Daily Shaarli

All links of one day in a single page.

November 22, 2021

When in Doubt: Hang Up, Look Up, & Call Back – Krebs on Security

Many security-conscious people probably think they’d never fall for a phone-based phishing scam. But if your response to such a scam involves anything other than hanging up and calling back the entity that claims to be calling, you may be in for a rude awakening. //

Mitch’s bank managed to reverse the unauthorized wire transfer before it could complete, and they’ve since put all the stolen funds back into his account and issued a new card. But he said he still feels like a chump for not observing the golden rule: If someone calls saying they’re from your bank, just hang up and call them back — ideally using a phone number that came from the bank’s Web site or from the back of your payment card. As it happened, Mitch only followed half of that advice.

Kyle Rittenhouse's Surprising Comments to Tucker Carlson – RedState

Kyle Rittenhouse: "This case has nothing to do with race."

Watch our exclusive interview, tomorrow at 8pm ET on @FoxNews pic.twitter.com/vXLEVtfycc

— Tucker Carlson (@TuckerCarlson) November 22, 2021 //

Tucker Carlson
@TuckerCarlson
"It wasn't Kyle Rittenhouse on trial in Wisconsin. It was the right to self-defense on trial."

Tonight at 8pm ET on @FoxNews

11:10 AM · Nov 22, 2021

Farewell to a Giant | airspacemag.com | Air & Space Magazine

Today, twin-engine airliners routinely fly routes that were once reserved for the jumbos, and those routes take them from one so-called “feeder” airport to another—“point-to-point” flights—bypassing the congested hubs, shortening travel time for passengers, saving money for the airlines, and—increasingly importantly to regulators and the flying public—reducing carbon emissions. Moreover, those smaller airliners are easier to fill with paying customers than the enormous A380. When the giant flew with only 70 percent of its seats occupied, it cost almost the same to operate as a full flight did.

Foreseeing the shift in the air travel industry, Boeing lost faith in the market for a superjumbo and in 1995 withdrew from discussions it had been having with Airbus about a partnership to produce a mega-airliner. Boeing eventually turned to the much smaller but enormously successful 787. Airbus continued alone.

Frank Vermeire defends the decision. “Every 15 years traffic doubles,” he says. “The problem is the biggest growth is at the major global hubs—London, Los Angeles, Paris, Hong Kong, Singapore—which were already getting more and more congested. They were also unable to expand, so the only way to grow was to have larger aircraft delivering more people with each flight. The question was how to use the existing infrastructure more efficiently, and the only way to do that was with larger aircraft.”

Vermeire believes that, no matter how many hub-bypass routes there are, the mega-hubs still need the A380.

Simple Banking Security Tip: Verbal Passwords – Krebs on Security

There was a time when I was content to let my bank authenticate me over the phone by asking for some personal identifiers (SSN/DOB) that are broadly for sale in the cybercrime underground. At some point, however, I decided this wasn’t acceptable for institutions that held significant chunks of our money, and I began taking our business away from those that wouldn’t let me add a simple verbal passphrase that needed to be uttered before any account details could be discussed over the phone.

Most financial institutions will let customers add verbal passwords or personal identification numbers (PINs) that are separate from any other PIN or online banking password you might use, although few will advertise this.

Even so, many institutions don’t properly train their customer support staff (or have high turnover in that department). This can allow clever and insistent crooks to coax customer service reps into validating the call with just the SSN and/or date of birth, or requiring the correct answers to so-called knowledge-based authentication (KBA) questions. //

A few years ago, I began testing financial institutions that held our personal assets. I was pleasantly surprised to discover that most of them were happy to add a PIN or pass phrase to the account. But many of the customer service personnel at those institutions failed in their responses when I called in and said I didn’t remember the phrase and was there any other way they could verify that I was me?

Ultimately, I ended up moving our investments to an institution that consistently adhered to my requirements. Namely, that failing to provide the pass phrase required an in-person visit to a bank branch to continue the transaction, at which time ID would be requested. Their customer service folks consistently asked the right questions, and weren’t interested in being much helpful otherwise (I’m not going to name the institution for obvious reasons).

Not sure whether your financial institution supports verbal passwords? Ask them. If they agree to set one up for you, take a moment or two over the next few days to call in and see if you can get the customer service folks at that institution to talk about your account without hearing that password. //

Even if your institution offers voice biometrics, adding a verbal password/passphrase is still a good idea.

Get Into Nuclear Energy | US, Canada, Australia, United Kingdom

We provide you with everything you need to get into nuclear...

