FBI warns “phantom” hacker scams are emptying financial accounts
tomsguide.com
tomsguide.com
Communication technologies have made the world small and flat, but maybe we need to enlarge it and unflatten it unidirectionally, on the sender's (and scammer's) side. Some people already do this manually on their phones, by refusing to answer calls from random, unknown numbers. Maybe such defense measures should be enabled by default for the public at large, with the option of carefully and partially disabling them, if desired.
Most (all?) protocols conflate the two. But the real world doesn’t speak in phone numbers, ip addresses, and private keys.
Group identities could help though. Let through emails and calls that are signed by a "official medical use" key, or "official federal police use" key. The public keys for those should be publicly available and easily verifiable.
User-level PKI is hard, and trust is shaky. Few well-known signature keys should be much easier. The infrastructure could, of course, be used for whatever other keys you choose to track and trust, e.g. your employer's org, your kid's school, etc. The problem of responsible stewardship remains, but is likely solvable in serious organizations with a dedicated IT department, like a hospital, or a police force.
You're moving closer to a human solution by mapping unstable identifiers (private keys, signatures) to human identifiers.
At the core, humans want to say "ignore everything that isn't from a friend or family member, unless it's an emergency"
Expressing that with technology is hard, especially when people try to solve for identity with technology. Identity is a social construct, it lives outside of cryptographic proof. The systems we build do very little to try and map cryptographic proof back outside the system to identity.
School clubs, hospitals, governments, family, names, friends, etc. are all social constructs. Some social constructs are stronger than others (hospitals and governments have a lot of steps involved in making the social construct!) but they're all still social constructs.
Identity is fiat. There is no way around it.
Spoon boy says it best:
> Do not try to bend the spoon. That is impossible. > Instead, only try to realize the truth. > There is no spoon. > Then you'll see it is not the spoon that bends, it is only yourself
If your kid is lost, tell them to call 911. They'll most likely be able to help more quickly than you will.
I considered your examples to describe two different kinds of scenarios, which might merit different kinds of security measures.
1. Incoming communication from a young child (or a person who is very dependent on you): you'll probably want your phone line to stay fully open. Hopefully in the case of young children, this means that their parents are relatively young and will have grown up with skepticism toward incoming communication from strangers.
2. Incoming communication about a younger, adult relative. Maybe for many people, such communication could bear the introduction of a bit of slowness by security measures. Probably in most cases, there's little that the older relative can do for the younger, temporarily incommunicado relative. They might not need to get a message about them right away. In many cases, the message will be bad news anyway, something that the older parent can do nothing about. Such bad news can probably wait a few hours, even a day or two to be delivered, and it's not too bad for the older relative to be none the wiser for a bit, if such temporary impotence protects them from the increasingly present threat of serious, life-altering scams.
As with all security measures, there's a tradeoff between convenience/immediacy/cost and security. It will likely be hard to design reliable, secure, and accessible emergency communication protocols, but I hope (and optimistically suspect) that it's indeed possible. Attempting to design such protocols is a worthy endeavor for us to undertake, given how many of our loved ones are increasingly vulnerable to randos who have no business getting to their front door so easily.
That right there will be a deal breaker to many.
Your kid gets hit on their bike across town. Maybe you'll find out two days later?!
Or someone has hours left to live, and you're not trying to do anything at all - just be by their side.
Organ donation? High risk operations?
These questions can't wait days.
For many people, the tradeoff--even if in the order of minutes or an hour or two--will be unacceptable and they'll prefer to leave their incoming communication channels completely open and unsecured. However, others people may decide that a small tradeoff is worth it, when weighing their own vulnerability to destructive scams vs. a much lower probability of needing to help a loved one with the catastrophic examples you mentioned. This latter group should not be considered by society to be heartless. Though nobody dies right away when they lose their life savings to a scam, they may very well end up dying or ending up with a very miserable life as a result of that scam. They should not be blamed for reasonably protecting themselves (AND their loved ones, who'd also be affected indirectly by that scam.)
1) Either your identity is blocked or your identity must be validated when it comes up on the phone.
Problem solved.
Phone companies know when they are selling to scammers and spammers. Hold them liable for fraud when companies are making misrepresentations.
2) "Identity theft" should be a verboten term and it should be called "financial fraud" and the banks that enable it held liable
Holding the banks liable for financial scams would cause the banks to identify things properly and spend the appropriate amount of money to stop them.
There are other ways in which banks tend to make losing money way too easily. I should be able to lock down an account or a given sum of money in an account that would prevent that money from being transferred anywhere unless I first show up at a bank office, am properly identified, and remove that lock. Ideally bank officers would be forced to ask me a few basic questions that could help me realize that I may be falling for a scam. They could also inform me of the most common and newest forms of scams before finalizing the account unlocking process. If I so choose, I want to be able to NOT have the option of being to clear out my accounts through online banking sessions.
On a different note, why are bank and credit card account statements so nearly useless in identifying where one's money is transferred? It's high time to upgrade ancient banking networks! Banks should expand the amount of space available for describing each transaction, along with providing the recipient's account number, financial institution name and ID , state/province and country. As it is, I often have trouble identifying many legitimate purchases I made, much less potentially fraudulent transactions.
If this were a common and popular protocol, it'd be easy to generate per-service-and-per-account keys, provide them to a service, and set them up for whitelisting in your email client/service.
