I really wish someone would make movies or enticing thriller series out of these post-mortems. There are some good stories to be told, plus it would help the most vulnerable to be better prepared..
I really wish someone would make movies or enticing thriller series out of these post-mortems. There are some good stories to be told, plus it would help the most vulnerable to be better prepared..
I really hate any system that relies on the telecom system for any sort of verification. I hate every website/app/whatever that doesn't let you disable SMS verification as a "backup". So many places that offer (and even force) 2FA just let you bypass your authenticator with SMS verification.
It's utterly ineffective to the scale of attack.
The system will die, if not from the abuse than from rejection by individuals, businesses, and organisations. And I suspect we'll never again have a single universally-accessible voice comms system again.
Email has similarly been slowly dying for similar reasons.
(The answer in my experience is: you can’t, and next, nobody knows what the different attestation levels mean, and many legit calls still come in without any attestation)
It’s like if browsers only told you that https was enabled after you POSTed your credit card number to the remote site.
https://ficom.fi/news/combatting-scam-calls-and-smss-how-fin...
The targeted old people still watch TV, and * hearing* the actual fraudulent pitches will be far more educational than reading about it.