I'm a security engineer and I still almost got scammed
robertheaton.com
robertheaton.com
You'll get your money back. I'd go as far as saying that if the bank genuinely wants you to decide fast, it's not to protect you. It's to protect itself. Shenanigans about "do it fast or they'll take more" are bullshit always. The bank is on the hook, not you. So never do things in a rush, take your time to verify yourself that money indeed disappeared. There. is. no. urgency.
Sense of urgency is one of the best ways to make people do bad decisions. Salespeople use it, scammers use it. Nobody who is trying to be helpful will come with a story "that needs to be fixed now!!!".
If you still want to be safe, and you use a debit card, have 2 accounts. One with the bulk of your money without a card associated with it. One with the card associated with it and no more than whatever you spend in a week. If you use a credit card, it totally doesn't matter, it's the banks money, not yours that they'd steal.
So whenever you find yourself in a situation where someone wants you to decide something fast that you didn't know about and isn't a direct threat to your life, don't do it. Think about it first.
It's impossible to keep up with all the scams, but if you stop to think and never take rash decisions you don't have to. Slow is safe.
I got some details wrong; in particular, the initial dispute denial was after two months (with the Consumer Financial Protection Bureau agreeing with the bank after another two months), and the resolution followed NJ Advance Media contacting BofA.
12 CFR § 1026.13 (f)(2)
Did they volunteer these details or were they asked? This is just conjecture, but sometimes when people volunteer too much information to front-line support you can get erratic responses if they latch on to superficial parts of the story rather than the underlying message.
i.e. support just hears "I gave someone access", and they close the ticket under "customer authorized someone else to purchase", because they're following a decision tree, not analyzing the root cause of a security incident.
If someone takes money from my account, it is absolutely urgent.
Now I use a "proper" credit card for anything. If a crook manages to run up a tab on that thing I still have all my cash for whatever scrapes may come along.
The bank executed on their promises of no disruption to his transfers; they told him he did not have to worry and the customer service was so terrific, he said he was going to stay with the bank.
"Did you ask if there were other accounts at the bank that had been accessed in this way?"
"A wire transfer to an international location went through with no red flags and 0 notifications?"
"Can you ask your security department to produce a report of their investigation into the matter?"
Nobody asks those questions.
There is, if you have recurring payments on the same card. If the bank knows there is fraud, some won't honor even known recurring payments. The card may be outright cancelled.
If one of those recurring payments is, eg, your Apple icloud or personal gmail/gsuite/gworkplace account, you better hop to with the utmost urgency.
^ THIS. your bank is training you to get phished. your health insurance, by leaving fake-urgent voicemails that require miserable phone tree navigation when you call back, and by having a million different numbers which resolve to 'scam or at least spam' aggregator sites when you google them, is teaching you to get phished.
my health insurance has a process which involves calling me and asking for a bunch of personal information. I called them back at a known number to ask if this was their number and they didn't know. I called three agents and they gave me three different answers. One said it was a 'system error that will be resolved in 24 hours'. Another said it was fake, don't trust it. A third called the number while I was on hold and assessed it as 'probably fine'.
teach someone to get phished and they're phished for the rest of their life
never accept inbound calls
This blows me away. Probably fine? That's the worst possible answer IMO.
This is a keeper.
I had an issue once with a claim. It was an ongoing ordeal with lots of small meetings and documentation. It was eventually denied. However, I had a rebuttal window. Unfortunately for me, it came during a stressful period of work. I made the initial call to my rep. No call back. I was buried under work, and the 5 day rebuttal window (how absurdly short) blew by without me realizing it. Turns out the rep was on vacation, and after my case was closed, there was no reason for them to return my call.
These issues are never a matter of urgency that should be dealt with in that instance. However, don't let your window of opportunity close due to an adversarial business policy.
out of curiosity which insurer did this + in which state?
I’ll sometimes accept them, but I will tell callers that I will reach out independently to the institution via a main number to continue the conversation Generally causes the old “the main number won’t be able to forward you to me…”.
I really think that security engineers should know this.
Still, I'm glad he's not embarrassed to share his story, to help others be more aware.
Lot of snake oil in the field at the moment.
> CISSP is much more consistent and predictable and known than random sampling of leetcode questions
Even the CISSP is just a test of memorization - The ISC2 cert prep book is 10 miles long, but only about 5 feet deep (if that makes any sense).
Being a good security engineer comes with experience and knowledge of basic scams such as caller ID spoofing (something I did to my friends as a bored 6th grader). Being a good security engineer is having a keen eye for small changes and being skeptical about EVERYTHING.