I enabled iOS “silence unknown callers” option as soon as they added it, but found I miss important calls sometimes. I rely on voicemail for those. There’s no way to completely whitelist your personal communications in this world.
I do get scam voicemails and emails sometimes, but am good at detecting them.
My 90 year old mother gets less and less able to think clearly each passing month. She always is calling me telling me that "her computer is completely dead" and it takes my 10 minutes to realize it's just her mouse that's not working becasue she forgot to charge it.
No amount of education will save her. Fortunately, she has no on-line bank or credit card accounts.
Actually, they often start when a user gotes to a malicious webset that tells him his computer is "infected" and to call a number.
These websites purport to have found a "virus" on your computer and you should call tech support. My 90 year old mother, fortunately, panics when she sees them and calls me. As she gets more and more confused, she may someday call the number. (Another fortuante thing -- she does NO online banking!)
And these pages are very common--and on legitimate domains! If your local plumber or hair salon doesn't keep its wordpress website up to date, you can visit their site and see one of these fake warning pages.
Not every user needs to be able to go to any corner of the web on a whim. Maybe my elderly future self needs to have less freedom of inquiry, as much as it pains to think of that likely future.
Nope. Through an expired domain of a once-legit site that was taken over, or through a mom-and-pop legit business that had their website taken over because of a wordpress bug. My brother mentioned to me the other day that he got to a "computer has been infected -- call this number" website from clicking on a Facebook ad!
This works because it breaks the economics of spam. If one in a million people fall for your $1000 scam, that’s a profit of $0.001/email. Thats ok if emails cost nothing to send. But if they cost $0.01 to send, it doesn’t make sense to send them.
It blows my mind.
People need to be able to open PDF documents, but unless there's a prior professional or personal relationship, or a stable and identifiable corporate entity involved, it's a bad idea. That obviously doesn't apply to PDFs you go out and find from sources you trust.
In the case I'm referring to, the solution is to have a standard application process, usually involving a nominal fee. That adds intermediaries, as well as some standardization for fairness sake.
Application fees can be substantial barriers to some people. The academia is international, and international payments are often difficult outside the trivial cases. For example, there are plenty of Iranian grad students around the world, but sanctions make many things difficult for them.
A standard application window, placing submitted materials in a cloud provider's infra (e.g., Google Drive), viewing materials with sandboxed web browsers rather than acrobat - these should be standard and well known methods. The poor hygiene of just getting sent documents by strangers and opening them needs to stop.
Is it convenient? No. Tough luck, it's 2023 and this is a well known vector for infection.
In some places, if you want to do a PhD, you apply to a school. If admitted, you take classes, do rotations in different labs, and pick a supervisor. In other places, you first have to find someone willing to supervise you, and maybe also secure funding. Once you have a supervisor and funding, the application process is just a formality that can be done at any time.
Reviewing candidates is the same in the academia and elsewhere. Maybe someone in your professional network already knows the candidate (the world is pretty small, after all), or maybe they already have experience and achievements to show. If there is nothing that makes them stand out, they probably wouldn't make it through the process anyway.
Also, it's easier to fix the technical issues with PDF than to get the academia to standardize on anything. Maybe create a safe subset without all the unnecessary features you would not expect in a printed document, and call it PDF. And then rename the full PDF to something appropriate, like "This will devour your soul and steal your children".
They then convinced her that they had "deposited" the money into her account by mistake. She could clearly see the extra money in her main account and so believed them. The person pleaded with her to return the money via transfer, and keep it secret, or he would lose his job.
Being a good person, she wanted to help him and not cause a problem.
Fortunately, the teller at the bank recognized it as a scam, but it was a close call.
She’s not a stupid person; has a masters degree and writes children’s books.
Kitboga, Harvey Denttt, Scam Sandwich and numerous other youtubers seek out these scammers and use virtual machines, elderly voice filters and other special effects to lead them on, sometimes for hours. It’s very satisfying.
I am just happy my mother fell into the pattern of messaging me instantly when she has an even slight suspicion. Had a few false positives, but overall i am very happy with how well this approach has been working out for her. Saved a ton of trouble down the road for both of us.
In low trust societies (both developed & developing) this is largely mitigated with family clans, where multiple generations of a family are living under the same roof. The problem in many developed high trust societies is that families have weaker links and adult children rarely live with their elderly parents. Maybe this will change in high trust societies if real estate continues to be unaffordable for most Millennials?
All it takes is one browser 0-day that gets distributed on an ad network. A large segment of the HN crowd is still executing untrusted JS on their computers and opposed to blocking their source of income.
At least back in the day when Flash was still a thing, it was a common issue for "enterprising" people to buy advertising slots, even on reputable media, and spread all kinds of malware via them.
Also, 0-days are generally hard to come by in browsers these days, the libwebp one was initially developed by NSO for example; and tech support scams are not that profitable.
It's too simple. People don't know who's trustworthy. And I don't make house calls hundreds of miles away.
Business opportunity for a "Local Trustworthy Techs"? Heck, the Goon Guys will search your drive for illicit material, and if they don't find any, they'll install some (If I recall some horror stories correctly).
Hopefully they uninstalled the software once the printer was working.
They are getting more and more creative.
More recently in the US I got a call where the other side didn't say anything and hung up after exactly one minute. Suspicious indeed.
[1] https://paxful.com/sell-bitcoin/with-any-payment-method/?pay...