Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You use a mobile phone, another line, or walk to the bank. Other than that one must ask himself, what type of crime? Why does my bank's website show none of it? Is it related to any of my cards missing? Why is the bank contacting me and not the card issuer (VISA, etc)?

I must guess this kind of primitive social engineering can work around 1 out of 100 cases and still be practical. As far as I've seen though the real treat is phishing. Really easy to set up and for most people it works.

Just the other day I was playing around an unprotected server of a phisher that had just sent me an email and there was plenty of people that had fallen for their trick. It could be seen on a text file were they were lousily saving all these details. Scary stuff.

Two factor authentication and even one-time cards (some banks issue this) can protect from this; but as always people that worry about security are already secure. It's the unaware that will fall for the trick.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: