10 ms·
what's your solution to combat scammers?
by wswin 6mo ago
what's your solution to combat scammers?
- singpolyma3 6mo agoIf cooldowns work, put them on granting permissions. There are just as many scam apps in play store and this system does nothing to help with those.
- dminik 6mo agoI'm going to break your kneecaps. Oh, what's that? You don't like it? Well, what's your solution to P=NP?
- skeaker 6mo ago[flagged]
- fluidcruft 6mo agoI wonder whether scammers will switch to using PWA.
- scoofy 6mo agoIt's very obviously not irrelevant. Google is not going to let their main phone app product become associated with Grandma losing her savings! That's not going to help the free software folks... it's going to send everyone over to iOS.
- tavavex 6mo ago> Google is not going to let their main phone app product become associated with Grandma losing her savings! How did they manage to survive as the grandma-account-draining brand for over 15 years, though? They're still the market leader. One of the best arguing tactics the pro-control side has come up with is "The way it works right now is JUST not good enough". And then you don't need to argue any further or substantiate that. You just force your opponent into coming up with new measures because obviously right now we have an emergency that must be dealt with immediately. So far, this reasoning has worked for program install restrictions, de-anonymizing internet users, all sorts of other random attestation and verification measures, and it will be used for so much more. My question to all that is - what has happened NOW that changed the situation from how it was just a couple years back?. Google hasn't been sitting idle for all these years, they've been adding measures to Android to detect malicious software and prevent app installs by clueless users - measures that were striking a balance between safety and freedom. Why is everything safety-related in the last few years suddenly an emergency that must be rectified by our corporate overlords immediately and in the most radical ways? How did we even survive the 2010s if people are less secure and more prone to being scammed with the new restrictions right now than they were back then? I'm not saying there's not an issue, but without hard stats, these issues will always be magnified by companies as much as possible as the wedge to put in measures that benefit them in ways other than the good-natured safeguarding of the consumer. In an open society, there's always a point where you balance the ability to act freely with ensuring that the worst actors can't prosper in the environment. Only one of these things is bad, but you can't have both. You need a middle ground.
- scoofy 6mo ago> How did they manage to survive as the grandma-account-draining brand for over 15 years, though? 15 years ago ransomware effectively didn't exist and virtually nobody's grandparents did their banking on their phones.
- Dylan16807 6mo agoInsufficient answer. "The past 15 years" is asking about that entire period. If you want to compare a specific point in time, they asked what changed since "a couple years ago". A fair point-in-time comparison might stretch "couple" as far back as 2020 because of how they talked about surviving the 10s, but no further. So, 2020 or 2023 or so. Plenty of ransomware, plenty of phone banking. What changed since then?
- lyu07282 6mo agoIt's for the same reason governments all over started to implement "age verification" laws all of a sudden, they never tell us their real motivation. That we can only speculate on, but for many people it seems they just go along with it and believe them all on face value, that's what all the media does anyway. The overarching goal they all work towards seems to be total control and surveillance of people's information sources and communication.
- wswin 6mo agoYou didn't even slightly research the topic of phone malware, browse /r/isthisascam for starters. I don't say the problem is an "epidemic" and it doesn't have to be an epidemic to be addressed.
- lukeschlather 6mo agoAll apps should be open source and subject to verification by nonprofit repositories like F-Droid which have scary warnings on software that does undesirable things. For-profit appstores like Google and Apple that allow closed source software are too friendly to scams and malware.
- staticassertion 6mo agoThat's absurd.
- RobotToaster 6mo agoNo more absurd than letting a megacorp control what I install on my own device.
- staticassertion 6mo agoInstead the megacorp forces open source licensing, which doesn't solve any of this shit anyway lol
- array_key_first 6mo agoIt's also true, the best way to audit software is source-code and behavior analysis. Google and Apple do surprisingly minimal amounts of auditing of the software they allow on the Play Store and App Store, mostly because they can't, by design. It should shock absolutely nobody then that those distribution methods are much more at risk of malware.
- staticassertion 6mo agoNo one is auditing. Behavior analysis works on closed source software too.
