I lost €4k in a Facebook scam
github.com
github.com
The TikTok promotional program is actually a real thing that does give around that amount of ad credit, and they have been promoting it very aggressively on Facebook with for a long while now, so it makes sense that OP would've not had any mental red flags triggered by the designs and creatives used by the scammers. The real killer is that PayPal is actually well within their rights to process this transaction (as part of the billing agreement generated when you link PayPal to Facebook Ads Manager: there actually was real ad spend in a real Facebook ad auction), so it's down to Facebook itself to refund the ad spend. (As an aside, I'm actually impressed that OP managed to reach Facebook support at all, and that they acknowledged or even understood what the problem was. I have had worse experiences in the past with FB...). What's really amazing to me is that the scammers managed to get on Google Play with thousands of obviously fake reviews, and get through Facebook ad review at all.
The scammer silently removing OP as an admin from their own ad account, preventing them from noticing or stopping the fraudulent ad campaign is just icing.
I suppose the real lesson to be learned is to simply avoid installing native applications when you can help it. OP didn't screenshot the login screen in app, so I can only assume it was a real Facebook oauth flow, but honestly at that point it's already too late. If anything OP should be grateful that the native app running on what was presumably his personal device didn't do anything worse.
This hints of not having 2 factor authentication anywhere in the chain?
Would definitely advise to setup 2 factor authentication on anything managing 5 figure sums.
I'm using "login" and "account" specifically here to highlight the difference. On systems where there are likely to be multiple people that need access, there's a distinction between the "service account" and "logins or user accounts" that can control it. Generally, when the service account is created by a login, that login is added implicitly as a controlling user account with full privileges, and other user accounts (logins) can be added with varying levels of control. This situation appears to have been along the lines of the following:
1. User "real_user" create facebook ads account id 123456, and real_user is the admin of the ads account id 123456.
2. At some point real_user adds "scam_user" to the facebook ads account id 123456 with full admin permissions.
3. scam_user uses the full admin permissions it has for facebook ads account 123456 to remove access for real_user.
Note that is is a fully legitimate and common action to take in systems like this. If you are a business and pay someone to manage your facebook ads, they are likely the admin on the account (and you may be too), and if they leave and you hire a new person to manage it, you would want to revoke the old employee's account access and add access to the new employee's account.
This is how you handle it on Google Suite, Zoom's business accounts, Active Directory in Windows domains, etc. The real problem here is that the scammer got enough permissions to revoke the original user, and the original user did not get an email notification. I'm not sure if facebook ads allows adding accounts with limited permissions so only certain actions can be taken and part of the scam was making the permissions asked for non-obvious, or if that's a permissions distinction facebook ads doesn't support.
I must say that it was a pretty clever scheme.
I see this most often with extensions, which usually want to act on all domains when they should really need an allow list of just 1-2 domains. There are also many app integrations that use an API token that just straight bypasses login with NO security restrictions.
I would use a lot more app integrations if I knew I could trust the host platform to keep the apps honest.
I think we're missing a lot of innovation because we lack secure and reliable integration points between commodity services. Banking and Health are the most obvious issues. It should be trivial for me to authorize a third-party app to download transaction history from any bank without giving it the ability to change anything. I should be able to assemble my entire medical history by pulling from any medical office I interact with, and push that to any provider I choose to use.
There are lots of industry incentives to prevent this though. It's just like the Cable Card saga. You need strong, un-captured, technically-literate regulators to fix this stuff and unleash broader innovation.
This [1] says that U2F avoids phishing by having the browser tell the 2FA device the domain, but that seems a bit weak to me. The same site even has an app where the info is relayed via a browser plugin, so literally relaying the data that's supposed to be trusted. The only way I can see that actually working is if the security key knew to only sign challenges for a specific domain.
1. https://krypt.co/blog/posts/prevent-phishing-on-the-web-with...
The WebAuthn spec says: "Direct communication between client and authenticator means the client can enforce the scope restrictions for credentials. By contrast, if the communication between client and authenticator is mediated by some third party, then the client has to trust the third party to enforce the scope restrictions and control access to the authenticator. Failure to do either could result in a malicious Relying Party receiving authentication assertions valid for other Relying Parties, or in a malicious user gaining access to authentication assertions for other users."
(https://w3c.github.io/webauthn/#sctn-client-authenticator-pr...)
If you click further into the older FIDO spec, they cover this more explicitly: "Malicious software on the FIDO user device is able to read, tamper with, or spoof the endpoint of inter-process communication channels between the FIDO Client and browser or Relying Party application. Consequences: Adversary is able to subvert [SA-2].
Mitigations: On platforms where [SA-2] is not strong the security of the system may depend on preventing malicious applications from being loaded onto the FIDO user device. Such protections, e.g. app store policing, are outside the scope of FIDO."
(https://fidoalliance.org/specs/fido-v2.0-id-20180227/fido-se...)
oAuth outside a browser is just training people to be phished.
When my bank calls me up about an issue with my account, they won't talk to me unless I give them my date of birth and email address for 'data protection' purposes.
They're always really confused when I say I will have to call them back.
...never, ever buy or even take anything from anyone who approaches you without you being the original initiator of the communication. Simple rule that applies to both online and real world and makes your life simpler and safer.
https://wp.josh.com/2019/05/06/breaking-news-google-adwords-...
They just fire off a request to google.com/url?... to track the click before letting you on your merry way.
Sigh
It's ok for the initial pull to be an ad, but only buy from the source.
What if they can register a very similar / regional domain that you didn’t set up already?
Normal rules don’t apply when you’re a criminal so spoofing SSL cert names is something you might as well do too. It’s just not practical to examine and confirm the cert manually of every company you interact with online.
These internets are dangerous, even if you know what you’re doing.
SAN dnsNames in certificates in the Web PKI are verified by the issuer - these days using one of the Ten Blessed Methods. It would certainly be possible to obtain certificates for a name you don't actually own, but it's a bit beyond the usual casual crooks that run scams like this. We see what appear to be nation state adversaries doing it, as part of wider targetted hijack schemes (e.g. to intercept IMAP credentials for a foreign government agency) but it's definitely not something you see an ad scammer doing.
Any vaguely competent modern browser checks the certificate is trusted in the Web PKI and that it matches the SAN dnsNames to the FQDN in the URL exactly so there's no room for any funny business there.
And human readable names in end entity certificates are largely irrelevant. Nobody looks at them, who cares?
"What if they can register a very similar / regional domain that you didn’t set up already?"
In other words, they register fakebook.com and then just go get a TLS cert for it. If you're not looking carefully, you might not notice the difference.