Any security engineer worth their salt would never discuss anything containing PII on an inbound phone call.
Yeah. Clearly "security" means something different to him than it does to us.
Except passing the (broad, but shallow) test isn't the real reason why CISSP is a decent certification.
Passing the exam is just the first part. You then need to document at least five years of professional infosec experience[0] and have one or more current CISSP holders recommend you[1].
Experience and the approval of your peers are much better predictors of value/knowledge than a test.
That's not to say that every CISSP cert holder is a rock star, but it's a lot more than just passing a test.
[0] https://www.isc2.org/Certifications/CISSP/experience-require...
I would not recommend viewing the CISSP as anything other than an attestation that someone can memorize a few concepts for a test.
I know plenty of leetcode aces that couldn’t work on a real world application if their lives depended on it. Leetcode might test the ability to write some academic algorithm from some college textbook, but it doesn’t test real world.
There is a reason many top companies don’t use Leetcode or HackerRank: zero prediction of real world skill or systems thinking.
Then again, even the other 10% of any given field that is actually good at what they do still fucks up occasionally, so maybe we needn't judge too harshly.
While this is more psychology than technology, that's very important in social engineering.
[0]: https://www.nytimes.com/2022/03/30/business/spam-texts-veriz...
FWIW, I had to answer the phone at my first office job in ~2005, and the office manual has a section on how caller ID was not trustworthy caller authentication. None of this is new, and it is odd that a self-described security engineer would blindly trust caller ID.
I do see how young adults are still not aware of that since they are not valuable target and their info is relatively unknown (no mortgage on their name, no car loans, cell phone number is not old, they never sign up for sweepstakes in Las Vegas, etc.)
The job of security engineer is a very very wide spread one. Someone might be an expert wrt. detecting avoiding DDoS, RCE, encryption and/or signing that doesn't mean they are an expert in social engineering or phone security.
You mean the post office?
Anyway, back to the point.
Sophisticated scammers can spoof your bank’s phone number and send a message that appears in a thread alongside other legitimate SMS from the bank.
This is harder to do than caller ID spoofing, but has become more prevalent recently.
Really, "security engineer" is as vague a term as "programmer". Web programmers are programmers yet they don't necessarily understand the layout of virtual memory or the way the kernel interacts with userland programs, something many other programmers would consider essential for their jobs. A kernel programmer couldn't give two hoots about how Chrome's CSS engine works, but the vast majority of modern programmers probably do.
I've had lectures in university on natural language processing and data structures that were slowed down because the lecturer couldn't get the beamer to work right with his Macbook. You can't expect someone to know everything, even if it's in their apparent area of expertise.
I'd go so far as to say that any security engineer worth their salt will admit that they too are vulnerable to being scammed under the right circumstances and that anyone pretending to be unscammable is severely overestimating their abilities.
However, I think it's common knowledge that inbound identifiers like IPs, user agents can be faked and aren't great technical indicators to anchor detections on for longer than an active incident. That intuition should extend to caller ID IMO, if they didn't know it already.
POTS is rarely of interest to a security organization. You have very few levers to pull even if you do consider it a threat, since it's just fundamentally an awful system, and you can't tell people "don't use telephones". At best you can train people, but your concern is probably phishing via email.
Only a few people, at the company level, are at risk in terms of this sort of attack, compared to everyone being at risk (with regards to the company) from phishing emails.
So a lot of people just don't really think about it. Security engineers might hand wavingly say "phone numbers can be spoofed" but I'd bet the percentage of seceng that know how that works is very small.
Not one person understands all the technology in existence, and no one person ever will.
Also engineers come in different levels of experience. Just because someone doesn't have experience in specific technology doesn't exclude them from being an engineer in a specific field.
I immediately tune out when anyone describes themselves as a security engineer.
One special class of vulnerable targets is security experts, and top ranks. I remind my students that "pride comes before a fall" and nobody is immune. While doing some training for <BIG INTERNATIONAL BANK> someone told me they call it the "cocks problem". It's the handful of 7 figure salary high flyers that get regularly pwned and cause grief for everybody else, because they are "too cocky". Lowly secretaries and desk staff are much harder marks. The more training you give to people who think they're above it the worse they get. It has to be pitched as participatory advice, as an invitation to co-create a secure practice.
We saw this cavalier attitude just the other day with Boris Johnson [0]. I bet Johnson was told time and again to use equipment that had been checked by his security detail. And I still cringe thinking of this one [1].
