Reported to Vercel a bank phishing site weeks ago, no response still. It’s amazing how little companies care.
Reported to Vercel a bank phishing site weeks ago, no response still. It’s amazing how little companies care.
But instead of forcing them, we have been letting them drag their feet while while regular people are losing billions to scams.
The whole phone system is ancient and long deprecated. When I get a call from my bank I should see their name and a badge of authentication. Not a random phone number.
Imagine you could register irs.gov and start sending e-mails from that domain. That is pretty much the current state of the phone system.
Un-fucking-believable no one is forcing change here.
They have these services and continue to offer them because they get paid for having them, despite the double decker bus sized hole this provides for scammers.
I agree 100% that there should be much tighter regulation on telcos.
What I'm not sure of is actually whether it's possible without having to rebuild a lot of their networks almost from scratch.
I like to do things in a modular fashion; sectioning off related parts.
The solution is to roll out signing for phone numbers. The owner of each phone number is known. It could even be published in DNS with ENUM. Most phone calls are from big companies like telcos and mobile providers. The VOIP callers would be harder to update, but could be restricted so can't spoof known numbers.
If going to roll out new identity system, easier to use existing phone numbers than make a whole new identifier system.
Anyone with BGP-equivalent access to the phone network can spoof numbers, even if they're coming from a landline. Might even be able to when you have a business landline terminated in a PBX.
i.e. the phone network backend is built on trust.
Do you use it?
I got a call with the caller id of my (credit union) credit card company. They had my name and address, knew I had a card, and were claiming they were investigating fraudulent charges. It sounded more official than my actual credit card company. The only real things to tip me off was that the list of fraudulent charges kept changing, and they were super keen on me reading the entire credit card number back to them.
There were never any fraudulent charges, and the actual fraud department didn't seem to care.
I'm guessing it was due to the Experian leak.
Declaring states that do nothing about these criminals as harboring terror is a good start. This is the same legal principle that resulted in the https://en.wikipedia.org/wiki/Barbary_Wars which stopped Barbary pirates enslaving US sailors.