Whether the CA system, with fungible, interchangeable certificates that can be issued by dozens of CA's (pinning excepted), is worth sinking lots of trust into is an entirely different matter ;)
But a very similar domain is the wrong domain. This is not a great novelty, people are aware that a ROJEX watch isn't the real deal, no surprise Fakebook isn't the social media site you actually wanted either.
In terms of authentication, this is where WebAuthn shines because it's tied to that actual domain name. Even if you're 100% dead certain this is really Facebook, your WebAuthn authenticator can't help you. There is no "Look, I know the URL says Fakebook, but ignore that, I am 100% sure this is really Facebook, just shut up and take my money" button.
Probably more relevant is that if I have registered luxowatch.com to sell my lovely watches, but am a small store, I certainly won't have registered (as yet) a bunch of global domains. There's nothing stopping you registering luxowatch.co.uk or luxowatch.net with a valid SSL cert to scam my potential customers. Cloning my site to one of those domains (with cert) can be done almost instantly for close to zero cost.
It really sucks that it seems like we've built the most important infrastructure of our generation effectively on quicksand.
My guess would be that it was an in-app phishing page. Many legitimate login flows result in the official login page opening in a web view and asking for a password, which is indistinguishable from a phishing page.
> but honestly at that point it's already too late. If anything OP should be grateful that the native app running on what was presumably his personal device didn't do anything worse.
On phones, sandboxing significantly reduces the risk. Yes, it is possible to break out of the sandboxes if you have an exploit for that device, but it's a lot harder than on desktop where by default anything you install has full control over everything and could just steal all the users' passwords.
I don't understand how Google/Facebook/etc can allow this to happen, let alone encourage it. I'm just baffled.
You have to fail at several steps if you're entering your credentials in this scenario.
Hasn't been 100% effective unfortunately, and even if it was, it's really hard to make users understand that this flow is incredibly dangerous.
And while Google on Android can simply go through system libraries, Facebook doesn't have the option if the app is not installed. They have to open something that will allow the user to log in (usually a browser), which is something the app can fake (in the case of the browser, just fake the whole browser UI, fake address bar included).
https://www.investopedia.com/articles/personal-finance/05021...
“ But if the item was bought with a debit card, it cannot be reversed unless the merchant is willing to do so. What is more, debit card theft victims do not get their refund until an investigation has been completed. Credit card holders, on the other hand, are not assessed the disputed charges; the amount is usually deducted immediately and restored only if the dispute is withdrawn or settled in the merchant's favor. While some credit and debit card providers offer zero-liability protection to their customers, the law is much more forgiving for credit card holders.”
The business can only dispute if I requested for my money back _after_ the 8 weeks. That's when the evidence and back-and-forth with the business comes in.
The normal flow will be your bank reimburses you from their own pocket. Then goes after the merchant to recover the funds, however if the merchant can present evidence that the charge is valid then the your bank will attempt to claw the money back from you.
Now the important question is here is what is a "valid" payment. Normally the direct debit scheme will outline that that is, and it probably some very simple like there's evidence that you requested the funds are removed from your account. With something like PayPal they can probably claim that the request was valid, at least the bit between PayPal and the bank was, and that the onwards movement of money is a separate issue that doesn't fall under the direct debit guarantee.
It's worth really digging through the small print on these things, they're frequently a lot less helpful than you think, and PayPal has managed to exploit these little holes to their benefit.
Personally I avoid using PayPal where possible and stick to debit/credit card where you have a very simple relationship between you, your bank and the merchant. Which makes disputes much easier, and places the law very much on your side. All this comes from experience dealing with disputes from the banks perspective, and trying to get the right result for the customer, while dealing with payment schemes, and regulatory obligations.
Why couldn't a web site have stolen his credentials in the same way?
And a bunch of other potential signals that would be missing in a native app.
It's not foolproof but it's a step forward.
I don't understand why any of these actions would be taken with a mobile phone ...
What I mean is, managing advertising campaigns and budgets and managing assets and spend, etc., is kind of a complicated workflow ... further, it's a fairly critical business process involving a lot of money.
I can see ordering some workroom supplies or paying a hosting bill with my phone ... but creating and managing ad campaigns ? That seems very unwieldy and inefficient. Google adwords, through the web based interface, is very complex and there's a lot of functions there. I can't imagine trying to do this on a phone.
So what am I missing here ?
I don't get involved in ad buys.
I don't understand the need for snark here on your part, do you not think I have already considered it?
By "desktop" I meant "desktop environment".
another reason why we should be training users to only do oAuth in a browser with a password manager.
It's one last solid line of defence.
OAuth in a native app is a security risk.
I looked at the playstore page and it immediately raised many red flags. The app isn't by Tiktok or Bytedance.
It's like clicking on a similar looking domain link in your email.
Last time I tried to find nvidia drivers for windows 1st result was an obvious scam/crapware. This is not acceptable that big tech companies are making money while not taking responsibility for advertisements.
Come on, dude.
I will say that even the most experienced techies among us sometimes become complacent and let our guard down. It's exhausting having to constantly second-guess every application you want to run.
(Not interested in starting another platform flame war, but this is the main reason I don't use Android. I deal with enough paranoia running Windows daily. Maybe I'm misinformed, but I'm also probably not unique in this respect)
I'm curious if this fake TikTok app would probably have been blocked at the outset in the Apple App Store review process because it's trying to masquerade as another business ?
I did try to modulate the harshness of "Come on, dude" with the rest of my comment. Like I said, sometimes we let our guard down. So it's understandable if you got fooled.
In hindsight there are more red flags in just that screenshot ("More by Develop App", obviously fake reviews to point out just two), but God knows I've clicked through installs for shit apps on iOS many times.
I think it's worth pointing out that the difficulty / impossibility of achieving that bar (at least in the general case) is one of, if not the central tenet of Christianity, ostensibly the dominant religion of the West for something like 1500 years. Regardless of one's metaphysical beliefs, it's worth remembering that arguments for the necessity of grace and slack in positive interactions have a long historical precedent, and I find we ignore them at our peril.
I still can't believe myself I fell for this, as said I have 2FA on all accounts and I'm normally very cautious. I guess it's a combination of all the factors here at play: Facebook allowing a fake TikTok Ads advertiser, the ad looking very legit (referring to an existing ad credit program), Google allowing a fake TikTok Ads app with fake reviews, and not getting any notifications until the amount was charged from my PayPal account.
Bad spelling and grammar used to be a great indicator of something being amiss, but the volume of it in legit business these days has made me so desensitized that I didn't even blink at this one.
I bet many thousands of people on HN would have done the same thing.
I think it's an issue with reading comprehension. In general, comprehension seems to have plummeted in the last five to ten years. I send people e-mails asking two questions, and only get the first one answered. People read a headline and think it means something other than what it says. Flamewars erupt online over something that nobody actually wrote, but someone thinks they saw.
