Woman loses over $44k after downloading third-party app to buy fish
straitstimes.com
straitstimes.com
And about transparency: I have a debit card from an EU bank. It's barely usable because every time I need to make a purchase, it has to go through 3DS and 50/50 the transaction gets rejected. On POS in Asia, it's 80/20. So quite frustrating. Anyway, two months ago, I get a 60-70 EUR transaction on it from some merchant. Not sure how the scammer got the numbers (some shady POS in Thailand?) but the operation was via "an online interface" and there was no confirmation.
More bizarre: No one can tell me who exactly debited my card. Not even the bank itself has any idea who the merchant or his identity is. There you have it, a fully dysfunctional system and yet somehow it has become solid because a "less" secure one has lost some people some money.
I have 2 debit cards and two credit cards from UK banks, and my partner has the same. I genuinely don't think I've ever had 3DS reject a transaction for either of us.
> a fully dysfunctional system and yet somehow it has become solid because a "less" secure one has lost some people some money.
No, it's solid because of legislation. Improving the technical details doesn't help the situation, as most of the issues are legislative.
I get a 50/50 rate with local businesses in Mexico when paying online with European cards. I don't even bother with foreign cards for local government portals, the success rate is close to 0% when paying online.
Also, many payments have to be authenticated with a SMS, which is sent to my European number. Thankfully some banks allow to add a US Google Voice number.
I'm talking about normal banks, fintech banks, such as Revolut, are actually pretty good. But I still can't pay the water bill with it.
If so, surely you can see that you are likely to be an absolute outlier and how your behaviour is likely almost indecipherable from actual fraud, unless you tell your bank your not actually living in the country (at which point presumably they close your account which is why you're doing this in the first place).
> I'm talking about normal banks, fintech banks, such as Revolut, are actually pretty good.
My bank accounts are NatWest and starling and CC's are Amex and NatWest - pretty traditional.
No, these things are not the same.
Amazon said there was nothing they could do because I had purchased products to send to her address before (true). Police said they couldn't do anything because there was no proof(false they were too lazy to do anything). Bank said they couldn't do anything because I should have changed my bank account information.
I had to beg the judge and prosecutor to even press charges but she never showed up and the warrant for her arrest (for not showing up 3x) got thrown out within days of being filed.
Looked into getting a civil suit going and was quoted around the same amount of money as was stolen. I guess New Jersey must be "the rest of world".
The amount and sophistication of scam is very worrying.
- If you approach a random person on the street for help, etc, 99 times out of 100 they will be helpful or at least not malicious.
- If one out of the 100 people on the street approaches you, there's a decent chance they are that 1 in 100 people looking to take advantage of you.
Bad people are the exception, there are just a lot of people.
> “I’m pretty sure I downloaded a version of MetaMask with some shit in it,” Cuban told DL News. He said he had searched for Circle on Google, not MetaMask. [1]
[1]: https://www.dlnews.com/articles/people-culture/mark-cuban-lo...
Is there a money manager effectively controlling a Schwab account with $1+ billion dollars? How do you minimize the blast radius to prevent internal/external loss of control? Even sub-dividing a fortune across N investment managers still leaves enormous targets painted on those accounts.
Or is it the more implicit threat that you do not steal from these people or the full weight of the government will aid in recovering these funds?
https://en.m.wikipedia.org/wiki/Family_office
The family office will manage the investment portfolio, typically across not only brokerages and banks but also direct investments / private equity/ vc / etc.
I sold some land, a guy sold me a Ferrari for it. I sold the Ferrari, never even saw it. He just couldn’t be bothered and wanted the land right then.
I will stick with a bank which is regulated to protect my money, and heads will roll if funny business happens.
To be fair, a lot of the crypto hype is predicated, if indirectly, on how few heads roll when (barely quasi-legal) funny business happens through official institutions.
B. "I lost my money while it was in crypto... I didn't get it back and nobody got in trouble!"
I'm not really sure B sounds like much of an improvement over A.
When did that ever happen? Did even a single head roll for the bullshit with subprime mortgages? Some people get a bonus when the scam is big enough.
The government went above and beyond (generating moral hazard) in protecting SVB clients.
Aren't apps sandboxed?
Was this using regular Android security permissions, or was this relying on security vulnerabilities? And if vulnerabilities, is the problem that Androids often stop getting updates, so a large proportion of phones are sitting ducks?
