But it's also impossible.
         | "Understand the security implications of every nuanced
         | technology decision" is not tractable, so we pick the ones we
         | can and specialize.
         | 
         | POTS is rarely of interest to a security organization. You have
         | very few levers to pull even if you do consider it a threat,
         | since it's just fundamentally an awful system, and you can't
         | tell people "don't use telephones". At best you can train
         | people, but your concern is probably phishing via email.
         | 
         | Only a few people, at the company level, are at risk in terms
         | of this sort of attack, compared to everyone being at risk
         | (with regards to the company) from phishing emails.
         | 
         | So a lot of people just don't really think about it. Security
         | engineers might hand wavingly say "phone numbers can be
         | spoofed" but I'd bet the percentage of seceng that know _how_
         | that works is very small.
        
         | softwarebeware wrote:
         | It was refreshing to read an honest post. If more people were
         | willing to admit they don't know something, the world would be
         | an infinitely better place.
        
         | xyst wrote:
         | I know this because I have done it in the past to mess with my
         | parents, family, and friends (ie, display 666-666-6666 on the
         | caller id)
        
         | dogman144 wrote:
         | Not that I disagree, but I think the majority of sec engs do
         | not deal with telephony or related fraud directly. In companies
         | where fraud with caller ID and responding to it matters, that's
         | often tasked to a fraud team dealing with account takeovers or
         | a user onboarding team that offloads verification to a vendor
         | like Persona -> not a security engineering team.
         | 
         | However, I think it's common knowledge that inbound identifiers
         | like IPs, user agents can be faked and aren't great technical
         | indicators to anchor detections on for longer than an active
         | incident. That intuition should extend to caller ID IMO, if
         | they didn't know it already.
        
         | duxup wrote:
         | I'm imagining this guy giving advice to someone that includes
         | validating by caller id or something ... scary.
        
         | usrn wrote:
         | Too many "security engineers" trust telcos _way_ too much.
        
         | ransom1538 wrote:
         | Anddd.. if you are into anti-scam https://aff.419eater.com/
        
         | csharpminor wrote:
         | One thing that many people don't know is that SMS caller IDs
         | are also being spoofed more frequently. In the article the
         | author mentions noticing that the authentication code came from
         | a number the bank didn't ever use.
         | 
         | Sophisticated scammers can spoof your bank's phone number and
         | send a message that appears in a thread alongside other
         | legitimate SMS from the bank.
         | 
         | This is harder to do than caller ID spoofing, but has become
         | more prevalent recently.
        
         | AnIdiotOnTheNet wrote:
         | A corollary to Sturgeon's Law: 90% of any given field is shit
         | at their job. I've met a lot of "Security Engineers" and I can
         | assure you the pattern holds.
         | 
         | Then again, even the other 10% of any given field that is
         | actually good at what they do still fucks up occasionally, so
         | maybe we needn't judge too harshly.
        
           | HL33tibCe7 wrote:
           | I don't think it's fair to claim that the author is "shit at
           | his job" because he doesn't know some (rather unintuitive and
           | unexpected) trivia about how phone ID works. There are plenty
           | of different roles in security engineering, many of which
           | would never need to be concerned about this.
        
             | carlmr wrote:
             | Also I think just his openness in admitting a mistake he
             | could hide in shame is a sign that he understands his job.
             | 
             | While this is more psychology than technology, that's very
             | important in social engineering.
        
             | giaour wrote:
             | Everyone in the US with a cell phone is getting inundated
             | these days with spam texts and calls with fake caller ID.
             | It's almost inconceivable that someone with an American
             | cell phone wouldn't know that phone ID is a lie, which is I
             | think where some of the incredulity from other commenters
             | is coming from. But I believe the author is from the UK,
             | where the spam situation might not be so dire?
        