It seems to be rooted in the fact that these days people skim text, rather than read what is written. I don't know if it's because of general information overload, or a lack of attention to detail, or if the mindless scrolling of phone apps has trained us that visual impressions of words are good enough.
Or, if I can put on my old man hat, maybe it's just that people aren't as good at reading as they think, and that if people looked at a book half as often as they look at their telephones, they might get some good reading practice.
A good way to write text where you're going to ask people for stuff is to write it in a top-down manner, where first of all you mention "I want X", then you quickly summarize what exactly you want and why, and then write a more detailed paragraph on the various nuances, always making sure to cut everything down to its absolute essentials.
Blog articles, especially medium, are really bad about this. I've clicked on headlines about an interesting topic only to find the article no even mention the topic from the headline until 2/3 of the way into the article.
Heh...reminds me of a couple anecdotes from my days in school.
Sometimes as we were being handed back tests/quizzes that had some questions that required a couple sentences to answer, there'd be times where I did exactly that. I wrote only a couple sentences. Meanwhile, I glance at the person next to me to discover that they had wrote two entire paragraphs. I got marked as having a correct answer with only two sentences, so what the hell were they writing about?
Then I had a teacher who, before the final exam, said that every question is able to be answered in four sentences or less. If you write several paragraphs, you would lose points for wasting his time, even if your answer was correct.
I think it is the former. I'm perfectly capable of reading a poem or code word-for-word, but as soon as I'm in my browser something "clicks" and I'm just skimming text. It is usually completely subconscious, but while reading your comment for example, I realized I was only reading half of each sentence.
OMG, this happens to be all the time, and I don't even use email as a primary communication mechanism. It's so frustrating. I think the case is that people are reading and responding to emails on the go on their phone and so don't have/take the time to write a full response.
In the "old days" it was appropriate to answer emails by leaving a partial quote in place and responding below that for each answer. Something changed (I blame Outlook) and now that never happens.
This has been bugging me for at least 10 years, and also extends to IM. If it's IM, I ask one at a time.
If it's email, I either have to ask one at a time, form the two questions into one, or turn it into a sandwich - question 1, question 2, rephrase question 1.
What I really want to do is grab them by the shoulders and shake them, shouting "You saw the second question - yes?!?!"
One aspect is that it's a parasitic efficiency increase. The 80/20 rule applies here; you can answer 80% of the emails by skimming. If you just don't handle, or poorly handle, the 20% of the emails that take 80% of the time, you get a bunch of time back.
I also think that the overload comes from notifications, not general information. We get a crazy number of notifications from our personal devices (and many/most people check them), and during the work day that's compounded with all the systems at work that send notifications. I think that we've subconsciously taught people to work between the notifications. It can feel like if you don't respond to them in real time then you might end up with an insurmountable backlog of notifications to handle, so people have acclimated to handling them in real time. Each time someone responds to an IM, a mental timer starts, counting down how long it is until it thinks the next notification might come. Or, conversely, you're in a notification lull, and you start thinking this is your only time to get anything done towards the sprint, so you smash out fast responses to the notifications you do get, trying not to break your train of thought.
Others may have different experiences, but I get notifications from so many systems and people that it can be overwhelming. And the tools we are offered to manage it suck. Slack's notification settings are better than what I had before with Lync, but they're still lackluster. Email has the best filtering record so far, but it is also by far the most abused by tools.
Some things I would love to see in a chat system: * Chat and notification filters based on whether the user is a bot or not * A sane "handle this later" queue or some kind of integration with a task manager to let me click to create a ticket * A way to communicate busy-ness through my status. Either a level I can manually set, or a system that can guesstimate it (i.e. "curryst has 8 active private chats right now") so we can all gauge whether what we need is that important right now * Customizable options to batch notifications. I would love it if I could have Slack batch my notifications and just send me one notification per minute that says "3 new messages"
My holy grail is if they would let me write my own functions to determine whether to notify for an event, batch it into the next batched notification, or to not alert at all. Most of these desktop clients are in Electron anyways, just let me pass it a path to a Javascript file that exports functions to filter notifications.
It doesn't help that the developer name and category have the exact same visual style, I guess.
I bet that it is possible to slip through the review process however there's also a safeguard on the developer account creation. Apple wouldn't let you create a developer account using vouchers, PayPal or prepaid cards, at least not from countries where scams are commonplace. Also you would be asked to provide documentation of company registration to have an account named “Develop App”.
It is a common theme on HN to trash Apple on its "draconian restrictions" but the reality is that Apple AppStore is a safe place to be. You don't have to study the App before downloading it, you first download then decide if you want to keep it and security is never a concern. The Apple tax is something I am happy to pay for that luxury.
I am a developer and I have no idea what com.acazira.tforbusiness means. What keeps it from being com.toktik.forbusiness?
On AppStore this is something that you type it by yourself on the project configuration screen in XCode and I don't remember reading any restrictions about it, only recommendation to use reverse domain name notation to prevent conflicts.
You can never change it. This is how you get com.toyopagroup.picaboo (Snapchat) or com.yourcompany.TestWithCustomTabs (AccuWeather).
It’s such a cat and mouse game that has massive jumps in acceleration when it comes to ‘novel’ ways attackers create new exploits.
Having Apple taking it seriously even for people like me is a huge win.
What I did see a lot of though in a lot of the case studies/readings/etc, was seemingly anytime advancements were made in one area, closing off particular patterns or styles of exploitation. The energy and resources often would switch to another domain, and there's a mad scramble to solve it.
Just my two-cents, and a bit off topic.
The way I view it, it's sort of like when a player glitches themselves outside of the boundaries of the level in a video game and are able to bypass all the battles the game has in store for them and walk directly to the objective. Anomaly detection only works if they are playing inside the realm of the system but if something manages to break out of the sandbox then detection can be bypassed because it was never a condition thought possible and therefore not checked for.
For Example, you can have code to detect abnormal requests http requests, but if there is a vulnerability in a webserver's memory management of reading bytes from a socket then it allows the attacker to "breakout" of the system before you can detect it. Now you might be saying well we can detect when they breach memory but it just creates another cat and mouse game at a different level. This all assumes there are no bugs in the anomaly detection systems themselves
That's not to say Apple is perfect. Their "root"/"" login bypass zero-day was absolutely unacceptable, even compared with Microsoft's problems.
Other than that, I'd trust an Apple device over a windows device any day of the week.
Google could up its Play Store review process + not installing from outside the store would result in the exact same security advantages you're talking about, while still letting you install from third party sources if you're a power user.
