The Victim Cloud: Gullibility in the golden age of scams
harpers.org
harpers.org
* Walgreens auto-calls me with prescription updates. For "verification purposes", their system asks for my date of birth. I hang up.
* Bank of America sends out emails with clickable links on them. I've reported that to their own security reporting address, but they still do it.
In the US, the legal protections for false charges on credit cards are pretty good, while the ones for debit cards are terrible. So avoid debit cards, Zelle, PayPal, etc.
It’s also sad how many people are willing to participate directly in these scams. The person calling and pretending to be “Miss Barbara” was not committing some targeted crime of passion. She was going to work every day and calmly stealing from trusting strangers. Someone who can do that day in and day out is seriously sick.
I’ve had many artists or their brokers that could have scammed me, or made things very inconvenient, but did not.
If you drop 4, 5 or 6 figures at an art show, you walk away and leave the piece on display. “My people will contact your people in a few weeks” kind of interaction. It can absolutely get taken advantage of.
I was immediately contacted by their social media customer support team.
They then phoned me to arrange the change. I told them off for bypassing security, but I was pretty confident it was them and did not give them any private info.
But if you insist on the bank acting securely, your life will be even more of a hassle. Note that in this case they had ignored my normal messages, so if I brushed off this call, most likely I would make no progress at all.
Most banks have the feature but it can be annoying to setup. Another issue I have had is both email and phone providers may start rate limiting or marking as spam if you get too many automated messages.
Latter part is somewhat fine, even if an opinionated default ("report all, no exceptions") would have sufficed.
Former is the annoying part, mostly because Bank of America's app is just slow and still isn't up to par with their website. Notably, the virtual card function is not present on the mobile app, even after many years (imagine a really bad Privacy.com clone, like really bad, but it still has virtual numbers at least).
Because people just get used to this being boilerplate and anyway services such as Plaid “override” that, so why wouldn’t “the bank’s own employees” do it?
No, we need exactly what I said above
Everyone should have a policy of never giving out personal info or confirming any digits until they HANG UP AND CALL BACK on the corporate number to discuss any issue.
Mandating that by law in the US would easily make these scams a lot more difficult to pull off.
Only HSBC requires a token to authorize transactions that I have found so far (token +PIN) Most happily let you do anything once logged in.
That said, I am sure we have all heard someone complain, “Why am I getting these login codes from my bank? I am not trying to login”. Most people don’t make the connection to fraud attempts.
As an example, an older friend called me the other day to say amazon had phoned him about his prime subscription needing to be renewed that day.
Does he have a Prime subscription - no Does he have an amazon account - no
Yet he still thought the call may have been genuine.
I disagree, for two reasons. First, an outside-view argument: lawyers who currently practice in that field apparently disagree:
> Deborah reached out to more than thirty attorneys. Only one called her back. Deborah’s eldest brother consulted another, who called her situation “a terminal case.” “There’s no life here,” he said. Her claim was dying, if not already dead.
Second, on the merits: most of the fraud protections have requirements that the defrauded customer notify the bank promptly (either after the fraudulent transfer or after the next bank statement). See, e.g. [0]. It looks like that didn't happen here.
[0] https://www.consumerfinance.gov/rules-policy/regulations/100...
has someone built a library or something we can replicate some of these banks/amazon so that more people can waste scammers time deliberately instead of watching sports for example.
i mean if i have an hour to kill, i could watch a movie or the game or waste an hour of some scammer because scammers are not going anywhere. if they are busy with you in an environment you control, they are not scamming anyone else.
i think there must be resources available so that more people do this. the banks have all sorts of kyc/aml so we can definitely drive their banking channels down as long as crypto is still not in the mainstream.
even then, imagine a dummy bitcoin/xrp client that actually uses testnet but doesn't display that fact to the user, that way we can use the funds in the fake bank to buy fake crypto and spend a day waiting for the bitcoin transaction to reach the testnet address. thats quite a good way to waste their time
The default 2FA solution should be Google authenticator or an analogous tech. If SMS MUST be used, it should be opt in.
Notification of anomalous transactions should be automatic, not something you have to configure.
Anomalous wire transfers should be flagged and require verbal authentication by phone.
Banks should stop sending so much spam marketing email so that when people receive an email from their bank it is something they actually read.
Etc
* I have to redo all my codes, and that’s annoying. I have about 15 and it took me almost an hour of logging in and out of all my accounts to switch the device. It’s very cumbersome and in most cases logs me out of my accounts on other devices. It’s frankly a huge pain. I understand the need for it but there needs to be a better way if we’re going to be 2FA everywhere.
