News: 1591086551

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Contact-tracer spoofing is already happening – and it's dangerously simple to do

(2020/06/02)


British people will soon begin receiving random phone calls from so-called "contact tracers" warning them about having been in close proximity with potential coronavirus carriers. One of many problems with this scheme is it's dangerously easy to pose as a government contact tracer.

As detailed by the NHS, contact tracers will [1]phone up and text people who report coronavirus symptoms to the government and demand lots of personally identifiable information – including information on other people.

What safeguards are in place? Er, not many. They'll call from a published phone number – 0300 013 5000 – and, bizarrely given the context, UK.gov promises its hired call centre won't "disclose any of your personal or medical information to your contacts".

Such a scheme bears all the hallmarks of cold-calling scammers, and indeed [2]has already been used for [3]that exact purpose . More to the point: publishing a phone number really doesn't guarantee that the caller is who they claim to be.

[4]SMS and caller line identification (CLI) information is straightforward to spoof if you know how, and with UK.gov publishing the number its callers will be using, there's now an increased level of risk; for the non-technically-adept, a call coming from a published government number is more likely to be taken at face value.

'It's mostly just embarrassing' how easy it is

El Reg asked Jake Davis, one-time Lulzsec hacker turned security researcher, about SMS spoofing and the ease with which malicious people could impersonate UK.gov. He pointed us to [5]a blog post he wrote back in March when the British government [6]sent the entire nation a text message saying "Stay at home."

Addressing how straightforward it is, without explicitly linking to tools or guides on how it's done, Davis wrote: "In fact I'd say this is a schoolyard prank level of exploit, available to anyone and without requiring any technical prowess whatsoever.

"Outside of large hypothetical threats it's mostly just embarrassing. It's embarrassing that any random person who searches for 'SMS spoofing' can essentially become the UK government with no immediate way for the victim to tell the difference."

An example of such a phishing text – including a link to a decidedly non-gov.uk-site (don't visit it!) – is below.

Be warned that text messages like this one are already in circulation as the track & trace service launches. They are not genuine and anyone going to that website link will be asked to submit personal information that will then be used by fraudsters. [7]pic.twitter.com/P11vyuPVmr — Stuart Fuller (@theballisround) [8]May 28, 2020

Back in 2015 The Register wrote about a VoIP-based CLI spoofing service which – inevitably – [9]took payment in Bitcoin . It's still a problem to this day, and across the pond a group of US attorney-generals complained of 40 billion CLI-spoofed robocalls, automated phishing calls, being [10]targeted at US citizens over the previous 12 months . While methods have evolved in Blighty since 2015, the problem continues to plague the UK.

In a statement, RSA Security's Ben Tuckwell agreed, adding some basic security advice: "Consumers can protect themselves by acting smart and pausing to consider each communication they receive, while remembering the three key smishing don'ts – don't respond to texts from unknown or unusual numbers; don't click on any links in text messages; and don't share any banking information, usernames or passwords or other personal details after receiving a text message, unless you can verify who you are speaking with." ®

Bootnote

Davis's blog also includes a post about acquiring free beer through a [11]comically inept system of QR code-reliant vouchers. Again, don't try this at home.



[1] https://www.gov.uk/guidance/nhs-test-and-trace-how-it-works

[2] https://www.tradingstandards.uk/news-policy/news-room/2020/new-covid-19-app-exploited-by-fraudsters-to-scam-public

[3] https://www.ofcom.org.uk/about-ofcom/latest/features-and-news/coronavirus-scam-calls-and-texts

[4] https://www.ofcom.org.uk/about-ofcom/latest/features-and-news/coronavirus-scam-calls-and-texts

[5] https://www.jake-davis.com/post/uk-government-covid19-text-alert

[6] https://www.theregister.com/2020/03/24/uk_coronavirus_advice_texts/

[7] https://t.co/P11vyuPVmr

[8] https://twitter.com/theballisround/status/1265916723464634368?ref_src=twsrc%5Etfw

[9] https://www.theregister.com/2015/07/28/bitphone_caller_id_spoofing_bitcoin/

[10] https://www.theregister.com/2019/05/07/stop_robocall/

[11] https://www.jake-davis.com/post/acquiring-1-000-000-free-drinks

Scam callers coming out of lockdown

The commentard formerly known as Mister_C

We had two scam calls to the landline yesterday. First since lockdown started. Not Covid, just good old recorded scare message with "press 1 to talk to us".

The parasites are taking govt advice and returning to work.