But there are a ton of bad actors out there who will also use those abilities to scam and steal. You can stereotype it as only clueless users falling for that, and there's even a little truth to it, but 1. Some are quite good and nobody is perfect, you can still get scammed yourself, and 2. It seems not cool to just write off everybody who isn't a tech expert, throw them to the wolves, blame them for falling for any scams.
I get it. And I don't think the threat justifies handing complete control of our computing environments to a single corporation.
But there are a ton of bad actors out there who will also use those abilities to scam and steal.
Bad actors often set up fake websites. Should computers and phones have mandatory browser filters so you can only go to approved sites?
Well they don't, but browsers do spend an inordinate amount of effort trying to make sure that bad websites can't do anything other than show you things. I'm pretty sure that all of the browser vendors will pay 5-6 figure sums for any exploit chains that would allow a website to do things like read files without permission or execute code on the OS. And people regularly complain about the ever-tightening restrictions on what websites are allowed to do.
Facebook on the other hand should have handled it differently. I don't know how their permission screen for app authorization looks, but I guess it should have a huge red warning sign if it includes a permission to allow the app to spend your money.
With no data, if one slips through it shouldn't be up to the spam filter if I can be scammed!
edit: that was a particularly bad typo to make. I mean scammed, not spammed :)
Given that a lot of companies outsource app development to third-party companies that in many cases mostly reskin and extend an existing app that they sell to many clients, a package name that could be from a development shop likely wouldn't cause concern.
Sure Tik-Tok has a significant in-house development staff, but they're focused on the backend and client apps and Sales and Marketing may not have much access to them. It may be much easier for those departments to fully outsource that development to a vertical-market vendor, particularly if it's SaaS and the resulting app(s) aren't integrating with internal systems except via downloaded CSV files.
Maybe try to have a sip of coffee before jumping for that $3000. Let's not pretend that this is just ToS fatigue. The only reason they installed this app is for the free money.
So yes, maybe if someone is offering you thousands of dollars, you should consider that to be the time to second-guess what's happening.
Who gets together and says, "I have the perfect name for a new dev shop: Develop Apps".
Maybe this is too risky to do on the Apple App Store because you need to /pay/ for an account to publish on the app store, which means you more or less need to verify yourself. Doing something like this would make it too easy to lead back to you and get in trouble?
Just wanted to highlight this. Things like this is why I avoid PayPal as much as possible. For many years now.
Here's news about a new protection scheme in the UK. But this is new (only came in last year), and it doesn't cover all banks. https://www.bbc.co.uk/news/business-48385426
> New protection for individuals tricked into transferring money to fraudsters has now taken effect - but not all banks are signed up to the scheme.
> Some 84,000 bank customers lost money - sometimes tens of thousands of pounds - last year after being caught out.
> Only a fraction of the amount lost was refunded by banks. Now a new code should mean more will be reimbursed.
> The refund will come from a central pot in cases when neither the bank nor the customer are to blame.
See especially this bit:
> Some of the more elaborate frauds see the con-artists using social media and other avenues such as data breaches to gather information about their victim, making it more likely that potential victims believe they are genuine.
> In all these cases, the individual authorises the payment. Banks have often refused to refund these frauds as a result.
Losing your card would have been similar to the OP's PayPal account being hacked.
I was under the assumption that the VISA debit card offers me the same protections as the crecit card but I think I was wrong...
> Are PayPal purchases covered? You are unlikely to be protected under debit card Chargeback schemes for items purchased using PayPal. In these cases the act of loading money onto your PayPal account counts as the debit card transaction so, unless the money fails to be credited, it won't be covered. PayPal runs its own purchase protection scheme which extends some cover to your purchases, but it is in house rather than regulated by law.
https://www.consumer.ftc.gov/articles/pdf-0075-lost-or-stole...
In the US, you don't have to pay the disputed portion of a credit card bill while the chargeback investigation is ongoing. Most financial institutions will issue a temporary credit to make this clear.
https://www.consumer.ftc.gov/articles/0219-disputing-credit-...
If anyone here is familiar with Dutch law, the author might appreciate your input.
Details are likely spelled out in the multipage 5-pt text pamphlet that you received with a new debit card at some point.
In the US, debit cards command different processing fees for the card issuer depending on how the transaction is processed. Sometimes, when using a debit card in person, the checkout terminal will ask the customer to choose "credit" or "debit" for the transaction. Choosing "credit" instead of "debit" grants the card issuer a much larger processing fee. Some financial institutions only offer certain features (including liability guarantees or rewards) when the debit card is used to make a "credit" transaction. Almost all online debit card transactions are processed as "credit" (which does not require you to enter a PIN).
About the status of PayPal: it is licensed as a money transmitter but manages a network of bank subsidiaries and third-party bank accounts to profit from interest rate arbitrage and perform other activities that banks would do.
https://ftalphaville.ft.com/2015/08/06/2136828/is-it-a-bank-...
In the US, you may also want to file a fraud report to the FTC and to your local police department.
https://www.ftc.gov/faq/consumer-protection/submit-consumer-...
Anyhow, I called my bank and explained to them that these were fraudulent transactions, and thank goodness you have them on hold but haven't processed them, because my rent is coming up and could you please release the money.
The bank refused. I'd been a member of the same institution for probably a dozen years, had a car loan out through them, was on track to get a mortgage through them in a few years, and they told me that even though I had caught it that very morning, about as soon as I could possibly have caught it, that there was nothing they could do.
Paypal, on the other hand, asked me to sign an affidavit, and a couple of weeks later, fully refunded my account.
I've held Paypal above banks ever since. In retrospect, eBay had acquired Paypal only two years prior, and this transaction happening on eBay probably garnered additional scrutiny at the time. However, nearly every time I read about someone's Paypal account getting locked out, it turns out they weren't paying attention to the Terms of Service - which are, without a doubt, designed to minimize fraudulent use of Paypal as a payment provider. It's why you can't do pre-sales on Paypal - it leaves them open to liability.
For better or for worse, the overwhelming narrative becomes "Paypal sucks", but as you start to look at the big boy payment providers, you'll discover that Paypal is often more permissive by comparison, with rates that are comparable to or better than the big boys when you're running with such small transactional values. And if you end up going to some upstart that will let you do things Paypal won't, that party's only going to last as long as those providers don't get stung by regulatory fees or plain old fraud.
https://news.ycombinator.com/item?id=13851120
https://news.ycombinator.com/item?id=1678582
https://news.ycombinator.com/item?id=6333203
https://news.ycombinator.com/item?id=7968737
https://news.ycombinator.com/item?id=18783493
https://news.ycombinator.com/item?id=4455520
https://news.ycombinator.com/item?id=6891306
Financial institutions do not have this kind of control over bank accounts. All bank accounts inherit a level of trustworthiness from consumer protection laws that only apply to bank accounts. PayPal does not.