* Most sites/services don’t have an option for “change to new device” although some do. In most cases the way to change the device is to turn 2FA off, then turn it back on with the new device. It’s a terrible user experience (it’s not like it even tells you this is what you have to do, you just have to know it). If 2FA is so critical why do I have to disable it to switch auth devices?
* The flow for using it on many sites still treats 2FA as like this geeky or techie thing, it would be very off putting if I wasn’t familiar with it. They’re not very reassuring about what it does or how it works (although some do try to help the user understand it).
* Backup codes are janky and not always offered. Sometimes when they’re offered they’re explicitly provided when enabling 2FA, sometimes they’re a totally separate menu item and the site doesn’t explain why they’re important, some don’t have them at all, and most just dump a text file of weird letters and numbers in your download folder. No header or anything to say what they are when trying to find them later. Abysmal user experience. I had to resort to printing them out and scribbling with a pen what site they were for. Some sites though do better, and include header info and/or a print button. Just not many.
* The Google Authenticator UI looks utilitarian and unintuitive. It’s nice that it’s so uncluttered, but again if I wasn’t already technical I would struggle with feeling comfortable with it. Why are the numbers blinking? What’s the countdown timer? Oh no the numbers are red now! Did I break something? Wait now they’re green again. What’s going on?
I love 2FA and think it needs to be way more ubiquitous. But at least right now it’s still pretty shit.
Retailers would a lot of the times not do additional security checks because those cost money. If someone buys something for 5-10$ the retailer doesn't pay for additional verifications to the bank and they are then liable for the loss. Sometimes they won't even pay for that for larger amounts OR that they avoid doing those checks because it breaks the transaction flow and the customer might just cancel the transaction - most of us are impulse creatures and if we're adding additional checks then the impulse could be stopped.
Banks also still use SMS messages for verification. SMS is horribly insecure[1] and it's shocking to see it's still the last line of defence between your life savings and a potential attacker. Yet having worked in this field, I know that the decisions are taken from a purely financial/time frame point of view. "We have 6 months to implement this, our devs have done this before and thus an SMS carousel is the easiest to implement. TADA". Or "we have already the contracts setup, we have done this for this other account type, so we're going to reuse it". There are very few incentives to use anything else and it goes back to adding friction in transactions. If our world wouldn't be obsessed with buying quickly and easily, more defences could be added.
Lastly, banks are horrible at talking to people. They don't know how to do it at all, so they cannot make communications clear. The biggest impact to fraud prevention would come from nationwide campaigns were users are shown some of the most common ways these attacks occur. Common sense suggestions also seem to lack entirely - "if you're ever unsure, pick up your credit/debit card and call the number on the back of it. That's your bank's contact number, it doesn't need a website, you don't need to call a number from a message, just call this one number". One bank I worked at did this small communication exercise and over the next few months it accounted for a significant decrease in phone-related fraud.
It's a very complex issue and I'm seeing Europe being the next big target from what I have seen regarding anti-fraud processes in European companies (a lot of them rely on outdated tech that cannot handle checks fast enough). European banks also move a lot slower than UK banks, transfers move slow, security checks are poor and in general they seem to spend A LOT less money on fraud prevention... Cybercrime is on the rise[2] and we're horribly unprepared.
Blaming people is the worst approach. We can all fall victims to these types of attacks, but we should spend time to educate those around us and exercise a bit of caution, yet understand that we can all be victims.
[1] - https://krebsonsecurity.com/2021/03/can-we-stop-pretending-s... [2] - https://risk.lexisnexis.com/-/media/files/financial%20servic...
And the fact that calling back means a looooong time on hold discourages people from doing it.
The scammer must have known before:
1) the victim's telephone number
2) the victim's Login AND Password (or Pin) to the bank website
What the scammer didn't manage to do was to intercept/mitm/whatever the SMS and thus needed the victim to read it aloud.
Or is US bank website access different from here (EU, Italy)?
Here to access the website you need to input login, password then request an SMS code for the authentication, and later you need to request an SMS code to validate any transaction.
But they neeeded anyway the login (here it is a customer number, usually).
I was referencing the parent post because - like everyone else - is talking about SMS interception as one of the major flaws in the authentication process, the way this scam has been carried seems instead to make it (the SMS code) the only thing that would have stopped it (if the victim hadn't revealed it, several times).
Fraudulently get a PPP loan, fraudulently get it taken out of your business account from a bank that should be considered to fraudulently subject its customers to poor and arbitrary security measures
Turtles all the way down