I swear, the proliferation of random ".xyz" type gTLD is not making things any easier in stopping non tech people from clicking on phishing links. There's so damn many of them. Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose...
I remember receiving a genuine "verify your account" email from PayPal way back. The phishers didn't make it up, they were just copying actual emails PayPal sent their own users.
In a recent example my step-mother, who is constantly getting cloud storage full scam emails, received an email from Google about 75% full storage that appears to be fully valid. However all the links use a domain c.gle and whois c.gle errors with "getaddrinfo(whois.nic.gle): Name or service not known". whois gle however does work. I was not sure of the validity of c.gle myself, my step-mother would have no idea.
There is a similar issue with the IRS. If you call the IRS they use a text-to-speech system to generate the voice for their call tree IVR. The problem is, it's a commercially available system that fake call center scammers also use, so they sound identical. It also doesn't help that it sounds fake and scammy, so you can't use that as a signal to avoid the number you're calling, either
This shit drives me insane. Last year I had my home insurer send me a link in an SMS pointing me to allstate.yem.bo to collect some information. Stop training your users to get phished!!
It reminds me how at work we had to take a course hosted on our domain about how to recognize phishing and a few days later we got an e-mail from outside our domain saying we had to take a course about a different subject on their domain. We got an email from management a week or so later that complained that so few people had completed the new training -- because we all assumed it was a phishing attempt because it was exactly the sort of thing the phishing course talked about!
Every official permissions block and exemption request popup our company's enterprise ops manages appears indistinguishable from malware. It's almost impressive.
This is so weird, seeing this. Two years ago, I got a customs notice from FedEx asking to fill in my details. That was just a plain email from __some guy__ at FedEx with a PDF file attached. I wasn't expecting any package.
I wrote to their chatbot (of course, no human assistance) and after some time of "prompt engineering," or what one might call coercing, it finally directed me to a human consultant who confirmed it was indeed not a scam, and that it was indeed their messaging.
I opened the PDF, and it was pre-filled with someone else's data, with blank rectangles placed over fields in a bad attempt at redacting them (you could just move those rectangles around to reveal the underlying data).
The package later turned out to be a surprise from collaborators abroad. Years later, I still feel that scam aftertaste whenever I see the FedEx logo.
If I had a nickel for every post I saw on HN front page involving companies confusing people on phishing-like patterns today, I would have two nickels. Which is not a lot but still weird that it happened twice.
I wonder how we could describe this so that aging non-technical executives understand.
"It's like your real salesperson showed up in a wrinkled suit smelling of booze, telling me that your product could be seen in the back of an anonymous white van... But only if I first proved I was carrying the asking-price in the form of gift-cards."
I would simplify the message a bunch, things like capitalization and even the currency issue, detract from the core issue.
"There are technologies and protocols from the early 2000s that need to be followed to ensure that a a message comes from your company, they are not being followed so messages requesting payment are indistinguishable from impersonators.
The protocols are called DNS and HTTPS, the cost to implement for the country in question would be in the 5 digits range, the benefits would be massively detracting scammers from targetting your company to impersonate and thus harm your brand."
I don't think metaphors help, non technical people, especially executives, can handle minimal technical details.
When I lived in Sunnyvale, CA, I got text that said "Renew your alarm license online at my-alarm-license-renew.info"
You do need a residential alarm license in Sunnyvale, but I was sure this was a scam. I called the city. It was the real address, and they were mystified as to why I'd call them. (I sent in a check to avoid the $1.50 processing fee, but that was before 50% of checks get stolen in the mail.)
I keep getting this message and it might be legit, but I have no idea:
> BlueShieldCA: ANON, you have an important benefits message in your health feed. blueshieldca.customerfeed.com/a/abcd12345 Txt help/stop Msg&DataRatesApply
If I login to BSCA, their messaging section shows nothing. But some threads on the internet make “customerfeed” seem like a real service.
It really doesn't help that after the acquisition of TNT couriers, some bright spark decided to call the Australian arm of FedEx "FedEx Express". That's right, "Federal Express Express".
