TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: How do you protect yourself from bank fraud?

12 点作者 benohear将近 12 年前
A friend of mine recently had €1600 stolen from his account in Germany, despite two-factor authentication (SMS Tan is the norm over here), which I always assumed was pretty secure.<p>Turns out the thieves first hack your web browser (through the usual means) and then alter the web page of your bank to display instructions to install a "security" app on your smartphone (MITB attack). So then they have access to both factors and you're boned. Google "Eurograbber" to find out more.<p>What I find kind of scary is the usual caution is likely to fail. After all, this is the correct URL and the correct SSL cert, so if the fake visuals are well produced it will appear completely legit.<p>I suppose one approach is to make sure you always logon with a clean browser, so I was thinking of a portable VirtualBox with a copy of Linux used solely for the purpose of online banking. I could even hand out keys to my friends.<p>Do you think this would be effective? And what precautions do you take with online banking?

5 条评论

tallanvor将近 12 年前
While a virtual machine used only to access online banking would probably work, would your friend actually stick with it? And be honest - if he wouldn't there's not much point.<p>The best option is education. Help him understand how the malware was installed and how he can try and prevent it from happening in the future (don't allow applications to be installed if they weren't specifically expecting it, keep their AV running - no matter what an installer says, always install Java and Adobe updates, and avoiding dodgy streaming video and proxy sites).<p>I recently had to help a friend clean ransomware off his system, and found a bunch of other crap while I was at it. --I <i>think</i> I got it all, but I still warned him that it was possible we missed something and a full format and reinstall would be safer. In his case I'm pretty sure it came from one of the many dodgy sites used to stream TV shows and such, although he had also downloaded and installed VLC from one of those sites that rebundled it with additional crap, so that could have compromised the system as well.
评论 #5734312 未加载
xSwag将近 12 年前
Eurograbber is a variation of the Zeus/Sopilka family of malware. I'm surprised his AV didn't pick it up because it's the most popular financial malware after SpyEye and Citadel.<p>What bank was this with? Did they cover the losses?<p>I'm assuming something like the following happened:<p><pre><code> Your friend → (direct) Mule in your country → (Western Union) to the criminal </code></pre> I tell my parents to use a linux Mint or Ubuntu live disk whenever they're banking online. It seems to have worked so far.
评论 #5733959 未加载
just_hobbyst将近 12 年前
It seems to me that using the same device to access banking website and receive SMS Tan is asking for trouble. If your smartphone is compromised you are toast. If you use 2 different devices than the hacker has to compromise both of them to get you.<p>My bank offers hardware tokens for authentication and I am glad to pay 1-2 additional euros a month for enhanced security.
gtani将近 12 年前
this is a good blog to follow: <a href="http://www.lightbluetouchpaper.org/category/banking-security/" rel="nofollow">http://www.lightbluetouchpaper.org/category/banking-security...</a>
anywherenotes将近 12 年前
instead of security app, I paid about $20 for a physical device from my bank. it seems more secure.