               | dwighttk wrote:
               | Huh. I get a bunch of spam calls I ignore, but I don't
               | know how I'd know that any of the caller ID is fake
        
               | giaour wrote:
               | The recent surge in spam texts that show as having been
               | sent by the recipient[0] has driven this point home for a
               | lot of mobile phone users. For me, the fact that caller
               | ID is fake was made evident when a spammer used _my_
               | number as their origin ID for a wave of spam calls and
               | texts, and I got ~100 voice mails and texts the next day
               | kindly asking me to eat shit and die. Verizon support
               | said that there was nothing they could do, that it was
               | happening left and right, and that I was in no way
               | legally or financially responsible for any of the
               | messages purporting to be from me. This was in 2020, and
               | the unreliability of long code origin ID numbers has come
               | up frequently in my work as a security engineer for the
               | past few years.
               | 
               | [0]: https://www.nytimes.com/2022/03/30/business/spam-
               | texts-veriz...
        
               | dwighttk wrote:
               | Hmm. Only get a few spam texts per... quarter. Never seen
               | one from my own number
        
               | staticassertion wrote:
               | That's hilarious. You really think that everyone, or even
               | many people, know that phone numbers can be spoofed?
        
               | tlogan wrote:
               | I think majority of older American is 100% aware of that.
               | 
               | I do see how young adults are still not aware of that
               | since they are not valuable target and their info is
               | relatively unknown (no mortgage on their name, no car
               | loans, cell phone number is not old, they never sign up
               | for sweepstakes in Las Vegas, etc.)
        
               | giaour wrote:
               | Yes. There have been multiple front-page news articles in
               | the NY Times in the past month about people getting spam
               | texts from themselves. The fact that caller ID is
               | unreliable is part of the public discourse today.
               | 
               | FWIW, I had to answer the phone at my first office job in
               | ~2005, and the office manual has a section on how caller
               | ID was not trustworthy caller authentication. None of
               | this is new, and it is odd that a self-described security
               | engineer would blindly trust caller ID.
        
               | staticassertion wrote:
               | Awareness may have grown, but I'd put money on people at-
               | large not knowing anything about caller ID spoofing, both
               | in terms of its existence, and certainly in terms of its
               | accessibility.
        
           | dathinab wrote:
           | More important:
           | 
           | The job of security engineer is a very very wide spread one.
           | Someone might be an expert wrt. detecting avoiding DDoS, RCE,
           | encryption and/or signing that doesn't mean they are an
           | expert in social engineering or phone security.
        
       | briHass wrote:
       | This is the second very similar report on HN where the end-goal
       | was ApplePay. There must be something poorly done in their card
       | linking/payment process that hackers are targetting. I don't use
       | it, so I'm not familiar.
       | 
       | Collectively, we software engineers that have security focus,
       | have done a piss-poor job with 2FA. Users should've been trained
       | from day-one that 2FA codes sent to their email or SMS should
       | never, EVER, be repeated back to a human. All the additional text
       | sent with the code should clearly and emphatically state that
       | this number is between you and a website that you are reasonably
       | certain represents a secured entity and that you explicitly
       | requested during a login flow. It's like the combination to a
       | safe: that code is between you and the dial on the safe, if it
       | ever verbally leaves your mouth, you're doing something wrong.
       | 
       | Any orgs that use 2FA codes to authenticate a user to a CSR are
       | screwing it up for everyone. Don't do that: you should be able to
       | mutually authenticate using shared knowledge that a hacker isn't
       | likely to have (not an address, FFS), like the previous
       | transactions thing the OP requested. 2FA codes are for computers
       | only.
        
         | rowls66 wrote:
         | I don't know for sure, but I suspect, that the reason that
         | ApplePay is being targeted is because other means of credit
         | card fraud at point of sale have become much more difficult
         | with chip cards. ApplePay itself is also quite secure, but the
         | process of enrolling a card in ApplePay is probably the weakest
         | link. The card chip does not provide any added security in the
         | process. I think that most banks use PAN and card security code
         | combined with one time password by email or mobile to verify
         | the cardholder. If a fraudster can crack this nut, and get a
         | card fraudulently enrolled into ApplePay on a phone, they can
         | use the card at point of sale, and point of sale is the ideal
         | fraud target since the fraudster can remain mostly anonymous,
         | and walk out of the shop with the stollen goods.
        
         | ant6n wrote:
         | What pisses me off to no end in Europe is that some banking
         | systems require, in order to do a credit card payment, to
         | provide the online bank account password and online bank
         | account 2fa generated transaction code -- requiring that both
         | be entered as part of the payment process on any merchants
         | website. It's so goddamn stupid I can't believe this exists.
         | It's so easy to fake this and use some sort of man in the
         | middle attack to transfer all money away from an account. Plus
         | it teaches ppl that it's okay to enter one's online banking
         | credentials one-time generated transaction codes into random
         | websites selling u random crap for 3EUR...
         | 
         | I don't understand security researchers. Is it all just a bunch
         | of hooey they sell or what?
        
           | eythian wrote:
           | > It's so goddamn stupid I can't believe this exists. It's so
           | easy to fake this and use some sort of man in the middle
           | attack to transfer all money away from an account
           | 
           | An MitM attack is significantly harder than "I have your CC
           | number and I'll use it with no authentication", therefore it
           | does increase the difficulty for fraud. Though I haven't seen
           | a requirement to enter the bank's password, my one requires
           | me to confirm the transaction by opening the credit card
           | provider's app on my phone which isn't vulnerable in the way
           | you're describing.
        
           | sofixa wrote:
           | Banks are supposed to do MFA. Some, apparently, are crap and
           | require you to login while doing a payment, but most ask for
           | a confirmation with an SMS code or the banks app, both of
           | which contain who the payment is towards, and the amount.
        
       | RadixDLT wrote:
       | "security expert" should be taken with a grain of salt
        
       | herf wrote:
       | 2FA should never be vague - it should say "Don't give this code
       | to anyone." People are getting scammed all the time this way.
        
       | fullstop wrote:
       | > I'm not sure where the 2 missed calls from my bank's real phone
       | number came from.
       | 
       | This sort of thing is incredibly easy to forge these days.
        
       | neogodless wrote:
       | Thought perhaps this was posted previously, but it's just a very
       | similar story.
       | 
       | https://news.ycombinator.com/item?id=30869427
       | 
       | "I'm a scam prevention expert and I got scammed" (544 comments 20
       | days ago)
        
         | perydell wrote:
         | I also thought of this prior post. I believe it is the same
         | scam and written up by someone also claiming to be a security
         | researcher. It seems too on the nose to be a coincidence.
        
         | post_break wrote:
         | Yeah I thought this was the same repost. It's very similar.
        
         | erwincoumans wrote:
         | It is too long-winded. Could the scam story be a scam itself?
        
       | liendolucas wrote:
       | Question: Why banks do not implement bait/decoy codes for people
       | that are aware they are being part of a scam? Wouldn't this
       | provide them at least more information about the scammer? With
       | all the technology that's available, why is not possible to let
       | the scammer believe that he/she is doing a real transaction but
       | behind scenes they are being monitored/traced? I'm asking out of
       | my ignorance on the subject.
        
       | senectus1 wrote:
       | I've recently noticed that I reflexively answer my phone with "
       | _MyName_ speaking ", it occurred to me that this is bad security
       | practice.
       | 
       | Any suggestion on how I should politely and professionally answer
       | a call without giving away my identity?
        
         | xcyu wrote:
         | Just stay silent until the other person speaks.
        
           | mbauman wrote:
           | This is my MO for unknown numbers these days (which I only
           | answer when I have a reasonable expectation of getting a call
           | from a new contact). Automated systems will just disconnect
           | when they think they got a dead line. Humans will go, "uh,
           | hello?"
        
             | dvtrn wrote:
             | I started doing this a few months ago, and the number of
             | spam calls I've gotten from certain area codes that used to
             | call me without fail at least three times a day has dropped
             | _considerably_.
        
         | bena wrote:
         | I just go with "Hello?".
         | 
         | I also don't mind confirming my name. But I try to never say
         | "yes" or "no" when they ask if something is right, I respond
         | with "That is correct" or "That is not correct". That may be me
         | being too paranoid of people editing the conversation to make
         | it look like I agreed to something I didn't.
         | 
         | There was some point where I was getting a call that claimed to
         | be a collection agency trying to collect on a DirectTV bill.
         | I've never had DirectTV. They kept trying to get me to confirm
         | an address, I kept informing them that I've never had DirectTV.
         | They would usually hang up when I would press them on who their
         | employer was. They often made the mistake of calling during my
         | commute when I lived roughly an hour away from my place. So,
         | you know, I had the time to kill.
        