- array_key_first 6mo agoMost open source repositories do have eyes on the code. Debian often has separate maintainers who maintain patches specific to Debian. It's not a coincidence that Linux distros are much less susceptible to malware in their official repositories. It's a result of the system. Trusted software currated and reviewed by maintainers. The play store will always have significant amounts of malware, so this entire conversation is moot.
- dataflow 6mo agoNot the parent or agreeing/disagreeing with them, but to your question: if you get creative, there are a lot of things you could do, some more unorthodox than others. Tongue-in-cheek example, just to get the point across: instead of calling it Developer Mode, call it "Scam mode (dangerous)". Require pressing a button that says "Someone might be scamming me right now." Then require the user to type (not paste) in a long sentence like "STOP! DO NOT CONTINUE IF SOMEONE IS TELLING YOU TO DO THIS! THIS IS A SCAM!"... you get the idea. Maybe ask them to type in some Linux command with special symbols to find the contents of some file with a random name. Then require a reboot for good measure and maybe require typing in another bit of text like "If a stranger told me to do this, it's a scam." Basically, make it as ridiculous and obnoxious as possible so that the message gets across loud and clear to anybody who doesn't know what they're doing.
- anonym29 6mo agoThe people falling for social engineering now won't be protected by this either. You could gate the functionality behind verification of an anti-scam awareness and education training and certification course, scammers would coach people through the entire course and the verification step, and people would still be victimized.
- dataflow 6mo agoNothing is perfect, but by what percentage would you think scams that leverage sideloading would drop? 1%? 10%? 50%? 90%? 99%?
- anonym29 6mo agoCompared the current paradigm, where you already need to enable developer options, allow installation from untrusted sources, and tap through a warning screen for each apk to be installed? Maybe 10-20%, generously. The people who are falling for it under current protections clearly are not reading anything they're looking at or thinking about security at all, they've fallen for social engineering scams and sincerely believe they're at imminent risk of being arrested by the FBI or that their adult child is about to be killed. They're in fight or flight mode already, not critical thinking and careful deliberation mode. If you were to rank everyone by gullibility, these people would largely be clustered in the top 1-2% of most gullible people. There is very little you can do to protect these people, realistically.
- fluidcruft 6mo agoI suppose you could make the cooldown apply to the actual installed app. Like... when it's first installed it won't work for 24 hours and the clock doesn't start until you reboot. And then on boot it scares you again before starting the clock. And then "scares" you again after the cooldown.
- RobotToaster 6mo ago'Those who would give up essential liberty to purchase a little temporary safety, deserve neither liberty nor safety.' - Benjamin Franklin
- fluidcruft 6mo ago'essential' means can't be bothered to wait 24 hours (once)?
- fsniper 6mo agoYou are missing the part that new 24 hour process was a response to backlash. It was not even in their plan.
- JoshTriplett 6mo agoSounds like backlash needs to continue until it's clear that that isn't acceptable either.
- bonoboTP 6mo agoBoiling the frog.
- xp84 6mo agoI have to completely concur that it's probably one step toward an increasingly restrictive final state. Add a few "Are you sure?? You'll brick your phone!!!" warnings, then ID and age-verification mandatory (think of the children!!)
- hparadiz 6mo agoMaybe it's not good idea for our entire civilization to use only two mobile operating systems controlled by companies that only want to make money.
- 6mo ago
- supern0va 6mo agoWould you support Microsoft doing the same thing to Windows? These are general purpose computing devices. It's sure taking a long time, but Cory Doctorow's talk on the war on general purpose computing is sure starting to become a depressing reality: https://www.youtube.com/watch?v=HUEvRyemKSg https://www.youtube.com/watch?v=HUEvRyemKSg
- tredre3 6mo agoMicrosoft is doing the same thing, they call it S-mode. A surprisingly large amount of computers are sold with Windows S. Thankfully S-Mode can usually be disabled even if your computer shipped with it enabled. Windows S mode is a streamlined version of Windows designed for enhanced security and performance, allowing only apps from the Microsoft Store and requiring Microsoft Edge for safe browsing.