Whether you're a business looking to win work, someone looking for a job, an influencer wanting to focus on nuclear, a non-profit organisation, a recruiter wanting to specialise in nuclear or a training provider waiting to deliver skills workshops...

Whatever it is, we can help you Get Into Nuclear.

One of Only Two Surviving 1934 Auburn 652X Broughhams Now on Display in Indiana

One of Only Two Surviving 1934 Auburn 652X Broughams Now on Display in Indiana

While you're there, don't miss the other 140 or so vintage cars in a restored Art Deco building that used to be Auburn Automobile's showroom. //

Nearly 90 years later, only two remain. Now, one of those extremely rare vehicles will now be on display at the Auburn Cord Duesenberg Automobile Museum in Auburn, Indiana after a donation from a couple in Baltimore, Maryland. //

In 1934, Donald Duck was introduced to the world as Mickey Mouse’s comedic sidekick and the Auburn Company was still in business designing gorgeous pre-World War II builds. Long before Toyota made the bZ4X and BMW launched the X5 xDrive 45e, Auburn was all in on using numbers as names and they weren’t any less confusing: in 1934, the company was making the 850X and 850Y with a powerful straight eight under the massive hood and the 652X and 652 Y with an inline six. The X and Y referred to the trim.

The ‘Zelle Fraud’ Scam: How it Works, How to Fight Back – Krebs on Security

One of the more common ways cybercriminals cash out access to bank accounts involves draining the victim’s funds via Zelle, a “peer-to-peer” (P2P) payment service used by many financial institutions that allows customers to quickly send cash to friends and family. Naturally, a great deal of phishing schemes that precede these bank account takeovers begin with a spoofed text message from the target’s bank warning about a suspicious Zelle transfer. What follows is a deep dive into how this increasingly clever Zelle fraud scam typically works, and what victims can do about it.

Last week’s story warned that scammers are blasting out text messages about suspicious bank transfers as a pretext for immediately calling and scamming anyone who responds via text.

Anyone who responds “yes,” “no” or at all will very soon after receive a phone call from a scammer pretending to be from the financial institution’s fraud department. The caller’s number will be spoofed so that it appears to be coming from the victim’s bank.

To “verify the identity” of the customer, the fraudster asks for their online banking username, and then tells the customer to read back a passcode sent via text or email. In reality, the fraudster initiates a transaction — such as the “forgot password” feature on the financial institution’s site — which is what generates the authentication passcode delivered to the member.

Ken Otsuka is a senior risk consultant at CUNA Mutual Group, an insurance company that provides financial services to credit unions. Otsuka said a phone fraudster typically will say something like, “Before I get into the details, I need to verify that I’m speaking to the right person. What’s your username?”

“In the background, they’re using the username with the forgot password feature, and that’s going to generate one of these two-factor authentication passcodes,” Otsuka said. “Then the fraudster will say, ‘I’m going to send you the password and you’re going to read it back to me over the phone.'”

The fraudster then uses the code to complete the password reset process, and then changes the victim’s online banking password. The fraudster then uses Zelle to transfer the victim’s funds to others.

An important aspect of this scam is that the fraudsters never even need to know or phish the victim’s password. By sharing their username and reading back the one-time code sent to them via email, the victim is allowing the fraudster to reset their online banking password. //

“Consumers — many who never ever realized they had a Zelle account – then call their banks, expecting they’ll be covered by credit-card-like protections, only to face disappointment and in some cases, financial ruin,” Sullivan wrote in a recent Substack post. “Consumers who suffer unauthorized transactions are entitled to Regulation E protection, and banks are required to refund the stolen money. This isn’t a controversial opinion, and it was recently affirmed by the CFPB here. If you are reading this story and fighting with your bank, start by providing that link to the financial institution.”

“If a criminal initiates a Zelle transfer — even if the criminal manipulates a victim into sharing login credentials — that fraud is covered by Regulation E, and banks should restore the stolen funds,” Sullivan said. “If a consumer initiates the transfer under false pretenses, the case for redress is more weak.” //

Anyone interested in letting the CFPB know about a fraud scam that abused a P2P payment platform like Zelle, Cashapp, or Venmo, for example, should send an email describing the incident to BigTechPaymentsInquiry@cfpb.gov. Be sure to include Docket No. CFPB-2021-0017 in the subject line of the message.

In the meantime, remember the mantra: Hang up, Look Up, and Call Back. If you receive a call from someone warning about fraud, hang up. If you believe the call might be legitimate, look up the number of the organization supposedly calling you, and call them back.