           | ceejayoz wrote:
           | > But I try to never say "yes" or "no" when they ask if
           | something is right, I respond with "That is correct" or "That
           | is not correct". That may be me being too paranoid of people
           | editing the conversation to make it look like I agreed to
           | something I didn't.
           | 
           | It's not overly paranoid. https://www.ag.state.mn.us/consumer
           | /Publications/CanYouHearM...
           | 
           | > The details of this scam vary, but it always begins with a
           | call, usually from a telephone number that appears to be
           | local. When the person answers the call, the scam artist
           | tries to get the person to say "yes"--most often by asking,
           | "Can you hear me?," "Is this the lady of the house?," or a
           | similar question. By responding "yes," people notify robo-
           | callers that their number is an active telephone number that
           | can be sold to other telemarketers for a higher price. This
           | then leads to more unwanted calls.
           | 
           | > In some cases, the caller may record the person saying
           | "yes." Scam artists may be able to use a recorded "yes" to
           | claim that the person authorized charges to his or her credit
           | card or account.
           | 
           | Used to be used a whole bunch for
           | https://en.wikipedia.org/wiki/Cramming_(fraud) back in the
           | days when you could subscribe to things via your phone bill.
        
             | bena wrote:
             | Good to know, I guess. On some level.
             | 
             | I've probably read something similar at some point, made
             | the change, and forgot the source that made me wary of it.
             | Cutting the ends of the roast as it were.
        
         | bombcar wrote:
         | Roadkill Cafe, you kill it, we grill it, how can I help you?
        
           | vlachen wrote:
           | Drinkwine Mortuary, You stab 'em, we slab 'em!
        
         | krageon wrote:
         | > Any suggestion on how I should politely and professionally
         | answer a call without giving away my identity?
         | 
         | I use "hello". It's pretty rude compared to how I was raised,
         | but it's also the only way to not give scam calls the ammo they
         | need to mess with me. So I can live with rude.
        
         | gre wrote:
         | I'm hostile to anyone who calls me until they deserve
         | otherwise. Just "hello", "mhmm", "mnnn" kind of grunts. Kind of
         | sad but 95% of phone calls that I don't know are from
         | scammers/telemarketers.
        
         | Angostura wrote:
         | Many years ago, I changed to simply using "Yes, hello?"
        
         | mattw2121 wrote:
         | Hello?
        
         | ceejayoz wrote:
         | Let it go to voicemail, and have your voicemail greeting say
         | "please send me an email instead".
        
         | jrootabega wrote:
         | First name only isn't that bad, right?
        
         | mikequinlan wrote:
         | Many people nowadays just answer 'Hello'. I do that and if I
         | don't get a response after a few seconds I hang up.
        
         | vegetablepotpie wrote:
         | I've taken up the practice of just not answering the phone.
         | Nothing good ever comes of it.
         | 
         | If it's important, they'll leave a voice mail and I can call
         | them back.
        
           | eks391 wrote:
           | A direct answer to your question, and depending on the
           | cultures of where you live, you could say something like
           | Hello, whom do I have the pleasure of speaking with? But
           | that's very southern, so I could see many people not feeling
           | that. I say Howdy, what may I do for you today?... Which I
           | now recognize is also southern... But there's a lot of things
           | you could say that distract from identifying yourself.
           | 
           | Along the topics others are replying with, I also don't
           | answer calls usually, and have a call blocker so I'm only
           | notified if someone from my contacts list is calling or if
           | they are recognized by my network carrier as a verified
           | business. Since businesses can also be spoofed, I still don't
           | give any information and find out why they are calling, then
           | politely hang up and call back myself, after first verifying
           | the number in about to call is actually associated with the
           | business.
        
