There are hard security rules that you should always follow, for example, never click on links from an unknown sender. In the last five years I’ve noticed a trend of bureaucracies in every institution now want you to violate generally accepted security rules for their own convenience.
For example, I got a text from a new number saying (sic) “we’re your dentist office and we’ve changed over to a new system, please click this link and provide some sensitive PII for us ahead of your visit.” Although I had a dentist appointment coming up in a week, I called their office to confirm the appointment, no one over the phone asked me to do anything different, so I ignored the text.
When I got into the office, the receptionist politely told me that I did not fill out the patient forms ahead of my visit, and that I should have received a text message, and now they had to print the forms, which is a problem for them because they’re trying to go paperless. It was a very polite interaction, but the subtext was that I violated an implied contract with their office to engage regularly with them.
As members of the public, we’re asked to click on links from places we don’t recognize, to support the functioning of bureaucracies. Everyone engages in this behavior. I’ve found financial and insurance companies to be the worst offenders.
Regardless, institutions in authoritative positions are opening up massive avenues for social engineering by requiring the general public to ignore security best practices to interact with them. It succeeds in reducing administrative costs from them, but introduces systemic risk that the public is paying for in the form of security breaches.
Older people start defaulting to trust due to the mental burnout induced by having to overthink every situation.
Insurance companies are trying to figure out right now how to cover scam insurance per your age.
What?
The lady agreed to install and run an app, because someone asked her to do so.
She literally handed over control of her phone with its bank account accesses, essentially.
Also, that's an Android phone, which might or might not matter, but i imagine this social engineering (as if) scam would work in general.
In the words of Laocoon, "quidquid id est, timeo danaos et dona ferentes" if i remember.
Fortunately, the solution of just sticking to mainstream platforms works. If I’m on a Mac with an iPhone, anything that hits me hits half of Americans. I’ll be in a nice big class-action once the damages are widespread.
Interestingly, this disincentivizes niche platforms.
Well, it depends. For widespread non-targeted attacks, like the one mentioned in the parent comment, I think using a niche platform is a form of security through obscurity that can actually work, because it's possible the generic exploit you encounter is not designed to work on your non-standard system (like a virtual machine, a hardened configuration, a non-mainstream OS like OpenBSD...). Although this is more difficult on phones, because it's not possible to use some mainstream services on niche platforms due to attestation requirements.