When PayPal freezes/limits an account in a way that a bank account could not legally be subject to, the problem is not the account holder, but PayPal itself.
On the other hand, all my credits card companies, Citi/Chase/etc. approved my similar requests after a review process.
In both cases, Discover approved charge-backs for the PayPal charges to my card.
Why does anyone still use PayPal?
Paypal.com -> Subscriptions -> Unsubscribe
Paypal makes it two or three clicks to unsub from any reoccurring payment. No dark patterns or "call us" required. I use it whenever I can for subscription services.
By the way, I did this ages ago, deleted my account, closed what I could, and I still regularly get a mail from PayPal that they changed their terms.
For example the New York Times forces you to call and speak to a retention specialist if you want to cancel and you paid by credit card. With PayPal it's 3 clicks.
And sadly there are people (on this thread) who still blame the OP. Of course the payment wasn't authorized, and the OP is very articulate about what happened. At the end of the day, money middle-men are very effective at pointing fingers at one-another, the effect being that the user will throw up their hands and give up. (This happened to me once and cost me about $15k, and I was unable to recover any of it). But what makes it even worse is how conditioned we all are to accepting blame for what is, ultimately, an authentication mistake made by the financial institution(s).
You can't afford to not accept PayPal because all the buyers have it, and all the buyers have it because you can pay with it everywhere.
An alternative network would have a hard time getting users to sign up.
I absolutely loathe them for their high-pressure sales tactics (their site is full of dark patterns and booking there is outright stressful; it feels like you're trying to browse while a drill sergeant is constantly yelling into your ear "BOOK NOW YOU WORTHLESS SCUM, BOOK, BOOK, WHAT ARE YOU WAITING FOR YOU IMBECILE, CLICK IT, BOOK, NOW, NOW YOU MAGGOT") - however, unfortunately they often do have the best price (by far) or are the only place certain accommodations are available, and aside from the drill sergeant, their UX is absolutely perfect.
I've been burned far too often with sites that let you go through the entire flow only to tack on ridiculous fees for payment or simply fail to process your credit card.
Really, the only way to not get PayPal to approve a refund is to work with the customer and solve the problem so the customer cancels the refund request.
The payment is authorized by the author (i.e. his PP account wasn't stolen), the whole thing being a scam is irrelevant and PayPal shouldn't be the judge here (if you got scammed and send some physical items to the scammer, can you ask the post office to take it back?)
I sold digital goods on eBay a few times (like, less than 10 times) and I've already got 3 (!) people claiming their purchase is "unauthorized" after I sent them the goods (redeem codes, so I can't really let them "return"). I'm more than glad that PayPal took my stance instead of giving them chargeback, since they're likely trying to scam me.
Why would we (I'm genuinely asking here) consider PayPal more similar to CC than the others? My point being, it could be (closer to) either, and both make sense to me. PP doesn't necessarily need to operate like CC.
After all, CC as a service charges much more with processing fees from merchants and sometimes annual fees from the customers. It's meant to provide a "better/premium" service.
PayPal does have a 6 month purchase protection policy in many cases. So... maybe, if you manage to argue that this was a purchase that you're entitled to protection for. But that's a different channel and probably a different physical department at the company.
This shit is why I don't sell on eBay anymore.
I have a friend who sells stuff on eBay a lot (or at least, used to), and he says about 5% of his sales go to scammers who will request refunds claiming they never received an item.
Of course, now that I think more on it, I wonder how many of those 5% were scammers versus how many of them simply had their package stolen from their front door.
This is an error on the Facebook side. Actions like this should never be possible without appropriate confirmation or re-requesting the password for 2FA confirmation.
* Employee starts a Facebook business page using their personal Facebook account.
* They add their boss to it.
* Employee is fired.
* Boss removed employee from Facebook business page.
edit: Should still send a notification email but I'm guessing angry "why did you remove me from X" reactions are why they don't. Not good but there's a logic behind it.
If you need to enter your credentials when using sign-in-using-xxx, be VERY cautious. Even if you have 2FA enabled, the fake oauth screen can just ask you for the 2FA code. You have no way of knowing whether the login page is keylogged or hijacked.
Not all 2FA is “enter a code”; it's a lot harder for a fake oauth screen to send a request to your registered authentication device.
EDIT: this doesn't really help, as a reply points out. OTOH, separate side channel verification of logon from unexpected devices does.
But now that I think about it, it would make sense to combine new device notification with push-notice 2FA for exactly that reason, since you've got a push channel that takes a confirmation already, flag unexpected devices in that channel as well and it becomes much more secure.
An attacker can play the legitimate WebAuthn request from the real site, which will (statistically certain) be nonsense if played by their phishing site.
Or they make their own request, which doesn't help them because it's not valid on the real site they want to sign into so it's pointless.
Something I still don't understand about the OAuth flow is how it's _not_ training users to be more easily phished for actual usernames and passwords. The very first step is "If you are not logged into the third-party, display a login-form from the third-party."
The thing is, you never really know off-hand if you're logged into the third-party (provider) or not without opening a second tab and going directly to the third-party's site, since you're always getting logged out after various timeouts, cookie-clearing, browser-closing, and computer-restarting events.
What prevents an OAuth client application from displaying an OAuth process that shows a fake login form, which looks identical to the provider's login form, to get the user to enter their provider username and password before they realize the URL is off? It seems like it trains users that it's normal for websites to launch a Gmail login form and this is perfectly safe.
This [1] says "In fact, the spec requires that browsers only expose the API in secure contexts", so if that's correct it's better, but still not good enough.
This [2] looks like it does U2F by grabbing the challenges via browser plugin and relaying them to a phone app for signing.
Trusting the browser to "expose the API in secure contexts" seems like a failure because it's assuming nothing else can collect the credentials or send a challenge to a security key. Is that true? Could I write an app that would phish a user into signing a challenge with their security key?
What sort of app? A full-blown Windows/ OS X/ Linux desktop application? Yes.
You definitely should not install software that asks you to interact with your FIDO authenticator in this way unless you really trust it. I trust the Operating System vendor installed OpenSSH packages, I would not trust some random github project.
The two big phone ecosystems won't let you talk directly to a third party authenticator or to their built-in platform authenticator. The authenticator talks to them, and they talk to you. So while it would be possible to make a Windows EXE program that says "Touch authenticator to stroke your 3D pet" or whatever and actually steals your Facebook login credential this way, it should not be possible to put something on Google Play or Apple's iPhone store that does the same thing.
