{"id":12265,"date":"2019-10-09T14:02:07","date_gmt":"2019-10-09T18:02:07","guid":{"rendered":"https:\/\/www.duck9.com\/?p=12265"},"modified":"2019-10-09T14:26:43","modified_gmt":"2019-10-09T18:26:43","slug":"phishing-is-when-people-fish-for-your-pin","status":"publish","type":"post","link":"https:\/\/www.duck9.com\/blog\/phishing-is-when-people-fish-for-your-pin\/","title":{"rendered":"Phishing is When People Fish For Your PIN"},"content":{"rendered":"<div>\n<div dir=\"ltr\">\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal\"><span style=\"direction: ltr; unicode-bidi: embed; background-color: rgba(255, 255, 255, 0)\">By Larry Chiang<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal\"><span style=\"direction: ltr; unicode-bidi: embed; background-color: rgba(255, 255, 255, 0)\"><br \/>\n<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal\"><span style=\"direction: ltr; unicode-bidi: embed; background-color: rgba(255, 255, 255, 0)\">Phishing.&nbsp;<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal; min-height: 13.8px\"><span style=\"background-color: rgba(255, 255, 255, 0)\"><br \/>\n<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal\"><span style=\"background-color: rgba(255, 255, 255, 0)\">1\/ Social engineering<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal\"><span style=\"background-color: rgba(255, 255, 255, 0)\"><br \/>\n<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal\"><span style=\"background-color: rgba(255, 255, 255, 0)\">Building trust by asking questions they know the answers to.&nbsp;<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal\"><span style=\"background-color: rgba(255, 255, 255, 0)\"><br \/>\n<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal\"><span style=\"background-color: rgba(255, 255, 255, 0)\">2\/ attack surface is anything with emotion<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal\"><span style=\"background-color: rgba(255, 255, 255, 0)\"><br \/>\n<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal\"><span style=\"background-color: rgba(255, 255, 255, 0)\">Humans.&nbsp;<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal\"><span style=\"background-color: rgba(255, 255, 255, 0)\"><br \/>\n<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal\"><span style=\"background-color: rgba(255, 255, 255, 0)\">3\/ texts can be spoofed<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal\"><span style=\"background-color: rgba(255, 255, 255, 0)\"><br \/>\n<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal\"><span style=\"background-color: rgba(255, 255, 255, 0)\">Texts and emails can be spoofed<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal; min-height: 13.8px\"><span style=\"background-color: rgba(255, 255, 255, 0)\"><br \/>\n<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal\"><span style=\"background-color: rgba(255, 255, 255, 0)\">Any asset touching the Internet that\u2019s accessible by \u201cPIN\u201d is in jeopardy.&nbsp;<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal\"><span style=\"background-color: rgba(255, 255, 255, 0)\"><br \/>\n<\/span><\/p>\n<p style=\"margin: 0px; font-stretch: normal; line-height: normal\"><span style=\"background-color: rgba(255, 255, 255, 0)\">Read Pieter Gunst\u2019s tweet and comment what your thoughts are<\/span><\/p>\n<table style=\"border: 1px solid black; padding: 8px\">\n<tbody>\n<tr valign=\"bottom\">\n<td width=\"48\"><span style=\"background-color: rgba(255, 255, 255, 0)\"><img decoding=\"async\" src=\"https:\/\/pbs.twimg.com\/profile_images\/662345762534113280\/FVk7uaEB_normal.jpg\" style=\"width: 48px; height: 48px; padding-right: 8px\"><\/span><\/td>\n<td><b style=\"background-color: rgba(255, 255, 255, 0)\">Pieter Gunst (<a href=\"https:\/\/twitter.com\/digitallawyer?s=11\">@DigitalLawyer<\/a>)<\/b><\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\">\n<div><a href=\"https:\/\/twitter.com\/digitallawyer\/status\/1181348689756864513?s=11\" style=\"caret-color: rgb(0, 0, 0); background-color: rgba(255, 255, 255, 0)\"><font color=\"#000000\">10\/7\/19, 4:20 PM<\/font><\/a><\/div>\n<div><span style=\"background-color: rgba(255, 255, 255, 0)\">Oooof. Was just subjected to the most credible phishing attempt I&#8217;ve experienced to date. Here were the steps:<\/p>\n<div>\n<div>\n<div>\n<div>\n<div>\n<p>1) &#8220;Hi, this is your bank. There was an attempt to use your card in Miami, Florida. Was this you?&#8221;<\/p>\n<p>Me: no.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p><\/span><\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"background-color: rgba(255, 255, 255, 0)\"><br \/>\n<\/span><\/p>\n<\/div>\n<div dir=\"ltr\">\n<table style=\"border: 1px solid black; padding: 8px\">\n<tbody>\n<tr valign=\"bottom\">\n<td width=\"48\"><span style=\"background-color: rgba(255, 255, 255, 0)\"><img decoding=\"async\" src=\"https:\/\/pbs.twimg.com\/profile_images\/662345762534113280\/FVk7uaEB_normal.jpg\" style=\"width: 48px; height: 48px; padding-right: 8px\"><\/span><\/td>\n<td><b style=\"background-color: rgba(255, 255, 255, 0)\">Pieter Gunst (<a href=\"https:\/\/twitter.com\/digitallawyer?s=11\">@DigitalLawyer<\/a>)<\/b><\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\">\n<div><a href=\"https:\/\/twitter.com\/digitallawyer\/status\/1181348690683760642?s=11\" style=\"caret-color: rgb(0, 0, 0); background-color: rgba(255, 255, 255, 0)\"><font color=\"#000000\">10\/7\/19, 4:20 PM<\/font><\/a><\/div>\n<div><span style=\"background-color: rgba(255, 255, 255, 0)\">2) &#8220;Ok. We&#8217;ve blocked the transaction. To verify that I am speaking to Pieter, what is your member number?