Bastards

Re: Scam callers coming out of lockdown

Anonymous Coward

I'm getting calls from people claiming to be my investment advisors "working from home" .... maybe, maybe not.

Aspie73

1) my phone blocks numbers not in my contact list

2) the gsm standard does not guarantee SMS delivery. If I get one of these messages, legit or not, I'll not be putting my life on hold.

Flame away.

John Robson

So if you got a bomb threat in the post (also doesn't guarantee delivery, things do get lost) then you'll ignore it and go that that place at that time?

SMS is, whilst not guaranteed, sufficiently reliable to be a useful way of contacting people.

Wellyboot

Bomb threat? I'd call plod, then mostly ignore it, anyone in a 'special' job will follow the procedure they were given for these events.

Can we just assume scam and call the 0300-013-5000 number directly if contacted?

re: 1) my phone blocks numbers not in my contact list

Steve Davies 3

That is all well and good but how does your Doctor or the NHS in general get in contact with you?

They think that calling from a phone with 'Number witheld' is a good idea. They say that it is for data protection and privacy reasons. (eg if the call is to tell you that you have the 'clap')

They could impliment a solution but my guess is that they can't be bovvered to impliment it.

Perhaps you might like to think again about that rule given the current climate with CV-19

Roland6

>1) my phone blocks numbers not in my contact list

A few weeks back my home phone received a call, the CLI indicated the caller was my home phone...

OT - Did I miss something? 301 moved permanently??

Jonathan Richards 1

The URL https://www.theregister. co.uk /Week has asked to redirect to https://www.theregister. com /Week [emphases added]

When did that happen? The .com incarnation still needs permissions to go back to regmedia.co.uk, though. Wossallthatthen?

Re: OT - Did I miss something? 301 moved permanently??

Benchops

Indeed. I only noticed because my password manager refused to dish out the goods for this previously unknown domain. I expect it's one big elaborate phishing scam. They can have my reg account -- Reg lost all the passwords some years ago anyway so they know what to do ;)

Re: OT - Did I miss something? 301 moved permanently??

big_D

Same here. I started my work PC after my leave and the password manager said no passwords, wtf?

Looked at the pinned site and it was now showing .com. No warning, nothing. I did a quick check of the certificate, before logging back in.

Unhearing government

Lotaresco

I have been in the position of giving advice to UKGOV about the security implications of their interactions with the public. They even have copious documentation on the subject such as the [1]2012 Requirements for secure delivery of online public services . Although the focus there is more about how the government sets out to avoid being scammed by the public. Yet repeatedly when there's a "government initiative" they fall flat on their face and constantly try to engage the public in ways that look like phishing, smishing etc. I had an invitation to an InfoSec conference that I ignored because it had all the paw prints of spear phishing on it, sent from a non-UK hosted domain using a no-reply From: address, poor grammar and spelling, talked in vague and inaccurate terms about security, asked for advance registration through a poorly designed http-only site with a long questionnaire about personal details and also requests for the applicant to state their security clearance(s) and provide the details of a referee from a client.

It turned out to be genuine and from NCSC who had farmed the work of taking bookings out to a particularly clueless contractor.

The financial industry is better at providing contact details and extra information to verify that a communication is genuine. The Government Communications Service exists with the mission statement "Supporting ministers’ priorities, enabling effective operation of public services and improving people’s lives." Either it's not very good at its job or it's not consulted for these mass-communication efforts.

[1] https://www.gov.uk/government/publications/requirements-for-secure-delivery-of-online-public-services

Re: Unhearing government

jake

"from NCSC who had farmed the work of talking bollocks out to a particularly clueless contractor."

FTFY

Re: Unhearing government

TimMaher

Ever tried reporting a phishing site to NCSC?

Totally impossible and they don’t reply when asked how, exactly, to achieve it.

I won’t bore you with the details.

Fume, rant!

Re: Unhearing government

Commswonk

@Lotaresco: "Supporting ministers’ priorities, enabling effective operation of public services and improving people’s lives." Either it's not very good at its job or it's not consulted for these mass-communication efforts.

OR (and IMHO much more likely) data security and the minimisation of the risk to the public from contact - tracing based scams simply isn't a ministerial priority. Why would this application be an exception?

Anonymous Coward

I just don't understand why this is a thing, and why it can't be prevented, shut down, stamped on.