Edited to add: For Android at least there is a concept of "Privileged" apps that get to do stuff that is otherwise impossible to ask a user for permission to do. The ability to fill out WebAuthn-style rpId values (for WebAuthn these are Internet FQDNs) is locked behind such a privilege. So, Chrome has privilege, release builds of Firefox have privilege, and so on, but yet another fly-by-night app developer who uploads Flappy Bird clones to the Play Store can't use this feature.
Without this privilege when you talk to the authenticator (either a platform authenticator or a 3rd party one) the OS will insist on picking an rpId with a platform specific prefix. So e.g. maybe your app can ask for rpId android-584fac03:google.com but there's no way (without privilege) to get just google.com, which is a problem because that's the value you'd need in order to get working Google credentials.
If you want your app to talk to your own web site, you can build a bunch of extra goops (in Android at least) to enable that, but part of what will happen is your web site's backend code needs to explicitly go "OK, I should allow android-584fac03:my-private-app even though that's nowhere close to my actual FQDN" so that seems safe enough.
Since neither iOS nor Android have any kind of trusted UI, there is no way you can be sure if you are logging into Facebook on an app, or just giving that app your credentials for them to do as they please.
Until iOS or Android get trusted UI for these usecases, I suggest using browsers on windows/Mac/Linux where you can see the in the address bar which company you are giving credentials to, and can't as easily be faked.
If you must use a mobile device to log into Facebook via a third party app, I suggest using a new Facebook account each time.
I might be wrong about this as I've not used Facebook for many years now, but doesn't Facebook require a phone number for new accounts nowadays, and requires you to use your real name as well?
Think of how many accounts are created for games reasons. Some games require friends taking action to progress. Some allow friends to send prizes like lives/money/resource.
Could be like my grandma who would occasionally manually log out of the app, but then the next time she loaded the app, rather than actually logging in again, she'd create a new account because that's what she did the first time she loaded the app and thought she had to do that every time.
Looks like it was a real Facebook login webview.
The difference may of course be subtle, but even obviously fake logins can work on the untrained eye.
It could be faked 95% accurately, but that's moot, because like I said, the user hasn't necessarily learned what "trusted UI" is in the first place.
Not mine. I just posted what Niek van der Maas wrote on his GitHub. I don't think he's even reading this HN thread.
While you are absolutely right, I want to highlight that this was done in a quite sophisticated way. It's actually the real login page of Facebook in a webview. I have 2FA on all my accounts including FB, so it looked very legit. Once you have logged in, they seem to grep the token and close the webview.
Some Google auth cookies can only be used on the same tls session that created them[1]. That means the TLS session resumption information (which can be tied to hardware platform features like the TPM) is required to make use of a stolen auth cookie. Unfortunately while that approach has big security benefits, it's pretty anti-user-privacy.
[1]: https://nakedsecurity.sophos.com/2018/10/25/could-tls-sessio...
I've been very impressed by eBay/PayPal providing "very good" almost native-feeling payment integration (swipe-to-pay, UI coming up from the bottom of the screen), so it may not last forever, but interesting to hear of the depth of scamming possible on phone UI's (and probably desktop UI's too).
1) Google Playstore allowing someone to impede on the TikTok brand.
2) The app getting 10k+ fake reviews. At this point can you trust the review system if it can be so easily manipulated?
3) "Strangely enough this is possible without getting any emails from Facebook." Facebook security is weak here. You shouldn't be able to change ownership without explicit 2fa verification. oauth tokens can be easily phished. password + 2fa device is much much harder.
In general the trend I see is that Facebook and Google are driven to making ad purchasing as frictionless as possible. Having scammers, click-farms, fake reviews on their platform is good for them, it helps them make more money. They'll happily tradeoff human oversight/support and security for automated algorithms that optimize $$$ growth.
Apple AppStore is polarizing. Some feel it has too much control, but on the other hand I find a lot less scammy apps in Apple AppStore than Google Playstore.
The fact that they took BTC as payment didn't raise any red flags either, because, you know, BitMain does.
I'm mostly infuriated at Facebook for not validating the company name or doing anything resembling protecting their audience. I lent them too much credibility because it looked like they were ads from the real company's page, and so I let down my guard elsewhere.
I've never otherwise been hacked or scammed, and I know allllll of the basics to look out for, but this one still infuriates me for making a fool of myself.
You can purchase an official ID under $10. Many Indian marketing firms use them.
It opened my eyes to how far scam can go. A billion dollar valuation or millions of likes says nothing.
I filed a complaint but have yet to follow up due to covid. It was a visit due to medical reasons so we didn't focus too much on it.
If you made this transaction with your credit card, you could call up your bank two weeks later and get your $2k back that day.
BitCoin? Kiss that virtual fool's gold goodbye.
Think of it more like cash. If you give someone 2k in cash nobody is going to find that person and refund you.
Except it's being used almost exactly like credit cards, so it is an apples to apples comparison.
>Think of it more like cash. If you give someone 2k in cash nobody is going to find that person and refund you.
Wrong. Tons of cash and debit card transactions can be undone, and banks can and will give you money back from fraudulent transactions.
I reported one of the 'miracle showerheads' to UK Trading Standards [it was possibly ASA?] as it clearly gave false (physically impossible) claims. I was seeing lots of their ads on FB and people were clearly falling for it.
They reported back that it was a foreign company and so they couldn't do anything. Which is weird because they're allowed to advertise to me, so they should have to follow the rules. Also, they had a UK Trademark, which seems a major flaw - protect the trade of scammers but don't hold them to account.
They all offer PayPal so I took the bait once. The scam was clever: they ship something that isn’t what you ordered. Like a jump rope for $1 instead of the $30 lamp (discounted from $200) or drone. To get a 60% refund, you have to send it back on your own cost.
Now it gets more tricky: the parcel might not even be delivered to your address. Mine never arrived but got delivered to a zip code close to mine, but not mine. There are lots of reports of people that receive things without ordering anything and people who never get their stuff. There is also no guarantee what you ship back arrives back at them. If it doesn’t, the company doesn’t refund anything.
I quickly realized this is an obvious scam and asked them to cancel, and opened a PayPal claim before anything got shipped. The company said they are processing my refund and it will take 3 days for my money to be back (which is not how PayPal works). Guess what? In the 3 days, they just shipped something which threw the PayPal claim off because now they have to wait until the shipment arrived and gets sent back (info from PayPal cs).
It’s been over a month and I am still trying to get my money from PayPal back. It’s difficult because I haven’t received anything but the shipping number says it arrived. The site no longer exists and the email I previously used to reach out is gone too.
It’s crazy to me that PayPal enables all of these scammers. They clearly know how to play PayPal to get around the buyer protection.
These days I can’t trust any ads because of this unless I do a lot of research on the site. It’s very likely all scam. I saw similar sites on google shopping (the price comparison product), so it’s not just Facebook.
