Ask HN: Protect loved ones from online scams?
97 points| paulryanrogers | 8 years ago | reply
Most of my efforts helping others were too little or too late: educating after the fact, Ubuntu Linux (too incompatible), password managers (left unused), etc.
How does the HN community protect their loved ones from these things?
[+] [-] Animats|8 years ago|reply
I call FedEx Revenue Services, and they can't find anything wrong with the account. They tell me the account isn't suspended. They want the expiration date on my credit card updated before the end of the month, but it hasn't expired yet.
I look at the message source, and it looks like it's really coming from FedEx, and the link really goes to FedEx. I keep looking, and can't find anything wrong in the headers. It's a legit email. It's just stupidity at FedEx.
Sloppy work, FedEx, sending out an email like that. You're training people to click on links they should not click on.
[+] [-] muzani|8 years ago|reply
The email was completely dodgy, had several typos. There was a lack of instructions on what to do, just a "please contact us". I tried to contact customer service instead of the representative, but it was impossible because I needed an order code, which they never gave me. Emails to the individuals were never replied to and he insisted on only calling and handling a bank transfer over the phone.
The whole situation was very similar to a man in the middle attack.
It turned out to be legit, but the whole situation makes me never want to order anything from them again.
[+] [-] a3n|8 years ago|reply
Either the people you are able to contact don't care, because they have no idea what you're talking about, or they don't care because they wrote/required exactly what you're complaining about, out of expediency or ignorance.
[+] [-] Xuebit|8 years ago|reply
https://superuser.com/questions/505503/how-can-you-fake-an-e...
[+] [-] bmay|8 years ago|reply
[+] [-] vertex-four|8 years ago|reply
[+] [-] louithethrid|8 years ago|reply
[+] [-] frik|8 years ago|reply
So why is this comment on top?
It seems HN got mainstream and with it the usefulness is declining - low quality comments staying on top that can be answered by common sense.
[+] [-] carlesfe|8 years ago|reply
I designed a series of rules + practices which are stated as absolutes (i.e. no margin for interpretation) and they have worked well:
1. All emails with claims are false, even if I send them. Not only spam but also "snopes-like" scams from her friends. This rule always has precedence over anything else. 100% Never trust an email content. If it looks like there could be really bad consequences from ignoring an email, forward it to me and I'll decide.
I told her "imagine a stranger calls you on the phone and reads you the content of an email. Would you trust it?". She understood the metaphor.
2. She doesn't know her passwords. They are stored in the browser's keyring. Thus, she can't provide credentials to phishing websites.
3. She can click on links from emails, unless it is from a bank, because she knows her bank credentials. The combination of (2) and (3) makes the internet very usable for her as she can browse with confidence.
4. She only logs in to the bank website from her browser bookmark. She uses Safari's "Top sites" heavily, and she has learned to Google basic stuff.
5. If there is a weird message on a website, treat it as an email (i.e. it is false, etc)
6. Adblock is installed
7. She is beginning to recognize OS prompts, like icloud messages (storage, passwords). She knows she can never click on one before sending me a picture by IM. For these prompts password managers don't auto-input them and that's a problem. I must confirm its validity and then she has permission to open a notepad where her passwords are written and transcribe it to the prompt. But she always needs to send me a pic before opening the password notebook.
8. I have enabled Gatekeeper on the mac, thus she can't open binaries from the internet, only documents. Word macros are disabled.
9. If something doesn't look right, call/IM me on your cellphone
She is a very simple user and her needs are limited to websites, mail, office and a few games, so this works well. YMMV.
Maybe there are more rules that I can't remember right now, but the combination of not knowing her passwords + password manager + not trusting email + unable to run unknown binaries + adblock has worked wonderfully.
Let me know if you have more suggestions
[+] [-] nl|8 years ago|reply
[+] [-] noir_lord|8 years ago|reply
That and a basic crash course in treat everything as suspicious unless you know it isn't has sufficed so far.
If she has any doubts she just rings me but that's rare.
[+] [-] imroot|8 years ago|reply
Works like a charm.
[+] [-] swinglock|8 years ago|reply
[+] [-] apexalpha|8 years ago|reply
Installed a PiHole to clear all their devices from malicious ads / malicious url's.
Seriously, since I installed PiHole my maintanance visits / calls have dropped by 90%.
They don't use a CC. Maybe once a year for flight tickets but I tell them to check the URL / https.
And I've told them 100 times: companies do not call you. They don't. Ignore calls!
[+] [-] jsingleton|8 years ago|reply
It's better than a browser extension, as it works for mobile devices and native apps (e.g. Skype). Remember to set a backup secondary DNS server in case it goes down though.
If the router allows changes to the DHCP DNS settings then make them there. Some don't, so then you'll need to use the Pi for DHCP too.
However, keep in mind that it provides an unauthenticated web interface that exposes all domains that have been visited. This could be a privacy risk. It's pretty easy to simply use dnsmasq on its own if you don't want the extras.
You can also use this technique to make some news sites less annoying: https://unop.uk/block-bbc-breaking-news-on-all-devices
No, BBC News still doesn't support HTTPS (it's now over 6 months later than they said it would).
[+] [-] charlesdm|8 years ago|reply
It's mostly immune to spyware, she's smart enough to know she shouldn't click on any random e-mails and not to use the same password of her email account anywhere else.
[+] [-] mattbgates|8 years ago|reply
As a result of this, I wrote a series of articles to try an educate my readers on the dangers of replying and/or dealing with any spam or scam emails.
