Scammers signed up, scammed us of $870 in 15 minutes
dev.to
dev.to
Scammers make money from receiving phone calls. Apparently, it is super difficult to tackle this problem - right from twilio to phone network carriers
The carriers try to hide behind old agreements that state all calls, fraudulent or not must be paid. If they want to keep these agreements they can just pay for them themselves. If not, they should change them. The end users aren’t in a position to enforce this so regulatory pressure is clearly required.
In our case, we were making phone calls to verify phone numbers. That was a crucial mistake.
Did they get access via tokens or email/password?
Knowing that Phone call is important, we needed to verify it. However, making phone call to verify is NOT a good idea.
We should have sent an SMS but getting an Alphanumeric sender ID took some time and we wanted to ship quickly.
Tech debt bit us bad
The attack happened and since I had spoken with their team once I decided to integrate quickly.
Why not use hcaptcha?
Having used Google reCaptcha before I immediately set it up.
Would you recommend hcaptcha over reCaptcha?
People where ggetting hit mostly on Firefox, and mainly when non being identifiable as using a google account/service so captcha wouldn't even show.
So the answer is maybe I guess, if you think you will need the scale at which point google might wanna charge you for using it's service.
So, I don't think we will fall under the segment where Google might have to charge us.
PS: Didn't know Google had started charging now.