           | enlyth wrote:
           | My apartment has almost no phone signal so I started leaving
           | my phone on airplane mode. Best decision I've ever made, it's
           | been like this for 6 months now without issues. With friends
           | and family I call through facetime/whatsapp/etc. anyway.
           | 
           | It also makes the battery last twice as long.
        
             | leephillips wrote:
             | Doesn't airplane mode also turn off the WiFi radio? Maybe
             | it depends on the phone. But if it does, how can you use
             | WhatsApp, etc.?
        
               | BenjiWiebe wrote:
               | You can turn WiFi back on.
        
               | leephillips wrote:
               | Haha. I actually knew that and have done it, but forgot
               | that it was possible. Thanks.
        
           | Timothycquinn wrote:
           | Agreed - As a minimum if the caller has no caller ID I don't
           | answer unless I'm expecting such a call. If I answer the
           | phone and get a long pause or clicks before I'm talking to
           | someone, I'm very dubious of who I'm talking to and get their
           | name and phone number so I can do quick background check and
           | call them back.
           | 
           | With that said, I almost got duped by a good samaritan debit
           | card scam about 20 years ago in Toronto.
        
           | TillE wrote:
           | Seriously, for the vast majority of people, the number of
           | legitimately urgent calls from strangers is going to be
           | vanishingly small. Why even bother answering?
           | 
           | Credit card fraud is not urgent unless maybe you know your
           | card has been deactivated. They can leave a quick message if
           | your relative is in the hospital or whatever.
        
           | wintermutestwin wrote:
           | Yes, but then they do the same and it is endless phone tag
           | which usually ends in "you can email me at blaa."
           | 
           | The telephone is broken.
        
           | daniel-cussen wrote:
           | Today, for sure, the phone is dead. But it could come back.
        
         | suprfsat wrote:
         | "Hello" -- Thomas Edison
         | 
         | "Ahoy" -- Alexander Graham Bell
        
         | postsantum wrote:
         | Drop the call and send an SMS saying "Busy now, please let me
         | know when it would be best to call you back"
        
         | bell-cot wrote:
         | If I don't recognize the #, "Tech. Support, do you have a
         | Contract # or Incident #?". Backed by a brusque "very busy
         | professional, required to bill his hours" attitude. Human cold
         | callers often identify with that - enough to either end the
         | call fast, or to try no "hooks" to keep me on the line when I
         | end it.
        
         | wglb wrote:
         | I've often answered calls from unknown numbers with "This is
         | Security" in my most formal voice. Nowadays, I don't answer
         | unknown numbers at all.
        
       | koala_man wrote:
       | > I got through to the bank, but they couldn't work out why they
       | had called me.
       | 
       | The bank said "we have no record of calling you" and it didn't
       | stop there?
        
       | scoot wrote:
       | Similar to another recent post: "I'm a scam prevention expert and
       | I got scammed"
       | 
       | https://news.ycombinator.com/item?id=30869427
        
       | causality0 wrote:
       | _I made a note to check my account when I got home_
       | 
       | It would take more than thirty seconds to go online and check the
       | account?
       | 
       |  _"I'm calling about some suspicious transactions on your account
       | ending in 1234. Is this a good time to talk?"_
       | 
       | I don't know how it works there, but my bank's fraud alert call
       | is automated and exactly the same every time.
       | 
       |  _"I'd like to enable enhanced security on your account, but I'll
       | need to text you a confirmation code first. Is that OK?"_
       | 
       | Do banks do that there? Mine won't make any kind of account
       | changes unless I show up in person with ID.
       | 
       |  _Barry couldn't use my card to buy anything online because my
       | bank sends me a one-time verification code whenever I use the
       | card on a new website._
       | 
       | This is great. All banks should do that.
        
       | scott_s wrote:
       | Basically the same scenario as this HN submission: "I'm a scam
       | prevention expert and I got scammed",
       | https://news.ycombinator.com/item?id=30869427
        
       | staticassertion wrote:
       | https://www.youtube.com/watch?v=YIWV5fSaUB8
       | 
       | Jim Browning is an expert in this area and is sort of famous for
       | his "scamming the scammers" videos where he hacks, tricks,
       | annoys, or otherwise scams scammers.
       | 
       | In the linked video he talks about how he was tricked into
       | deleting his account. These things can happen to anyone, even
       | experts.
        