Here are the links:
http://www.confessionsoftheprofessions.com/avoid-phishing-sc...
http://www.confessionsoftheprofessions.com/truth-seo-marketi...
http://www.confessionsoftheprofessions.com/confessions-profe...
http://www.confessionsoftheprofessions.com/how-to-notice-a-s...
http://www.confessionsoftheprofessions.com/teaching-children...
[+] [-] navd|8 years ago|reply
[+] [-] jcahill|8 years ago|reply
[+] [-] a_imho|8 years ago|reply
Otherwise I just advised her not to give out personal information, including email, phone and credit card numbers. And don't click links in emails she does not recognize the sender or looks suspicious. Best not to even open them. In doubt, I'm usually available to doublecheck.
Pendrives caused a lot of problems in the past, luckily broadband solved most of the file transfer issues.
[+] [-] scandox|8 years ago|reply
[+] [-] Fnoord|8 years ago|reply
SEO affects search engines like Google, putting shady businesses high in the search result (sometimes even #1).
I've seen this first hand with my mother who needed a locksmith because the lock on her front door broke. The cost of 'repairing' was well over 500 EUR, and the lock wasn't repaired at all, it had to be completely replaced afterwards by a real locksmith which was legit but due to the damage the scammer caused was expensive a well. This is a known scam trick going on in The Netherlands, but probably just one of the many examples.
[+] [-] lathiat|8 years ago|reply
It's a subtle way to educate without "telling" which puts alot of people of. For more direct approaches, see some of the other comments about rules for his mother, etc. :)
I find this helpful as 90% of the time these scams are super obvious to me but not others, so I try to share that knowledge.
[+] [-] ptr_void|8 years ago|reply
There's also a lot of youtube videos that could be easier to send and less boring to go through. Ex:
- https://www.youtube.com/embed/bjYhmX_OUQQ?rel=0
- https://www.youtube.com/embed/DXfrfbNk7jo?rel=0
- https://www.youtube.com/embed/poFAzDCGLrI?rel=0
- https://www.youtube.com/embed/5zlnI3Bzslo?rel=0
- https://www.youtube.com/embed/O4KJq0XXIy8?rel=0
- https://www.youtube.com/playlist?list=PLDBC1CF5C16D5585D
[+] [-] dannysu|8 years ago|reply
That's basically the setup I have with my dad. He's using Ubuntu on desktop, which I taught him to use. There wasn't much to teach. He really just wants to use a browser. I taught him how to scan documents and print documents as well. That's pretty much all he needs to do.
And then he has his iPad as well, and I taught him how to print stuff from his iPad too.
I also got him to use 1Password, and he has unique password for each site.
These are all things I've taught my dad to do.
[+] [-] paulryanrogers|8 years ago|reply
[+] [-] secretsinger|8 years ago|reply
Here are some things I've found which are simple enough to implement but actually offer substantial gains. Learned mainly from helping partners and parents:
1. Move them to Gmail. Email seems to still be the primary vector for most attacks and Gmail's filters are awesome.
2. Get them on a less permissive OS. Shifting from Windows to OSX/iOS has made a huge difference.
3. Teach them a reasonable password-generating method (correct-horse-battery-staple or some such). They are gonna forget and reset passwords regularly, which is OK. I gave up on getting them to habitually use a password manager.
4. Force (coerce/bribe/cajole) them to use 2FA on critical accounts (email, FB)
5. Tell them lots of anecdotes about hacks, things I spotted in my email, etc. As someone else pointed out, you can work in a lot of useful info in a memorable way in these anecdotes.
Tech does seem to be only part of the solution (and probably not even the major part). I've been doing some gig work for a company [http://www.popcorntraining.com] that does story-based security awareness videos, mainly for corporates. They have pretty good results based on fairly small time investment by the participants.
Sadly, most of the players in this market seem to be focused on big companies at the moment, with a few starting to aim at SMEs. We've bounced around the idea of trying to help the consumer market, but its not yet been worthwhile for them.
[+] [-] sep|8 years ago|reply
That being said, there's no getting around education. It's key to prevent a person from being scammed out of their passwords or oauth-access in the first place.
[+] [-] austinjp|8 years ago|reply
Are there other web-based services people here can recommend? Haveibeenpwned is great of course, but the horse has left the stable by that point, something that sniffs out suspicious activity before trouble occurs would be great.
[+] [-] Mz|8 years ago|reply
2) Develop or help them develop viable processes for their needs and abilities that will sidestep issues.
This involves a small amount of educating people, less than is needed for real internet literacy. The difference is it makes them literate enough to navigate the parts they actually use, without some huge burden of additional general information that they son&t really need and which will just interfere with them learning the pieces they actually need to know.
[+] [-] jakub_g|8 years ago|reply
Good advice is to never click links in emails, but go manually to a given page (via Google perhaps) and log in yourself.
It's a bit easier if your family lives outside of English-speaking country when it comes to phishing. Phishing spam is either English, or a poor google translate 95% of the time.
[+] [-] akulbe|8 years ago|reply
I'd also recommend a Chromebook, for folks who don't like our can't asked the iPad option.
[+] [-] zamalek|8 years ago|reply
[+] [-] frik|8 years ago|reply
[+] [-] Rjevski|8 years ago|reply
[+] [-] paulryanrogers|8 years ago|reply
[+] [-] gcb0|8 years ago|reply