QR code scammers hitting on-street parking in Texas cities
click2houston.com
click2houston.com
And twice last week. Few times the month before that.
Even configured Exchange to give people a “report suspected phishing” button in their outlook clients.
They keep on clickin’.
(Each time was a different person btw)
Edit following the comments: maybe reversing the approach would work, by attaching monetary rewards to correctly reporting phishing emails? That would encourage everyone to be extra suspicious and report anything that looks amiss for the chance of getting some extra cash while avoiding the negatives of firing people on sight.
This time is much better spent securing the environment: spend the money on Yubikeys, lock down your default browser or use an isolation system, beef up your network filtering, etc. — things which can actually work and won’t make your users think you’re just trying to get them fired.
I guess instead of a penalty a more user-friendly way would be to attach monetary rewards to reporting phishing emails? That would incentivize reporting anything that looks even just slightly suspicious, which is probably a better outcome from a security point of view even with false positives.
We use one of those services, too, and you have to use a very light touch. Just using them at all makes people paranoid. If there are people you find who pose a risk, yes, you should do something about that, but terrorizing your workforce is a terrible idea for multiple reasons.
> putting their own employment at risk
Even looking at it amorally, that only really works in declining industries where people don't have a choice. Do that to engineers in a hot economy, and I suspect you'll be employing only the otherwise-unemployable soon.
Less than 3 months later, HR was begging people to click the link in their email to set up their benefits for the year, because they had a 0% click-through rate.
Hang up, look up, call back.
Turns out it was the link to our mandatory security training portal. Of all the people to get it wrong....
This is why I would usually focus on things like WebAuthn (making phishing much harder) or locking down the default browser environment more so it takes more than one click to cause a major problem. That doesn’t prevent social engineering, of course, but that requires a lot more work and gives more time for other safeguards to work.
Smart person? Sounds more like a person looking for trouble.
Maybe the fake app can say "Now you need to go to walmart.com to buy a gift card and enter that gift card code's to pay for parking", but that would filter out a lot of people who was looking for convenience in the first place. If I were consulting for this criminal, I'd say "You need to get to their greed by offering them a big prize, e.g. 1 year free parking in $CITY...".
These scammers are either smart and done everything anonymously, or too stupid to understand how this can all be tracked, but unfortunately this stupidity does often end up paying off.
Getting the money would be hard, and you would be easy to track.
They would probably be better off just collecting the credit card info and selling it.
I endorse absolutely none of this, just to be clear.
The best scam is the one that isn't detected. There's a story about a guy who collected £3 from every visitor to the Bristol Zoo car park here in the UK. Supposedly he did it for nearly two decades. Car park was free. No idea if it's real.
https://www.youtube.com/watch?v=FsWcc-9KMEc
This one's actually rather clever.
https://www.courthousenews.com/hertz-settles-flap-over-golde...
You're telling me. (not so humble brag) I developed a software solution and 3 patents granted over 10 years ago to stop these kind of shenanigans. Ahead of our time.
*Unfortunately, matrix barcodes may sometimes reference malicious websites, which may be used to steal confidential information (e.g., user credentials or credit card numbers) as part of a phishing attack or exploit vulnerabilities in mobile web browser software that may allow malware to be downloaded to a user's mobile computing device. Furthermore, some legitimate Internet resources (through the use of spam, comment posts, etc.) may be used to redirect users to malicious websites. Accordingly, the instant disclosure identifies a need for systems and methods for providing security information about quick response codes.*
https://patft.uspto.gov/netacgi/nph-Parser?Sect1=PTO2&Sect2=...
People will take the barcode from one bike and put it on others, meaning when someone comes to unlock a bike, it actually unlocks the scammer's bike. By the time the victim realizes why the bike they're scanning won't unlock, the scammer has ridden away.
Just reported them through the generic Stripe contact form (all I could quickly find).
In general, Stripe describes a 7-14 day payout schedule, but has shorter ones for many countries.
Presumably it takes a fair amount of identity info to get to the 2 business day accelerated payout speed available to low-risk businesses in the US.
Maybe this is just a single occurrence in a large scheme with lots more websites & separate payment providers.
I cannot fathom how scammers get away with this. The police have the QR code, the URL, and the cash going out of one account into another. How is it possible that these people don't get caught and locked up immediately?
I bet you could get plenty of marks to do the sticker work.
Door-to-door campaigners, protestors, petition signers, there's a massive shadow labor force of unnamed people getting paid cash for work no one wants to get caught paying for.
The QR code and URL (essentially the same piece of information) point to a server somewhere that could be some idiot running it on their personal real-name AWS account but is probably a dead end of the server host either being shifty/ignorant and accepting cash with no contact details or having given the server out to someone with entirely fraudulent contact details.
It's possible if they're greedy the money trail will be easy to follow, but if they're willing to lose a large proportion of their earnings passing it through some people that can launder money well then they'll probably get off scot free.
As a result, if you’re stealing funds in a purely digital fashion, you can generally expect to be able to steal millions before anyone investigates you. You need to operating at a level where the FBI or, more likely, Secret Service takes an interest. QR codes on parking signs just doesn’t cut it.
If I pay via coins / credit card the parking meter will tell me "Okay, you have XY minutes left." If I pay via the app, does the meter update as well? If I pay via the scam app... presumably there is no feedback loop, though people may not realize this.
As a second order effect, wouldn't it make sense to investigate the domain and find the owners? Assuming they are paying some other party to put these stickers up the owners of the domain are the real problem. Telling residents to educate each other feels similar to the trope of you are a "victim of identity theft" when Equifax loses your personal details.
Looks like it is registered with Google Domains. They use magic.link to send a URL. They are using Stripe to process payments. Any one of these could lead to the perpetrator.
(It looks like Stripe might have shut them down already though.)
Scammers can still put fake stickers/posters/whatever up, but the QR scanner shouldn't trigger an action, it should just provide some static location data when it comes to some payment action.
I think it's just a really poorly thought out system that didn't really research how other successful implementations of QR codes work.
I suppose this is harder to pull off with a lower benefit, and a higher chance of getting caught (i.e. fast acting law enforcement would know which car was in the free space).
To mitigate this, you might need space numbers posted. This is easy to verify that each space is different. But at this point, why even have a QR code?
It should not be an app. Or there could be an app in addition to other methods of paying.
Edit: the reason is accessibility and the fact that they are providing a public service https://news.ycombinator.com/item?id=29818536
With the app, I have to do all of that once and the app remembers everything for me. If I am driving my wife's car, I don't have to try to remember her plate number. I can pay for my parking while walking to wherever I am going and I'll get a notification 5 minutes before my payment expires and can add time right where I stand at that moment. Parking apps can be great though it is annoying that every town seems to have their own app or payment provider.
Edit: just to elaborate a bit further in case it's not clear: should people who don't have a smartphone, or their smartphone is broken, or maybe they forgot the charger home, still be allowed to park their vehicle in a public area? Isn't there a higher standard in terms of accessibility requirements, when you are providing a public service?
Thankfully there are still kiosks that accept physical credit cards so I am able to legally park my car. It's a lucky thing I have a credit card that hasn't been banned because there no longer seems to be any way to pay with quarters.
In some cities the parking meters are run by a private company.
Chicago, for example, leased its parking meters to an Australian company. (Or Spanish. I forget, one got the parking meters the other got the Skyway) In exchange for an up-front payment to the city, the private company gets to run the parking meters almost any way they want.
This includes raising prices.
Or worse, in the Chicago example, the parking meter company successfully sued the city and now Chicago isn't allowed to permit the construction of any new public parking garages in the downtown core, because that would hurt the parking meter business. The only new garages that are permitted are for new residential buildings and a calculated number of spaces exclusively for office buildings for hotels.
If city's hands are tied for more car-centric infrastructure, now they can spend that budget on bike lanes, citibikes, and other transit projects.
I made a comment about how ads are being "stickered."
It could be funnier to replace the menu with a slightly fake one and see what happens when people try to order things that don't exist (but could reasonably be thought to exist).
Or outrageous items. Let's experiment.
I've parked in lots where you enter the parking spot number and payment into a website. There is no physical confirmation, and it would be trivial to put a QR code on the parking information sign.
Especially because typically people are walking into the station while paying, and not standing in front of the sign double checking the details.
Insult to injury, the UI on the legit system is so bad and slow that scammers wouldn't even need to try to replicate what exists. Basically anything else would be an improvement.
If there is something to be exploited somewhere, someone will find it.
Looks like it is registered with Google Domains. Hosted at 76.76.21.21 (vercel.com). They use magic.link to send a URL. They are using Stripe to process payments. Any one of these could lead to the perpetrator. But I doubt anyone will ever be arrested.
(It looks like Stripe might have shut them down already though.)
1. The city should've provided a QR code payment solution along with an app to scan and vet those QR codes.
2. The parking app that includes a QR code scanner, only needs to interpret the information in the QR code (eg. location id + parking spot id), it doesn't need a full URL.
In China QR codes are ubiquitous. You can find them on menus in restaurants, when paying a cabbie for the ride, or a guy in the fresh market for vegetables, you can even buy toilet paper in a public toilet in the middle of the night using a QR code. The reason why there is no QR code fraud is because the payment is done through 1-2 apps which are able to detect fraudulent QR codes.
