home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky sci.crypt:3239 alt.security:4369 comp.security.misc:1250
- Newsgroups: sci.crypt,alt.security,comp.security.misc
- Path: sparky!uunet!mcsun!sunic!psinntp!psinntp!viper!news
- From: ken@visix.com (Ken Mayer)
- Subject: Re: ATM fraud
- Sender: news@visix.com
- Message-ID: <BuL2pH.6s3@visix.com>
- Date: Mon, 14 Sep 1992 19:41:41 GMT
- Reply-To: ken@visix.com
- References: <1992Sep8.115050.8694@cl.cam.ac.uk>
- <JIM.92Sep9125700@hunter.cs.strath.ac.uk>
- Organization: Visix Software Inc., Reston, VA
- Lines: 48
-
-
- Jim> In article <1992Sep8.115050.8694@cl.cam.ac.uk>
- Jim> rja14@cl.cam.ac.uk (Ross Anderson) writes:
-
- Jim> A new type of ATM fraud has just arrived in London.
-
- Jim> A much simpler (and successful) fraud is to steal someone's
- Jim> wallet or purse. This usually yields the victim's phone number
- Jim> as well as ATM cards. The fraudster then calls the victim
- Jim> claiming to be a police officer or bank security official and
- Jim> asks for the PIN number for "verification" or "for their
- Jim> report".
-
- An *even* simpler fraud than that is the following. Place the
- following advertisement in any large metropolitan or national
- newspaper (names etc. paraphrased):
-
- Sally Sue Cosmetics
- Receive $89.99 worth of name brand cosmetics
- for only $19.99!!!
- Visa/MasterCard Accepted
- Call 1-800-555-5555
- 6-8 weeks delivery
-
- Then contract with any telephone order service (basically an answering
- service) to collect name, address, credit card number, telephone, etc.
- The order service will deliver to your doorstep a list (on tape,
- printout, whatever) with all the suckers that called in. While your
- "customers" are waiting for their order, you can rob them blind. By
- the time they've noticed the problem, you're long gone.
-
- This is a true story, reported in a recent 60-minutes (a U.S. news
- show). The perpetrator was a prisoner, awaiting trial for murder. And
- while he was waiting, he ran this and other successful telephone scams
- right from his cell.
-
- Face it, no matter how sophisticated you make your authentication
- scheme, if the end user doesn't know how to take adavantage of it,
- they're going to get ripped off. You are much better off trying to
- educate them (a lost cause, but far cheaper than technological slight
- of hand), in hopes that someone learns something.
-
- Ken
- --
-
- Ken Mayer (ken@visix.com)
- Visix Software Inc./703.758.8230
- Bene Vivere Ultio Optima --- Living Well is the Best Revenge
-