It's moronic that these big companies can't get their shit together and provide nice links like this:
Twenty or so years ago I ordered wheels and tires from tire rack dot com and as I was in college had them delivered to my parents house. The FedEx driver proceeded to roll them down the driveway and into my parents siding scraping up my new wheels and causing about 20k in damage to the siding.
The French Post is also living in the 90s. They send SMSs that look like a scam ("your package something, click here"), the link is on a wild domain completely unrelated to anything close to a post office service, and then the content of the page screams Nigerian fraud.
But it is real. I wondered one day how many people opening it fall into the category
- this is normal and expected, it is France
- this is a scam, let's see how it was done
- this is obviously from the post office and I would do the same if I was scammed
I virtually never click anything texted to me (other than personal stuff from friends and family). If a bank or a shipping company texts me, I go to their website and look up the information myself.
Like the author of this post, I also have a better than average eye for spotting scams, but it’s foolish to assume you’ll be right 100% of the time.
26 comments
[ 0.25 ms ] story [ 28.6 ms ] threadList of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt
I wrote to their chatbot (of course, no human assistance) and after some time of "prompt engineering," or what one might call coercing, it finally directed me to a human consultant who confirmed it was indeed not a scam, and that it was indeed their messaging.
I opened the PDF, and it was pre-filled with someone else's data, with blank rectangles placed over fields in a bad attempt at redacting them (you could just move those rectangles around to reveal the underlying data).
The package later turned out to be a surprise from collaborators abroad. Years later, I still feel that scam aftertaste whenever I see the FedEx logo.
https://news.ycombinator.com/item?id=49172834
You should be more respectful, you’ve clearly received a Message direct from President Trump!
Australia has mandatory identity verification for getting a SIM card.
The FCC is now proposing [1] to add a rule to require government ID, physical address, and alternative phone number for every phone line in the US.
KYC for phone lines would cause more IDs to be leaked, and more American dollars lost to scammers and fraudsters.
[1] https://www.404media.co/fcc-wants-to-kill-burner-phones-by-f...
Discussion:
https://news.ycombinator.com/item?id=48462308
My first suspicion would be that they’re getting hold of the Fedex invoice data, via a software compromise or an insider.
If it really is real, then wow, FedEx Australia sounds like it’s one guy operating out of a shipping container down at the docks.
Despite trying to tell people not to trust unknown callers.
"It's like your real salesperson showed up in a wrinkled suit smelling of booze, telling me that your product could be seen in the back of an anonymous white van... But only if I first proved I was carrying the asking-price in the form of gift-cards."
"There are technologies and protocols from the early 2000s that need to be followed to ensure that a a message comes from your company, they are not being followed so messages requesting payment are indistinguishable from impersonators.
The protocols are called DNS and HTTPS, the cost to implement for the country in question would be in the 5 digits range, the benefits would be massively detracting scammers from targetting your company to impersonate and thus harm your brand."
I don't think metaphors help, non technical people, especially executives, can handle minimal technical details.
You do need a residential alarm license in Sunnyvale, but I was sure this was a scam. I called the city. It was the real address, and they were mystified as to why I'd call them. (I sent in a check to avoid the $1.50 processing fee, but that was before 50% of checks get stolen in the mail.)
> BlueShieldCA: ANON, you have an important benefits message in your health feed. blueshieldca.customerfeed.com/a/abcd12345 Txt help/stop Msg&DataRatesApply
If I login to BSCA, their messaging section shows nothing. But some threads on the internet make “customerfeed” seem like a real service.
It's moronic that these big companies can't get their shit together and provide nice links like this:
https://fedex.au/duty/abc123
which could have an explainer landing page before prompting you to visit the grotesque original link.
They seem to have improved so much in that time.
(╯°□°)╯︵ ┻━┻
But it is real. I wondered one day how many people opening it fall into the category
- this is normal and expected, it is France
- this is a scam, let's see how it was done
- this is obviously from the post office and I would do the same if I was scammed
Like the author of this post, I also have a better than average eye for spotting scams, but it’s foolish to assume you’ll be right 100% of the time.