I suggest there's no correlation between domain knowledge and behavioural invulnerability. Good security posture is a mind-set. I also think it's a very strange combination of contradictory qualities (or attitudes you can be trained to adopt) that are hard to describe, such as high conscientiousness and humility mixed with utterly cynical disrespect for "authority", high openness but brutally meticulous self-checking and introspection. And definitely, never call yourself an 'expert'.
[0] https://news.ycombinator.com/item?id=31075558
[1] https://www.arrse.co.uk/community/threads/77-bde-twitter-fee...
I guess the common factor is that the most important thing is to be careful and follow the proper procedure to not get caught in a problematic situation in the first place, not to be overconfident and assume you are safe because you can handle any situation with your knowledge or skills.
Totally. I saw this Krav Maga instructor say:
"Now. I'm going to tell you one of the most effective self defence moves known in any martial art... run away!"
> security engineers need to design systems that are resilient to them
The problem here, to a security engineer, is that we need better systems. I suspect they mean the hardware and software systems, although the 'system' includes the participants. The problem and solution space should strongly include people as it just was clearly demonstrated.
Could be an occupational hazard, having seen so many insecure and poorly designed system to have low opinions of them. Having low expectation of security practices sets a lower bar for acceptance of what's authentic. I can't say if I would be caught in similar circumstances without being in the moment. The two things I hope I'd do is see the tx in my own history and not tell a human a code. These are for machines to verify. I recall when everyone switched their system so PINs could be entered for machine verification and the human returning after. A machine sent code should also be checked by a machine.
A practice that does bother me greatly is how many different domain names are used by a company. Only subdomains should be used for any kind of official interaction (or perhaps period).
I was pretty annoyed that they didn't follow good identity practices by encouraging their customers to trust people who could be scamming them.
Phone numbers as a proxy for "who is calling me" is terrible. Numbers change, numbers can be spoofed, numbers can be stolen. All identification that happens via a phone is fundamentally bad and it is only getting worse.
The trick is, don't use phones. Really. Block every number that isn't someone you know, for starters. If someone calls you and it's a bank ask them to contact you via email, and only use the phone to confirm what has already been discussed via email - for example, if you are performing a wire transfer, initiate that via email, and if you confirm information via the phone never offer any information, just validate what they say.
This issue is so common and pervasive that, as the author demonstrates, we just assume everything is horribly broken and when something is suspicious we just think "well, everything's horrible, so why wouldn't this be horrible?".
"Silly but plausible" - this is the cost of security theater. I have to jump through hilariously stupid loops sometimes.
But ultimately I blame phones being used as proxies for identity.
https://news.ycombinator.com/item?id=30869427
"I'm a scam prevention expert and I got scammed" (544 comments 20 days ago)
Wrong. Some banks, and with certain account types, the bank will absolutely make a courtesy call to you if something unusual is happening.
I had a call from my bank while spending a few hundred on cocktails in Bali (I'm from London), I hadn't used my card yet on that trip as I'd taken cash.
They also called me to check a payment into my account with an "unusual" reference; a joke from a friend returning the money he owed for a holiday I paid for, but which made it look like he was paying me for "special services".
They called me to query a payment at a home furniture store for a couple thousand pounds in a city ~300 miles from where I live only hours after I'd used the card near home; I'd driven to this particular store to check out the furniture.
If you're not sure, the _real_ bank will suggest you hang up and call their number found on your card or their website (or in your contacts list, where I keep it) and will never pressure you to answer or provide them information, and they'll NEVER, EVER ask you to read a security code out to them sent to your phone, or using your banking app.
EDIT: To further clarify; my particular bank's app, has, on rotation, a series of warnings, displayed each time I log in, saying things like "BEWARE; if someone [calls/texts/etc] asking/telling you to do [XYZ] ...", e.g. to get this code or that code, or do something else in this app, you're being scammed, "WE WILL NEVER ASK YOU FOR [XYZ]...".
Here's a comment from a similar post last month, where the commenter believes the legit bank asked for a verbal confirmation of security code: https://news.ycombinator.com/item?id=30875233
(I suppose it's possible the commenter was actually interacting with a scammer there and still doesn't realize it?)
He was 100% being scammed.
That would be stunning in it's own way! What a world.
“Amex Fraud Free Msg: Your requested code is: xxxx. We won't call to ask for it. Don't share it. Call ######## if you didn't request it. Reply STOP to opt out.”