Luckily for me, taking it up with PayPal got me my 100% refund, but I was nervous while they went through the motions of asking the seller to settle up with me, which I had to approve or reject, and then PayPal would review further. Screenshots of everything, showing the weird random email addresses, and the fact that their website didn't exist anymore landed in my favor.
But there is a thread on the PayPal forums and a lot of people don't have the luck I have - https://www.paypal-community.com/t5/Disputes-and-Limitations...
It's hard to believe that this seller is able to play PayPal like this though. There must be dozens over dozens of claims against the same vendor at this point.
But I wouldn't think twice if I was asked to enter my credentials (which happens if you don't have the Facebook app installed) and didn't receive that permissions prompt.
> Initiated a PayPal chargeback process - PayPal responded: "we’ve determined there was no unauthorized use"
While I get the impression that the user had authorized Facebook to charge via PayPal in the past, I find this conclusion rather silly. If I give my credit card number to Amazon, and someone hacks my Amazon account and starts making random purchases, chances are I'd have no trouble filing a chargeback.
> Tik Tok ads business is best application. It's very awesome application.
And every other review is similar
Specifically, I think it would help for them to verify ads, as they do people / pages.
If you're thinking that sending pictures of identity documents or bills is going to fix it no, it's clown-tier identity verification and will just postpone the issue a tiny bit with massive human resource cost and false negatives.
I remember learning this when I got my first code signing certificate. I had to jump through a TON of hoops including sending notarized copies of my ID to Comodo. After all that, they asked ME to send them a list of notaries for my jurisdiction. They also wanted a direct line to call the notary I used which is basically impossible to provide.
The verification is outsourced to the cheapest English speaking 3rd world country they can find and there's ZERO localized knowledge. I don't think you could build a system that's worse if you tried. The whole think is just a process of checking boxes which is very similar to most of the 2FA systems in existence.
I learned that a lot of apps behave differently if they find a different language keyboard. I don’t know if this attack is still possible in Android, it’s been some years now.
Where I'm going with this is that there needs to be some sort of mandatory linkage between something you trust and this random app you see on the app store. You trust Google. You trust TikTok. So why doesn't Google generate some sort of code that TikTok can stick in their DNS (or website) to create a linkage? By default, an app on the store could say "not trusted by any company", but then TikTok could add that record on their website and it would say "Trusted by TikTok" or something.
There are some problems with this, of course. Anyone could claim any app, and then you'd see incorrect information. DNS and web servers can be hacked, TLS roots of trust aren't trustworthy, etc. But there has to be some way to create this linkage safely, so that people aren't misled again and again and again in the same way.
1) His FB credentials were hacked?
2) All to force 'spend' on some odd Vietnamese add? How does that benefit the scammer?
3) If the money went to FB for clearly scummy purposes, how on earth does FB not simply refund the ad spend? There's not cost of goods sold here for them, usually they should be pretty easy on giving you the money - or at very least giving you credits?
There's always money to be made if you can generate significant legitimate traffic to a given destination.
2) The scammer either actually has a vietnamese metallurgy business ore (more likely) sold ad space on facebook to a vietnamese metallurgy business.
3) yes
If you are able to use the account to purchase something in my name, I would expect the security to at least include a 2FA prompt. I'm not really big into the Facebook ecosystem but this sounds terrible.
Thankfully, I had paid with a credit card as the PayPal funding source for that transaction, and I disputed the charge with my CC company, which found in my favor, and did a chargeback to PayPal.
After that, I immediately unlinked all of my funding sources from PayPal and closed my decade+ account. Never again. Not as a buyer, and certainly not as a seller.
These places (facebook, google, etc) really need to separate the "login with ____" button with a "authorized ___" button. Several times I've tried to login using google only be greeted with a permission request, such as READING ALL OF MY EMAILS. Even Dropbox requires you to give them permission to your contacts if you want to login with google.
When you're not paying attention it's really easy to miss this kind of thing. So much so that now I prefer creating an account traditionally using a generated password.
If it’s a fake OAuth screen? The first tip-off, assuming you use the application, is that it didn’t open the application. The second tip-off, in either case, is that it’s prompting you to log in. You can verify that you are logging directly into Facebook by going back to the home screen (which is not something an application can intercept), and re-opening Safari or the native application. If you were really in Safari / the Facebook application beforehand, it will come back to the same screen. Then you can check the URL to ensure you are on Facebook if you are in Safari.
As far as I am aware, it’s never "impossible to know". However it may be difficult for the average user to know how to determine this. For the average user, the rule of thumb "never log in to Facebook if a different application opened the Facebook login screen; only log in to Facebook if you opened the native application yourself or typed the website address yourself" is adequate.
It’s also worth mentioning that most password managers will pay attention to the domain, and there’s also a mechanism for this for native applications on iOS. So the password manager not auto-filling is another red flag.
Can someone else confirm this?
Those authentication screens are scary.
With a web browser, I can at least scrutinize the URL.
Bu really, the tip-off is the login prompt. Unless it’s the first time using the Facebook application on this device, you would normally be already logged in and it shouldn’t be prompting you to log in to Facebook.
The official app screws up with my share menu. I'd see one set of share targets and just before I hit my choice, outlook will place two contacts at the top. And this causes the remaining to rearrange.
Got pissed and uninstalled it. And I don't want to copy my contacts over to gmail.
I tried two contact apps and they both open a login screen - typing my password both times raised alarms in my head. Neither app worked. And couldn't risk trying more apps. Gave up and reinstalled the official outlook.
The image above is a confirmation that they removed a false AD I flagged and thaking me for it. Yeah, ok, but as I said, I'm getting tired of flagging this kind of ads.
I sent an email to Instagram not so long ago, complaining that is hard to know a official AD from a fake one in Instagram, cause they use that ridiculous thing of opening a webpage inside their own browser (?!) hiding the address.
I'm sorry that this happened to you. I usually deal with low effort scams (but they usually get my parent's attention) but maybe it's time for Facebook to be held accountable for this kind of stuff.
Did you bought a TV from an AD you saw on Instagram and turned out to be a scam?! Well, let's have Facebook accountable. Maybe they'll improve their ADs platform.
They sold virtual space at an almost infinite margin to a hacked account. The account was hacked on their system, the ad that facilitated the attack was ran on their platform and they allowed the whole thing to perpetuate.
If this was in meatspace, Facebook would be an accessory to fraud.
Was that a legit OAuth 2.0/OpenID Connect log in? (In this case this must have been OAuth 2.0 with a scope giving the application write access to business stuff.)
Or was it a phishing page in which the author gave his facebook password?