       | skeeter2020 wrote:
       | I appreciate that the OP calls out his bias towards bank
       | mismanagement and "the system". Scammers (like this one) are
       | using the stereotype to run their scams. Are bank systems often
       | disjointed bureaucracies and less than stellar examples of best
       | practices? Absolutely, but scams are so common now I believe it's
       | time that we accept them as the default conclusion until proven
       | otherwise.
        
         | bombcar wrote:
         | You see this over and over again in the crypto space; scammers
         | are very good at imitation the "group" and using that to their
         | advantage.
        
       | anonsec123 wrote:
       | Just being a security engineer doesn't instill you with a
       | defensive or paranoid mindset. I work with security analysts who
       | use TAILS to browse random websites and security engineers who
       | torrent cracked software and install whatever they find directly
       | on their baremetal PC/laptop.
        
         | shkkmo wrote:
         | I would hope that a security engineer would keep up enough with
         | news about security issues to be aware how easy it is to spoof
         | numbers for calls and texts.
        
           | BeefWellington wrote:
           | There are people in all manner of jobs that are just working
           | a job and don't have a significant interest in learning all
           | they can about their area of employment. IME security has a
           | lot of people who see it as a hot new thing but don't
           | actually invest their time and attention into maintaining an
           | appropriate level of awareness.
        
             | shkkmo wrote:
             | Phone calls are one of the primary means of communication.
             | If you aren't aware of how it can be compromised, you are
             | not capable of adequately assessing security.
             | 
             | It is not like the spoofibility of phone numbers is some
             | security industry specific news. It gets talked about all
             | the time outside of tech given the prevalence of spam
             | calls.
        
       | badrabbit wrote:
       | I work with phishing content on a daily basis, ashamed to say I
       | fell for a scam on a dating app once, but I was careful enough to
       | use a burner credit card, cancelled it right away with no loss to
       | myself. I don't think I can fend off a well planned scam or phish
       | no matter how careful I am. At the end of the day I have to be a
       | normal human being with predictable weaknesses and psychological
       | vulnerabilities. Instead, I try to rely on security controls that
       | don't rely on my psychological hardening.
        
       | rmbyrro wrote:
       | Any reasonable bank would freeze the card before even contacting
       | you.
       | 
       | If they want a confirmation, they'd rather use an automated
       | method. Like send an SMS: "Did you spend $X on Merchant, Inc?
       | Reply with Yes or No".
       | 
       | They can't afford a human calling you for every fraud suspicion.
        
       | SunlightEdge wrote:
       | I have a dumb fraud story.
       | 
       | A fraudster called me up (I knew it was a fraudster right away).
       | I played along as he said there had been some fraudulent activity
       | on my account - payments from random locations etc.etc.
       | 
       | The crux was that he wanted to send me a verification code from
       | PayPal. This is where I was dumb. I assumed it was from a fake
       | PayPal messaging system and they knew the number already. When
       | they asked me to repeat it back to them I pretended to be dumb
       | and gave a fake number back, repeatedly. I at first thought they
       | knew the number. It then hit me that they didn't know the number
       | and were actually trying to break into my PayPal account. I was
       | so dumb! Still no bad outcome other than me looking stupid.
        
       | projektfu wrote:
       | I got a call from a bank and they said they wanted to verify my
       | identity. I said, all due respect but you called me. I need to
       | verify your identity. They sounded offended but told me how to
       | continue the discussion when I called back. It was a legitimate
       | call.
       | 
       | I was pretty annoyed that they didn't follow good identity
       | practices by encouraging their customers to trust people who
       | could be scamming them.
        
         | marcus_holmes wrote:
         | "all due respect" in this case being none.
        
         | mnw21cam wrote:
         | I used to get a call every two months from a service I actually
         | use, to arrange their next delivery. The first thing they ask
         | is for my date of birth and address so I can pass their
         | security checks. Each time, there has been a _really_ awkward
         | silence for a few seconds when my response is  "Nope".
        