> The seller texted Ms Khoo on WhatsApp and instructed her to download a third-party app called Grab&Go on her phone. The app prompted her to make a $5 payment through PayNow as a “deposit” before her order could be placed, but she asked if she could pay when her order arrived.
> The seller reassured her that he did not need her banking details and asked her to enter her name, address and phone number on the app to check out her purchase.
My guess would be the payment information combined with the personal information (and using that personal information to get more personal information online) was just enough to call the bank and impersonate her.
The app eating CPU and battery is definitely a red herring, even with a vulnerability that let it directly get at banking details there's no reason for it to do that. Probably just badly written.
I would consider an android app sandbox escape bug to be the lowest level of difficulty in mobile phone exploit chains.
I am more interested in the question if this was available on the app store or if the social engineering included her enabling 3rd party apps and side loading. A redacted copy of the chat would probably reveal a lot more how this worked.
Fortunately, the solution of just sticking to mainstream platforms works. If I’m on a Mac with an iPhone, anything that hits me hits half of Americans. I’ll be in a nice big class-action once the damages are widespread.
Interestingly, this disincentivizes niche platforms.
Well, it depends. For widespread non-targeted attacks, like the one mentioned in the parent comment, I think using a niche platform is a form of security through obscurity that can actually work, because it's possible the generic exploit you encounter is not designed to work on your non-standard system (like a virtual machine, a hardened configuration, a non-mainstream OS like OpenBSD...). Although this is more difficult on phones, because it's not possible to use some mainstream services on niche platforms due to attestation requirements.
Older people start defaulting to trust due to the mental burnout induced by having to overthink every situation.
Insurance companies are trying to figure out right now how to cover scam insurance per your age.
There are hard security rules that you should always follow, for example, never click on links from an unknown sender. In the last five years I’ve noticed a trend of bureaucracies in every institution now want you to violate generally accepted security rules for their own convenience.
For example, I got a text from a new number saying (sic) “we’re your dentist office and we’ve changed over to a new system, please click this link and provide some sensitive PII for us ahead of your visit.” Although I had a dentist appointment coming up in a week, I called their office to confirm the appointment, no one over the phone asked me to do anything different, so I ignored the text.
When I got into the office, the receptionist politely told me that I did not fill out the patient forms ahead of my visit, and that I should have received a text message, and now they had to print the forms, which is a problem for them because they’re trying to go paperless. It was a very polite interaction, but the subtext was that I violated an implied contract with their office to engage regularly with them.
As members of the public, we’re asked to click on links from places we don’t recognize, to support the functioning of bureaucracies. Everyone engages in this behavior. I’ve found financial and insurance companies to be the worst offenders.
Regardless, institutions in authoritative positions are opening up massive avenues for social engineering by requiring the general public to ignore security best practices to interact with them. It succeeds in reducing administrative costs from them, but introduces systemic risk that the public is paying for in the form of security breaches.
What?
The lady agreed to install and run an app, because someone asked her to do so.
She literally handed over control of her phone with its bank account accesses, essentially.
Also, that's an Android phone, which might or might not matter, but i imagine this social engineering (as if) scam would work in general.
In the words of Laocoon, "quidquid id est, timeo danaos et dona ferentes" if i remember.
Edit: Has 2FA enabled
No financial apps on the phone.
Only other apps are from big companies with a reputation for strong security practices. That means no sports and weather apps, no restaurant or game apps, no Samsung or Tmobile apps, no TikTok.
Banking and brokerage are all in the browser, on a Chromebook, with no third-party extensions installed. This means no adblock and no other browsing on that user profile.
Most banks and brokerages don't offer FIDO 2FA, they all just want to do SMS. Their hardware tokens are a pain, but they work.
I think it's based on their Knox framework.
Not sure how much security this adds overall but may still be worth considering.
It seems like the creators of this malicious app found a way to break out of the app sandbox [1] and obtain root access. From there getting access to other apps was trivial. Why the Hong Kong bank fraud detection did not block these transactions or freeze the account for suspicious activity is another issue.
I think Google should reach out here and get more information. Perhaps give this woman a lifeline. Something like this shouldn’t be possible.
Especially when a lot of scams go through crypto. I should be able to say "I do not ever buy any cryptocurrency, nor do I do any hand picked random investments, don't let me do anything but pay for stuff at retail stores or online sites in the top 100 largest without app verification".