- tadfisher 6mo agoWhich is frankly hilarious because the Microsoft Store is the worst offender when it comes to hosting straight-up scams. I'm not the only one who has noticed: https://www.reddit.com/r/windows/s/6y39VNaLUh https://www.reddit.com/r/windows/s/6y39VNaLUh
- GeekyBear 6mo agoTell the unsophisticated users that they would be safer inside the ecosystem that has always been a walled garden. Why destroy the ecosystem that gives you the freedom to shoot yourself in the foot? Turning Android into another walled garden removes user choice from the equation.
- deleted 6mo ago[deleted]
- bonoboTP 6mo agoDo you think regular desktop computer should be locked down like this too? Scammers can also tell people to run Windows programs. Should that be banned too? I'm fine with an opt-in lock-down feature so people can do it for their parents/grandparents/children. Also, just let people get used to it. People will get burned, then tell their friends and they will then know not to simply follow what a stranger guides them to do over the phone. Maybe they will actually have second thoughts about what personal data they enter on their phone and when and where and who it may be sent to. Same as with emails telling you to buy gift cards at the gas station. Should the clerk tell people to come back tomorrow if they want to buy a gift card, just in case they are being "guided" by a Nigerian prince scammer?
- pas 6mo agoMaybe? Let people form CAs, and if a CA gives out certs for malicious apps remove them. (Old apps continue to work, to publish new one get new cert.) Yes, sad, but works. People will learn about scams, but scammers are unfortunately a few steps ahead. (Lots of scammers, good techniques spread faster among them than among the general public.)
- flomo 6mo agoIf "they" is Google, this is just a really pointless middleman proposal. Android does all the cert stuff. Also Chrome trusts like 300 CAs. Does that work? Probably not if you live in 200 of those countries.
- flomo 6mo agoKeep in mind that Android has like a billion users who have never touched a Windows computer. (And unmanaged Windows was/is also a disaster zone.) Coming at this from a internet forum perspective is missing the scope of the problem. > I'm fine with an opt-in lock-down feature Me too, but it's really just some UI semantics whether this is 'opt-in' or 'opt-out'. Essentially it would be an option to set up the phone in "developer mode".
- Dylan16807 6mo ago
- whatshisface 6mo agoLet's say I'm sitting outside of your office with a bazooka and boxes of high explosives. You ask my why, and I say, "someone might try to rob this office." You say, "somehow, that does not persuade me that a stranger should loiter outside of my workplace with a massive stockpile of ordinance." I reply, "what's your solution to combat robberies?"
- rtpg 6mo agolet's say I put a lock on an office door. You say "Why? Bazookas will get through the door anyways". I don't know how I feel about this change but context does in fact matter about whether something is a good idea or not
- fsniper 6mo agoIs it a lock? I buy a building and the builder put an id verification lock on the doors and I am not allowed to remove it. And they also require a separate one time fee of 2 to 5 percent of the purchase price.
- rtpg 6mo agototally my point here. The actual shape of the thing starts mattering so much that at one point your metaphor is just completely useless for judging the actual tradeoffs
- strogonoff 6mo agoMetaphors have their limits. In physical world, there’s only so many people who can rob you if you do something stupid (like constantly give away copies of your keys to strangers), they will be very noticeable when they are doing so, and if you feel like something’s off you can always change the lock. On the Internet, an you are fair game to anyone and everyone in the entire world (where in some jurisdictions even if it’s known precisely who is the figurative robber they wouldn’t face any consequences), you could get pwned as a result of an undirected mass attack, and if you do get pwned you get pwned invisibly and persistently. Some might say in these circumstances the management company installing a (figurative) biometric lock is warranted, and the most reliable way to stop unsuspecting residents from figuratively giving access to random masked strangers (in exchange for often very minor promised convenience) is to require money to change hands. Of course, that is predicated on that figurative management company 1) constantly upping their defences against tenacious, well-funded adversaries across the globe and 2) themselves being careful about their roster of approved trusted parties, whom they make it easy to grant access to your premises to.
- passwordoops 6mo agoLike the ones constantly advertising across Google's plethora of platforms without any repercussions or possibility of recourse with Google? For my safety, of course.
