I usually post the article in the comments so it is easier to read, but Troy hunt 's website is already so easy to read its a joy!
Technology
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
One cool thing that just went live in the last month or so is SMS Sender ID. You need to file a shitton of paperwork before being given the keys to send an SMS to an Australian with a name instead of a phone number.
https://www.acma.gov.au/sms-sender-id-register
I personally had to write the code to make this work for a rather large financial institution that uses AWS for bulk SMS. It was a lot of hoops to jump through. If you get one detail wrong, your SMS just has a phone number instead of a name.
At this point, it should be impossble to deceptively get "Fedex" into an SMS header.
Yeah. Recently I was expecting a message from a bank, finally I got a call... from a chatbot claiming it has an important message for me, but first I have to give it my private info to verify myself and there's no way to validate the call is legit first.
When I complained to the bank they just told me I shouldn't worry, they made the call so it's perfectly safe and there's nothing to worry about...
I would change banks over that and list that as the reason why.
My baking app has a "is calling" button, which is pretty neat. The button is highlighted whenever I open the banking app whilst on a phone call, presumably as a subtle anti-scammer warning.
There's a sage piece of advice that's always relevant in these cases and it's very simple: if in doubt, go the website in question and verify the request yourself.
Now the spamer has confirmation that this address is active, can be shared in their network.
The known legit website, not the one in the link.
You don't use the link. You go to the website by your normal means. In this case, he opened a browser and went to the FedEx site on his own. That way you know you are on the real site.
Never thought about it that way, I usually open sketchy stuff in tor
If you remove the tracking parts of the URL.
Is this for real? I would’ve automatically deleted and reported it as spam lol.
You and the "87%" of people who responded to his Tweet or whatever.
Yeah, of course. Surprised there are “13%” of people of his Tweet that would not or whatever.
hurr durr sus message here and there but surprise he is expecting a package. that sus af email is exactly that kind of email i would expect in that situation, including broken links and everything. not worth a read
Pro tip: Scammers want your money, their links will work ;)
You keep getting phished by links with bpoint.com.au as the domain claiming to be FedEx?
Read the article. All the communications were legit, but they looked more suspicious than actual phishing because FedEx is just that inept. Also, bpoint.com.au is a legit domain used by these services.