You wouldn’t be the requesting this text and code, the person on the phone would. And it says don’t share it. Maybe I was hoodwinked but it seemed really legit although in principle I refused to give it.
It seems so scammy, but I’d called the number on the back of the card.
I presume because I initiated the call they think it's ok, but it's still silly.
I think reading any code during inbound call is red flag for fraud. However, more than once i took the initiative to call ccs to unblock a large / international charges. The only way for the bank to verify my identity is for me to read the code.
So it is not true that you NEVER read ever. Maybe for inbound this should be true. But not outbound
We called the credit card company and there was indeed a fraudulent purchase, so yeah the real companies don't pressure you into unsafe things.
Mine dit that as well a couple of times (Santander UK; my account was nothing special though I do travel internationally several times a year; it was a mistake every time and I never had any fraud with this card). The first time I took it, but now I would say that I cannot, end the discussion, and then call them to their known number. Also, I’ve never had a human ask me to read numbers from a text message. They (well, another bank, but still) do occasionally ask me to unlock their app using either biometrics or a PIN; they can see it in real time and that can only be done on a single pre-approved device.
Collectively, we software engineers that have security focus, have done a piss-poor job with 2FA. Users should've been trained from day-one that 2FA codes sent to their email or SMS should never, EVER, be repeated back to a human. All the additional text sent with the code should clearly and emphatically state that this number is between you and a website that you are reasonably certain represents a secured entity and that you explicitly requested during a login flow. It's like the combination to a safe: that code is between you and the dial on the safe, if it ever verbally leaves your mouth, you're doing something wrong.
Any orgs that use 2FA codes to authenticate a user to a CSR are screwing it up for everyone. Don't do that: you should be able to mutually authenticate using shared knowledge that a hacker isn't likely to have (not an address, FFS), like the previous transactions thing the OP requested. 2FA codes are for computers only.
I don’t understand security researchers. Is it all just a bunch of hooey they sell or what?
An MitM attack is significantly harder than "I have your CC number and I'll use it with no authentication", therefore it does increase the difficulty for fraud. Though I haven't seen a requirement to enter the bank's password, my one requires me to confirm the transaction by opening the credit card provider's app on my phone which isn't vulnerable in the way you're describing.
Like, let's say I insisted on hanging up and calling the number on the back of my phone -- are there any cases that would be disastrous for me, would end up in me losing money, and I really should have stayed on the phone with the person who called me, who really was a non-fraudulent representative?
I'm not confident there are not.
I honestly believe that there are no cases for that on a credit card. On a debit card, that might be different. This is why I never use my debit card for purchases.
Any suggestion on how I should politely and professionally answer a call without giving away my identity?
If it’s important, they’ll leave a voice mail and I can call them back.
The telephone is broken.
It also makes the battery last twice as long.
With that said, I almost got duped by a good samaritan debit card scam about 20 years ago in Toronto.
Along the topics others are replying with, I also don't answer calls usually, and have a call blocker so I'm only notified if someone from my contacts list is calling or if they are recognized by my network carrier as a verified business. Since businesses can also be spoofed, I still don't give any information and find out why they are calling, then politely hang up and call back myself, after first verifying the number in about to call is actually associated with the business.
Credit card fraud is not urgent unless maybe you know your card has been deactivated. They can leave a quick message if your relative is in the hospital or whatever.
"Ahoy" — Alexander Graham Bell
Seems to get me on a "don't call this number" list after a few goes.
I also don't mind confirming my name. But I try to never say "yes" or "no" when they ask if something is right, I respond with "That is correct" or "That is not correct". That may be me being too paranoid of people editing the conversation to make it look like I agreed to something I didn't.
There was some point where I was getting a call that claimed to be a collection agency trying to collect on a DirectTV bill. I've never had DirectTV. They kept trying to get me to confirm an address, I kept informing them that I've never had DirectTV. They would usually hang up when I would press them on who their employer was. They often made the mistake of calling during my commute when I lived roughly an hour away from my place. So, you know, I had the time to kill.
It's not overly paranoid. https://www.ag.state.mn.us/consumer/Publications/CanYouHearM...
> The details of this scam vary, but it always begins with a call, usually from a telephone number that appears to be local. When the person answers the call, the scam artist tries to get the person to say “yes”—most often by asking, “Can you hear me?,” “Is this the lady of the house?,” or a similar question. By responding “yes,” people notify robo-callers that their number is an active telephone number that can be sold to other telemarketers for a higher price. This then leads to more unwanted calls.