Theres no way a scam app like Tik Tok Business would be able to stay on the App Store for a sustained period of time.
Even still the Dev admits himself he could have been more on guard with an Android Developer name like "Develop App".
It is a walled garden but the walls simply aren't as high.
Please always check for the correct spelling, punctuation and stylizations of words/brands in a suspected ad. It's written as "TikTok" everywhere, not "Tiktok". I almost always see this kind of stylization errors in fraud ads.
Verification of origin is something companies need to put more effort into in general.
After that, I started commenting on every Facebook scam ad I saw, and guess what? That just got me into the queue for MORE scam ads! Facebook sees me commenting "SCAM" on ads about cheap Legos, and it says "Hey, this guy likes cheap Lego scam ads!"
Plus, these ads go to different sites, have different company names, and different images every time, but they are the EXACT same scam, guaranteed. It's like Facebook is incapable of having a legitimate and ethical advertising business at some genetic level, and all the money from these obvious scam ads is just too good.
This shit is so prevalent and so brazen, I've considered setting up my own scam ad, maybe sell a Qanon book that's blank and say "Fuck you, idiot" inside... I mean, why not? It seems like people are getting rich by fucking over Facebook users, and Facebook LOVES it!
They have such utter contempt for their users. And here I am still using it because it's the only platform I can see pictures of my family members on, as they are non-technical users. Am I supposed to run some kind of internal family campaign to get them all to move to some non-existent alternative? I hate this so much. I feel trapped by Zuck's heartless machine.
I once created a Facebook account to test something and for some reason it decided I was some sort of gambling addict (that e-mail was registered on a legitimate gambling website and I guess they leaked it) and the "people you may know" was full of fake accounts all related to some kind of scummy mobile casino game (I guess the game requires login with FB or maybe gives new people free tokens so they just register tons of fake accounts?).
I've spent a good 20 minutes reporting every single one of them (up to actually hitting the rate limit on the report endpoint) and not only did the algorithm not take the hint that maybe it wasn't a good idea to recommend me more accounts out of that category but their support didn't deem the majority of them as violating the community guidelines despite them being obviously fake (and I couldn't notice any difference between those that were deemed as violating their guidelines and those that don't).
1. Inconsistent spelling TikTok vs Tiktok, business vs Business in app names and logos
2. Inconsistent font in Tiktok logo (Times New Roman like font in Android app, wut)
3. Typos and clumsiness: "vocher" instead of "voucher"; space between $ and 3000 on confirmation screen.
4. As mentioned, the app developer not being TikTok
I'd not be surprised for random person to fall for this, but an experienced techie should have seen many red signs.
(Having said that, as some other comment said, logging with FB on mobile is inherently unsafe because you can't really tell if it's FB or impostor site. Plus the way the ads markets work, which is just built for scams like this. Modern web sucks).
What tech-savvy person is not only SEEING ads, but would actually deliberately click on one? I feel like I'm taking crazy pills.
You don't click on ads! Why would you click on an ad! What's wrong with you people!?
As user beefield points out, another good rule of thumbs is to just never buy or take anything from anyone who approaches you or communicates to you if you are not the originator of that communication/request. Just don't do it, and you save yourself a lot of pain (and don't worry, you're not missing out on anything).
Sorry that you have to deal with this, and well done on actually flagging all these things as suspicious. I also sometime make these tradeoffs, when something sounds 'not quite right' I would still sometimes make a judgement to ignore it.
The fact that just about every damn site (reddit, etc) all desperately try and force the issue makes me think that if apple/google had ones best interests at heart they would disable the functionality.
If the price is consistent across them, that means 1000 reviews costs about $3.1k. Expensive, but it apparently only takes 1 tricked user to become a profitable scam.
Not saying a similar scam would not have fooled me, as I'm looking at the screenshot in the article with the knowledge that it's a scam, so it's an unfair comparison. However the first thing that immediately stands out to me is there are no 2,3,4 star reviews on this app. The reviewer comments are also very generic and have many grammatical errors in each featured one in the screenshot, and the featured reviews are all from Sept 1.
[0] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
This is both incredibly frustrating and incredibly unsurprising.
'we're inspecting your home on behalf of the government' [steal your jewelry]
'we're calling from your bank as there's been a problem with your account; we need you to read an access code from your phone' (steals savings)
'we're calling from your pension advisor as you appear to have been missold payment protection' (steals pension)
They're doesn't appear to be any need for dishonesty on the part of the conned.
It's possibly easier to con a greedy person?
Yep. This is why I avoid PayPal like the plague. I've never heard good things about them.
FYI I believe there is a way you can see the ads you've clicked on in the last 3 months from within Facebook settings somewhere.
https://www.paypal.com/uk/smarthelp/article/what-is-a-billin...
To cancel the billing agreement, follow these instructions:
https://www.paypal.com/us/smarthelp/article/how-do-i-cancel-...
Some merchants encourage or force a billing agreement before the customer can make a purchase. The PayPal UI does not make a strong distinction between entering into a billing agreement and making a standard purchase. For users who are not familiar with the PayPal checkout process, the billing agreement UI looks just like a normal step in the process.
I had around a dozen merchants who were listed in the automatic billing payment list and only one of them was a subscription I remember setting up. (the others were all legit and large businesses and none of them have charged me, but they could have!). I have since 'deactivated' all of them.
I really do hate Paypal but I often choose them when I buy something from a smaller web shop as I do not trust the web shop to keep my card details safe...
https://apkpure.com/tiktok-ads-business/com.acazira.tforbusi...
Never click on them
TL;DR: don't click ads
Those two statements are mutually exclusive.
Spam and web advertising have always been underhanded, and if a person with "15+ years in adtech" can't avoid an ad scam, what does that mean for everybody else?
That was like, the #1 rule I learned in the 90's: don't click on banner ads unless you want to get a virus or get scammed, what the heck.
Just to be clear, this didn't happen to me. I just posted what Niek van der Maas wrote on his GitHub. I don't think he's even reading this HN thread, so no use giving him advice.
I wonder why something like this never happens to me?
- I am not paying a dime for advertising as it is completely inappropriate to spam more users with ads (Zillions of ads and you are one of them? And this works? Really? Not for my users and my reputation.)
- I dont use facebook as I have real friends to go to a beer with
- I dont open any ads (but ad nauseum [1] does)
- I dont use TikTok and I dont see anything positive in it so even if I would be advertising I surely wouldn't spam kids with ads
-- ...
(I could call this whole event a "poetic justice")
(edit: fixed wrong wording as suggested - anyway I dont attack op - in same manner I dont attack drug dealers. I am just explaining why I dont do that. Or sell drugs. Someone might learn something from it.)
"inappropriate", as in: "Your attack on OP is inappropriate."