       | bennyp101 wrote:
       | Seems like this is more a story type thing?
        
       | awinter-py wrote:
       | > A lot of the credit that I gave Barry came from my lack of
       | faith in my bank's systems and security. ... Insecure business
       | practices often don't stand out as a sign of a con; they just
       | look like another boneheaded but authentic policy.
       | 
       | ^ _THIS_. your bank is training you to get phished. your health
       | insurance, by leaving fake-urgent voicemails that require
       | miserable phone tree navigation when you call back, and by having
       | a million different numbers which resolve to  'scam or at least
       | spam' aggregator sites when you google them, is teaching you to
       | get phished.
       | 
       | my health insurance has a process which involves calling me and
       | asking for a bunch of personal information. I called them back at
       | a known number to ask if this was their number and _they didn 't
       | know_. I called three agents and they gave me three different
       | answers. One said it was a 'system error that will be resolved in
       | 24 hours'. Another said it was fake, don't trust it. A third
       | _called the number_ while I was on hold and assessed it as
       | 'probably fine'.
       | 
       | teach someone to get phished and they're phished for the rest of
       | their life
       | 
       | never accept inbound calls
        
         | testudovictoria wrote:
         | Part of the problem with this is the horrible business
         | practices and policies in place. In a way, it is urgent that
         | you get back to your health insurance rep or your car insurance
         | rep or whatever private business that's selling you a
         | government mandated service. That phone rep knows that you only
         | have 15 more days to finish your insurance claim, or you've
         | gone past the deadline. Then when you call back, the rep can't
         | do anything. Terrible business policy doesn't allow them to.
         | Something like this happened to me.
         | 
         | I had an issue once with a claim. It was an ongoing ordeal with
         | lots of small meetings and documentation. It was eventually
         | denied. However, I had a rebuttal window. Unfortunately for me,
         | it came during a stressful period of work. I made the initial
         | call to my rep. No call back. I was buried under work, and the
         | 5 day rebuttal window (how absurdly short) blew by without me
         | realizing it. Turns out the rep was on vacation, and after my
         | case was closed, there was no reason for them to return my
         | call.
         | 
         | These issues are never a matter of urgency that should be dealt
         | with in that instance. However, don't let your window of
         | opportunity close due to an adversarial business policy.
        
         | sidewndr46 wrote:
         | I had some healthcare provider just never bill me. 9 months
         | later they called and then asked to verify my identity....by
         | having me give them my social security number. Over the phone.
         | I declined.
        
         | DFHippie wrote:
         | > teach someone to get phished and they're phished for the rest
         | of their life
         | 
         | This is a keeper.
        
         | higeorge13 wrote:
         | ^this 100% I stopped accepting calls from unknown numbers,
         | stopped reading messages from unknown numbers and every email
         | from unknown contacts marked as spam. I don't care about their
         | offers and crap. If they need anything important they know how
         | to properly reach me directly and not through agents and random
         | crap.
        
         | evandale wrote:
         | >A third called the number while I was on hold and assessed it
         | as 'probably fine'
         | 
         | This blows me away. Probably fine? That's the worst possible
         | answer IMO.
        
       | smm11 wrote:
       | I got the same call, but it really was my bank!
       | 
       | Hey, wait a second.
        
       | furyofantares wrote:
       | I firmly believe that anyone can get scammed if they're caught on
       | a bad day and the scammers happen to get lucky with some details
       | or approach that happens to match something the target is
       | inclined to believe.
       | 
       | I don't believe scams are typically designed to maximize success
       | rate per scam; they're designed to cast a very wide net and get
       | lucky on a few targets.
        
       | dr_orpheus wrote:
       | I believe I saw this exact same scam on another recent Hacker
       | News article. Same premise of "I'm from the bank and you are a
       | victim of fraud and I need to deactivate your Apple pay but I am
       | actually activating my own Apply pay with your card"
       | 
       | Also had a similar title along the lines of "I give presentations
       | on scams and I still got scammed"
        
       ___________________________________________________________________
       (page generated 2022-04-21 23:02 UTC)