- lyu07282 6mo agoBut this has nothing to do with combating scammers in the first place, have you never used the play store before? It's overwhelmingly scam apps with the most intrusive ad/tracking shit imaginable. There are scammers openly buying sponsored search results for names of popular apps so their malicious app with similar name appears as the first result.
- userbinator 6mo agoSomething called personal responsibility and intelligence. ...which clearly companies don't want, because complacent mindless idiots are easier to brainwash, control, and milk.
- JoshTriplett 6mo ago"Warning: if someone is talking to you and walking you through this screen, you may be being scammed!" Done.
- jaimex2 6mo agoWe need to remove the play store from Android phones. People have been scammed there more than any other store.
- ReptileMan 6mo agoChina just executed couple of them that operated in Myanmar. Since we are hurling towards the bad parts in their dystopia anyway, why not also get the good ones?
- themafia 6mo agoForce the phones to be open so I can install my own OS on them. Then Google can do whatever they want with their OS and I can do what I need with mine. You might actually get phone OS competition. This is what the walled garden is actually meant to prevent.
- steve_woody 6mo agoDon't install crap on your phone
- ajb 6mo agoThe choice is not between "individuals are on their own against scammers" and "users are locked into Google vetting their phone". Users should be able to choose another organisation to do the vetting. They bought a phone, they didn't sell their life to Google.
- kryptiskt 6mo agoAs if Google Play itself isn't a cesspool full of scammers, or Google ads, or Youtube. As long as Google get their cut they don't give a shit about scams. For a reality check, turn off your adblockers and you'll see how much Google profits from scams. Any solution to scamming can't involve Google, since they long have been a willing tool for scammers. Pretending that this is about anything but Google's greed is giving them far too much credit.
- KoolKat23 6mo agoEnable unknown sources in developer options, have the user type out in order to proceed "If I am typing this and don't know what I am doing, I am likely being scammed".
- poulpy123 6mo agoAre scammers using sideloaded apps when they can use whatever remote connexion the apps in the store allow ? I think a big warning in red "Warning :If you don't personally know the person asking you to install this app, you are getting scammed. No legitimate business or Institution will ask you to install this app"
- rawbot 6mo agoWhy would you need to sideload anything when scammers can just use Teamviewer or any remote operation software, readily available in the Play Store, that will surely pass whatever "checkmark" process Google uses to validate "safe" apps?
- AlfeG 6mo agoI wonder how this will help combat scammers. Do you really think they don’t have $25 for a fee? Furthermore, this verification system also functions as a US sanction mechanism—one that can be triggered against any entity the US decides to ban.
- troyvit 6mo ago> what's your solution to combat scammers? I'd wipe the Play Store off the face of the earth. Have you looked at the garbage on there that Google considers legit? This: https://news.ycombinator.com/item?id=47447600 https://news.ycombinator.com/item?id=47447600 is is the shit people are exposed to when they go through the Play Store. You don't find that on F-droid. The second thing I'd do to combat scammers is the same thing I'd do to combat child porn and disinformation: educate people. This silly process is a technical answer to a social problem, and those rarely work well.
- nazgulsenpai 6mo agoeducation
- mrguyorama 6mo agoSo there's no scamming happening in Apple's fully walled garden, "Only approved apps allowed" system, right? https://blog.lastpass.com/posts/warning-fraudulent-app-impersonating-lastpass-currently-available-in-apple-app-store https://blog.lastpass.com/posts/warning-fraudulent-app-imper... Oh, turns out they just let you pretend to be the real company to sell your scam app. What a load of good that "Approval" process does.
- ozgrakkurt 6mo agoEducation is the only solution to this. You can’t feasibly protect someone that believes the person on the phone is their family member or the chief of police. This kind of thing has to be verified like how they try drugs. Just randomly doing things will surely be useless, similar to how randomly optimizing parts of a program is generally worthless.
- ulrikrasmussen 6mo agoIf I proposed putting mandatory cameras in all homes and you objected, would it then be fair for me to demand that you justify your position by proposing a better alternative to combat domestic violence? Locking down computing is just fundamentally wrong and leads to an unfree society.
- gzread 6mo agoArrest the scammers