Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Apparently, the following Verizon SMS text[1] Cody Brown got was genuine:

>Free VZQ Msg: You're on the phone with Verizon and just authenticated with an alternative method. Not you? Please call us at 800-922-0204 immediately.

And one of CB's followup recommendations is:

>Make urgent text alerts actionable through SMS. If I received the original alert and was able to text a reply stopping it, or even delaying it, this entire hack would have stopped in its tracks. Instead I was told to ‘immediately’ call a number for Verizon that no one was there to answer.

It seems inevitable that the Verizon SMS alert as a bonafide safety check would embolden social engineers to use that very same method to trick people into calling their own 800-555-2222. Then, a fake Verizon customer service agent "phishes" for even more sensitive identification data by asking official-sounding questions in the guise of "verifying the account".

The tone of that Verizon SMS is panic-inducing and it's very easy for people to not realize they need to verify that the 800-922-0204 is actually a legitimate Verizon phone#. Even if non-techies take the extra step of googling "800-922-0204", they may get conflicting information and get confused on whether it's safe to call back: e.g. http://stopthecap.com/2015/10/05/got-a-call-from-1-800-922-0...

EDIT ADD: I think it's very challenging to come up with a generalized decision tree for non-techies (e.g. your 75-year old grandmother) to follow such that they know they are "really really REALLY talking to Verizon".

If the techie-grandson thinks they can simply the decision matrix by instructing his grandmother to simply get a hold of him when she receives such an alert, then in the 15 minutes plus it takes the grandson to research the legitimacy of the SMS, the grandmother's life savings in the bank account is drained. In that scenario, the alert was legitimate. The extra delay introduced by the grandson made the situation worse.

In substituting in-person transactions that require biometric verification (e.g. thumbprint at the bank counter) with non-physical "information verifying other information over information channels to unlock access", it creates new vectors of social engineering attacks. It's a very hard safety problem to solve for the mass population.

[1] https://cdn-images-1.medium.com/max/800/1*TJo_9dnPNqJC0eecYp...



Fortunately, the banks are on Grandma's side on this one. Unlike Bitcoin, banks will not let someone who obtains a few credentials simply transfer an arbitrary amount of money to anywhere in the world in seconds. Banks seems to have many layers of checking for potentially suspicious activity, and ways to reverse transactions that are later proven to be fraudulent.

Bitcoin has some interesting properties, but holding bitcoins directly is definitely not right for anyone who can't be trusted to keep their critical credentials secure no matter what.


"Banks seems to have many layers of checking for potentially suspicious activity,..."

I don’t think so. I had this kind of incident and nobody from bank noticed it (60 euro paid over night 3:35 AM from central europe to fake company somwhere in tax paradise, summer 2014). If i asked why and how it was possible, they replied with formal letter how much sorry they are. Nothing more.

I was in touch with ViSA guys and they confirmed payment as fraud and returned my money back to me.

Around 10 years ago i was in national bank. We had small project for entrance gateway automation. Control unit was strange DIY solution.

Banks aren’t so secure as we think. At least in my country.

I worked for big oil company and even their infrastructure and solutions are far from ideal. So i don’t have false expectations about security.


I'm talking about bank transfers, not debit cards. Try and transfer $50k to another account and see how many steps you have to go through, presuming it's a individual account and not a business. And then see how long it takes to actually go through, and how many times they call you to make sure you are really trying to do that before it goes through.


60 euro is not a lot of money, relatively speaking.


I think there's a 3-digit code (611?) that direct dials whoever your service provider is.

As long as that's secure, I think that's the solution to knowing who you are talking to.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: