this post was submitted on 15 Mar 2024
209 points (97.3% liked)

Technology

59312 readers
5268 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

I was tricked by a phone-phisher pretending to be from my bank, and he convinced me to hand over my credit-card number, then did $8,000+ worth of fraud with it before I figured out what happened.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 26 points 8 months ago (14 children)

The real answer here is to have decent digital ID as 2-factor authentication.

This scam would be practically impossible in Sweden with BankID for example.

[–] [email protected] 28 points 8 months ago (2 children)

Adding multiple factors to authentication just adds another step to the scam, it doesn't make it impossible by any means.

[–] [email protected] 20 points 8 months ago (2 children)

For BankID it somewhat does, because only registered services can make the request - so they'd need to register a scam service and then use that. Which also makes it an easier job for anti-fraud police.

So it'd be a lot more complicated.

Like obviously at a certain point if someone is willing to do everything they can - then they will be scammed, see this for example: https://www.bbc.com/news/uk-england-leeds-67208755

But the more steps there are, the higher the chance the person realises it is a scam.

[–] [email protected] 8 points 8 months ago* (last edited 8 months ago) (1 children)

For BankID it somewhat does, because only registered services can make the request

I'm not an expert on digital banking, but this sounds like a no-brainer... Aside from marginally increasing compliance costs, why would this not just be the norm everywhere?

I mean... It was rhetorical. I know why.

[–] [email protected] 7 points 8 months ago

It kind of is the norm.

Just a few countries like the US are really backward in terms of accessible banking - mainly due to having no federal ID, residence registration, etc. too on top of outdated bureaucracy.

[–] [email protected] 4 points 8 months ago

"A chain is only as strong as its weakest link" - We are the weakest link in any security chain, and always will be. Social engineering is one hell of a drug.

[–] [email protected] 11 points 8 months ago

It doesn’t matter how many locks you have if you give the scammers the keys. And so many people give up the keys

load more comments (11 replies)