&#8221;<\/p>\n<div>\n<div>\n<div>\n<div>\n<div>\n<p>Me: &lt;gives member number&gt; (that number, by itself, is useless).<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p><\/span><\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"background-color: rgba(255, 255, 255, 0)\"><\/span><\/p>\n<\/div>\n<div dir=\"ltr\">\n<table style=\"border: 1px solid black; padding: 8px\">\n<tbody>\n<tr valign=\"bottom\">\n<td width=\"48\"><span style=\"background-color: rgba(255, 255, 255, 0)\"><img decoding=\"async\" src=\"https:\/\/pbs.twimg.com\/profile_images\/662345762534113280\/FVk7uaEB_normal.jpg\" style=\"width: 48px; height: 48px; padding-right: 8px\"><\/span><\/td>\n<td><b style=\"background-color: rgba(255, 255, 255, 0)\">Pieter Gunst (<a href=\"https:\/\/twitter.com\/digitallawyer?s=11\">@DigitalLawyer<\/a>)<\/b><\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\">\n<div><a href=\"https:\/\/twitter.com\/digitallawyer\/status\/1181348691623337984?s=11\" style=\"caret-color: rgb(0, 0, 0); background-color: rgba(255, 255, 255, 0)\"><font color=\"#000000\">10\/7\/19, 4:20 PM<\/font><\/a><\/div>\n<div><span style=\"background-color: rgba(255, 255, 255, 0)\">3) &#8220;We&#8217;ve sent a verification pin to your phone.&#8221;<\/p>\n<div>\n<div>\n<div>\n<div>\n<div>\n<p>~ Gets verification pin text from bank&#8217;s regular number ~<\/p>\n<p>Me: &lt;reads out the pin&gt;<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p><\/span><\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"background-color: rgba(255, 255, 255, 0)\"><\/span><\/p>\n<\/div>\n<div dir=\"ltr\">\n<table style=\"border: 1px solid black; padding: 8px\">\n<tbody>\n<tr valign=\"bottom\">\n<td width=\"48\"><span style=\"background-color: rgba(255, 255, 255, 0)\"><img decoding=\"async\" src=\"https:\/\/pbs.twimg.com\/profile_images\/662345762534113280\/FVk7uaEB_normal.jpg\" style=\"width: 48px; height: 48px; padding-right: 8px\"><\/span><\/td>\n<td><b style=\"background-color: rgba(255, 255, 255, 0)\">Pieter Gunst (<a href=\"https:\/\/twitter.com\/digitallawyer?s=11\">@DigitalLawyer<\/a>)<\/b><\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\">\n<div><a href=\"https:\/\/twitter.com\/digitallawyer\/status\/1181348692462198784?s=11\" style=\"caret-color: rgb(0, 0, 0); background-color: rgba(255, 255, 255, 0)\"><font color=\"#000000\">10\/7\/19, 4:20 PM<\/font><\/a><\/div>\n<div><span style=\"background-color: rgba(255, 255, 255, 0)\">4) &#8220;Ok. I am going to read some other transactions, tell me if these are yours. ~ Reads transactions ~&#8221;<\/p>\n<div>\n<div>\n<div>\n<div>\n<div>\n<p>Me: Yes. These are all legitimate transactions I made<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p><\/span><\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"background-color: rgba(255, 255, 255, 0)\"><\/span><\/p>\n<\/div>\n<div dir=\"ltr\">\n<table style=\"border: 1px solid black; padding: 8px\">\n<tbody>\n<tr valign=\"bottom\">\n<td width=\"48\"><img decoding=\"async\" src=\"https:\/\/pbs.twimg.com\/profile_images\/662345762534113280\/FVk7uaEB_normal.jpg\" style=\"width: 48px; height: 48px; padding-right: 8px\"><\/td>\n<td><b>Pieter Gunst (<a href=\"https:\/\/twitter.com\/digitallawyer?s=11\">@DigitalLawyer<\/a>)<\/b><\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\">\n<div><a href=\"https:\/\/twitter.com\/digitallawyer\/status\/1181348693326254083?s=11\">10\/7\/19, 4:20 PM<\/a><\/div>\n<div>5) &#8220;Thank you! We now want to block the pin on your account, so you get a fraud alert when it is used again. What is your pin?&#8221;<\/p>\n<div>\n<div>\n<div>\n<div>\n<div>\n<p>Me: Are you effing kidding me, no way.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div dir=\"ltr\"><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>By Larry Chiang Phishing.&nbsp; 1\/ Social engineering Building trust by asking questions they know the answers to.&nbsp; 2\/ attack surface is anything with emotion Humans.&nbsp; 3\/ texts can be spoofed Texts and emails can be spoofed Any asset touching the Internet that\u2019s accessible by \u201cPIN\u201d is in jeopardy.&nbsp; Read Pieter Gunst\u2019s tweet and comment what [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[40],"tags":[],"class_list":["post-12265","post","type-post","status-publish","format-standard","hentry","category-deep-underground-credit-knowledge-via-subroutines"],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.duck9.com\/blog\/wp-json\/wp\/v2\/posts\/12265","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.duck9.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.duck9.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.duck9.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.duck9.com\/blog\/wp-json\/wp\/v2\/comments?post=12265"}],"version-history":[{"count":0,"href":"https:\/\/www.duck9.com\/blog\/wp-json\/wp\/v2\/posts\/12265\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.duck9.com\/blog\/wp-json\/wp\/v2\/media?parent=12265"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.duck9.com\/blog\/wp-json\/wp\/v2\/categories?post=12265"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.duck9.com\/blog\/wp-json\/wp\/v2\/tags?post=12265"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}