It would only deter people who already have the app since before, which is already the case, i assume most people just enter the Parking zone number by reading it from afar or using GPS from app, not by walking up to the machine and scan it.
From the Houston police department's 911 information page [1]:
> Call 9-1-1 to report a life or death emergency that requires an immediate response from police, fire, or ambulance personnel.
...
> Do not use 9-1-1 for non-emergency situations -- this causes a delay in answering emergency calls.
Then I realized it was technically a government building and then it all made sense, because cars and bikes get stolen daily without a peep.
They must think they’re stuck with fools for constituents. :)
This is a crime in progress. That's why 911 is being recommended. (Yes this can vary from place ot place) 311 is about reporting that has happened non-crime related a time ago.. 911 is something that is/just happened.
But yes, their messaging is terrible. I'm sure that they're just saying "don't call 911 because your sister is being a pain"
If you felt the person was a danger to themselves or others they were right to redirect you to 911.
Off-topic, but one of the symptoms of alcohol poisoning is confusion. If memory serves, a drunk, off-duty Texas cop once shot in to the wrong apartment, confusing it with their own home while thinking an intruder was present. The kind of erratic behavior you described is absolutely dangerous, especially in a place with as many guns as Texas.
Not drunk, just said she was tired or overworked: https://en.m.wikipedia.org/wiki/Murder_of_Botham_Jean
For what it's worth, Click2Houston is widely known for ad-ridden clickbait masquerading as news. They used to be good, but now they just suck.
Also, calling 911 in Houston really sucks. Good luck getting a response within 30 minutes unless it's active gun related (and even then, I've personally waited nearly an hour after reporting gunshots in my neighborhood). Not the cops fault - they're generally ok, but the city management is poor.
They have to link back to an app on the app store, so they're more trustworthy.
Obviously that can be construed as a down side as well, and the app store isn't immune to scams, but it does give one layer of effective gating
The trains have these big posters, which are ads. They rotate, like, once a month, or so.
Most of these ads have QR codes, to their sites.
I often see that the QR code is a sticker, which means a scammer placed it over the real one.
Here come the righteous downvotes; to defend myself, I never went through with it, and they were ads to promote the city's iniative to invite the corrupt organization the International Olympic Committee so they could feast on our tax money.
So, if you bought gloves at an REI in Bellevue Washington, and got rickrolled by the NFC packaging, that was me.
Maybe some indirect system would defeat this, where the real QR code only works if you have a cookie registered some other way - a phone app or something... and the fake one can't scrape that...
The issue is if your customers are using the QR code to install your app. A scammer can change that QR code and hijack the customer's entire experience.
I guess you could have the city's public ID in your phone and then the city could just sign their QR codes ... or not in this case...
I did it for the lulz but now I think it may be a public service, getting people to blindly trust these things a little less
Sure, scammers are bad, meter maids could incorrectly cite vehicles, and it's highly likely the scammers are doing more than just collecting the fees, but I don't find the basic premise that terrible.
It’s strange to frame this as us vs them. Revenue lost by the city is coming out of your pocket. Don’t you have a vested interest in not having scammers drain your city’s income? I do. It definitely matters who gets the money, if you aren’t singularly focused on the behavioral results of drivers having to pay for parking.
It’s also strange to use language suggesting the city couldn’t possibly be damaged by the loss of revenue. Enforcement efforts are trying to be net positive, cover their costs, and contribute any remainder to other public works.
The contract in chicago also reportedly contained stipulations that the city wouldn't install certain types of infrastructure that might affect parking revenues like bike lanes. That's the sort of conflict-of-interest I was talking about.
In general, of course I agree that metered parking can be a great solution to many issues. I would just prefer that the money actually go to the city rather than terrible private companies.
Right. And that money comes from taxes, right? It’s plausible under the scenario you’re describing that fake QR codes could end up costing the city as well; contractor may argue the city is responsible for enforcing & cleaning QR graffiti. (I have no idea whether that’s the case in reality, just imagining ways it’s possible that you are paying for scammers even though you don’t think so.)
The regulatory capture sucks, especially if a meter contractor is preventing bikes lanes. The city needs to resist such stipulations, but I realize this kind of shit happens all the time. I wonder why the contractor would have such leverage; I would think the city’s in the stronger position. I agree with you, I wish the money were going directly to the city rather than for-profit businesses, especially when those businesses are draining city revenue on a larger scale than some QR hackers.
May as well just not pay the scammers at all then, and now the allocation strategy is just "first come, first serve, stay forever, try to avoid police".