> In some cases, the caller may record the person saying “yes.” Scam artists may be able to use a recorded “yes” to claim that the person authorized charges to his or her credit card or account.
Used to be used a whole bunch for https://en.wikipedia.org/wiki/Cramming_(fraud) back in the days when you could subscribe to things via your phone bill.
I've probably read something similar at some point, made the change, and forgot the source that made me wary of it. Cutting the ends of the roast as it were.
I use "hello". It's pretty rude compared to how I was raised, but it's also the only way to not give scam calls the ammo they need to mess with me. So I can live with rude.
I find it quite amusing that the scam used the domain `people.ds.cam.ac.uk`, which contains `s.cam`.
Also had a similar title along the lines of "I give presentations on scams and I still got scammed"
It is not like the spoofibility of phone numbers is some security industry specific news. It gets talked about all the time outside of tech given the prevalence of spam calls.
If they want a confirmation, they'd rather use an automated method. Like send an SMS: "Did you spend $X on Merchant, Inc? Reply with Yes or No".
They can't afford a human calling you for every fraud suspicion.
Local couriers often send links by SMS when an international package needs customs duty paid, and they often shorten URLs due to SMS limits. So they might send a URL like couri.er/1ea6dz. Often the payment sites look a little dodgy too, frequently just an un-themed Worldpay form.
Unfortunately I was expecting an international package and an SMS woke me up saying delivery would happen today provided I pay the customs duty. I luckily had gained my senses enough by the time the page had loaded to double check everything, but it could have got me.
When the legit request to pay customs duty came through, it didn't look all that different...
This sort of thing is incredibly easy to forge these days.
I'd also logon to the bank website first to look at recent transactions myself so that I "do my own research" before talking to a person at the bank.
Most often the fraud check is something like an apple hardware purchase that I made months ago which only just went through after I got the front of the waiting list. I'd want to debug that stuff myself first. If I'm out doing something and a text/VM comes in while I'm on thumbs I'll happily wait until later that night to debug the problem. Like the top thread here says, there's no urgency.
Really helps to be an introvert where you very actively don't want to call someone up and chat on the phone about shit, so you first seek to avoid having to talk to anyone in person, and then have all the information you can acquire ready first to keep the phone call as short as possible.
A fraudster called me up (I knew it was a fraudster right away). I played along as he said there had been some fraudulent activity on my account - payments from random locations etc.etc.
The crux was that he wanted to send me a verification code from PayPal. This is where I was dumb. I assumed it was from a fake PayPal messaging system and they knew the number already. When they asked me to repeat it back to them I pretended to be dumb and gave a fake number back, repeatedly. I at first thought they knew the number. It then hit me that they didn't know the number and were actually trying to break into my PayPal account. I was so dumb! Still no bad outcome other than me looking stupid.
"Hopefully" enough people get scammed at such organisations, such that having the ability to easily contact a human at the company becomes a valid selling point, and lack of it an actual pain point for the company, so that pointy-haired CEOs start to appreciate it again.
I had to add my wife's name to our gas bill recently. There was no option to do this from the online system. I had to call 4-5 times to get this fixed. Each time I had to wait about 50 minutes before getting to a human at the other end.
It would take more than thirty seconds to go online and check the account?
“I’m calling about some suspicious transactions on your account ending in 1234. Is this a good time to talk?”
I don't know how it works there, but my bank's fraud alert call is automated and exactly the same every time.
“I’d like to enable enhanced security on your account, but I’ll need to text you a confirmation code first. Is that OK?”
Do banks do that there? Mine won't make any kind of account changes unless I show up in person with ID.
Barry couldn’t use my card to buy anything online because my bank sends me a one-time verification code whenever I use the card on a new website.
This is great. All banks should do that.
Jim Browning is an expert in this area and is sort of famous for his "scamming the scammers" videos where he hacks, tricks, annoys, or otherwise scams scammers.
In the linked video he talks about how he was tricked into deleting his account. These things can happen to anyone, even experts.
Here you can watch video for taking down one of these call centers by police, not so long ago: https://www.delfi.lv/news/national/criminal/video-latvija-ai...
You have instant access to your financial information. You can easily see "pending" and "posted" charges on your credit accounts without a third party.
I don't believe scams are typically designed to maximize success rate per scam; they're designed to cast a very wide net and get lucky on a few targets.
https://news.ycombinator.com/item?id=30869427
EDIT: silly typos
The bank said "we have no record of calling you" and it didn't stop there?
Hey, wait a second.