Persona

I just don't understand why this is a thing

Crime exists partially because it is easier than working. Crime is prevented, shut down, stamped on, yet it still persists.

iron

Even if the actual government contact tracers call, how are you supposed to answer their questions? During lockdown I've gone to a nearby shop 10 minutes walk away for food every 3 or 4 days, on some trips I came into contact with up to 90 people! I don't know who any of them are. Nor can I remember which days or at what times I made those trips. So all I would be able to tell the NHS is I've come into contact with hundreds of people in the last 2 weeks but I've no idea who, how, what, where or when it happened. Very useful I'm sure.

Once more we lead the world in being a total shambles. The whole thing is a fucking farce.

Christopher Reeve's Horse

I think it’s not the people you happen to have casually passed, but the people you’ve had a more meaningful and longer interaction with?

Commswonk

a more meaningful and longer interaction

Sounds very like some sort of euphemism to me. In which case "I should be so lucky..."

Here in the States ...

jake

... I've been receiving cold-calls from people purporting to be contact tracers for about two weeks now. I tell 'em to fuck off and hang up. I have no idea if they are legit or not, and quite frankly I don't care, either. If they need to talk to me, they have my address. And they'd best have some really, really good ID/credentials if they decide to show up here.

Re: Here in the States ...

Chris G

When I lived in the boonies in Nothern California, our credential checking equipment was supplied by a Mr Mossberg.

STIR/SHAKEN

Chewi

As someone who helped to implement the STIR/SHAKEN protocol to allow telcos to block robocalls, I was wondering why it wasn't extended to SMS, but apparently it's being looked into. I guess they figured it was less of a priority because it's arguably less annoying and SMS is falling out of use anyway.

Re: SMS falling out of use

Anonymous Coward

not amongst those who are ditching FartBook/Twitter etc it isn't.

SMS is the one thing you know that everyone with a phone has. You have no clue (unless they tell you) what a person's Social Media ID's are.

What are the odds?

IanRS

How likely is it that while reading an article on COVID-19 related spam or phishing calls, the phone rings? And it is a COVID-19 related phishing call?

Regardless of the odds, it happened.

Re: What are the odds?

Anonymous Coward

One in a million chance?

Re: What are the odds?

Evil Scot

About 90% then!!!!!

Jumping the gun a bit, aren't they ?

Pascal Monett

The UK contact tracing app has [1]just been made available and scammers are already on the hunt ?

It's a bit quick I think, and a lot of those calls must logically end in "but I don't have the app on my phone yet, so how did I get into your database ?".

Of course, there still is the obvious issue of users not engaging brains when getting a phone call, so maybe it's okay for the scammers.

[1] https://www.telegraph.co.uk/technology/2020/06/02/nhs-app-track-trace-coronavirus-when-how-download-uk/

Re: Jumping the gun a bit, aren't they ?

Anonymous Coward

At the moment the UK contact tracing is not using an app. You get diagnosed positive, you get phoned, you tell the tracers who your significant contacts were, tracers phone your contact and say 'please self isolate' but won't say who it was you were in contact with. So you could get a scam call.

Personally I'm not too worried, as if you are abiding by the recommendations you should know which mate you went to the pub lock-in with / significant other who popped around for afternoon delight etc, and you can just call them up and check if they are coughing.

But if spam calls didn't work that nice man from BT wouldn't have phoned 5 minutes ago to tell me about the 'suspicious activity on my line'......

Eh...

A. Lewis

If one calls me, the only person I'm going to say I've had any contact with is Dominic Cummings.

Re: Eh...

Anonymous Coward

if you really have then self-isolation is not enough. I recommend an acid wash, gargle a pint of dettol and say 24 hail-marys.

The government "shielding" calls for the vulnerable

Anonymous Coward

They also came across like a phone scam. The wife is officially in the high risk category and she passed me the phone when she got such a call. They wanted to take her through security by asking her some personal questions. As I said to the caller - "You called us, you could be absolutely anyone; so we need to take YOU through security." All I got was blather along the lines of "I assure you I am not a scammer" to which I replied "I assure you then that you've called the correct person and don't need personal information from us to verify who we are." We hung up in the end as they wouldn't budge. Even their claim that they are legit based upon the telephone number is bogus as scammers routinely spoof the number they are calling from.

osakajin

The government is not your friend.

This is not how security works

anthonyhegedus

I just got a text from 'UK_Gov' that said along the lines of "UK Gov National Shielding Service. Please expect a call from 03333 xxxxxx blah blah blah". We use a text message service for bulk texting some of our clients, and I tried to send myself a text with a 'from' of 'UK_Gov'. It didn't arrive. The service said it was delivered, so it must have been the carrier that blocked it.

So OK, that's *some* protection. At least one mobile provider blocked a spoof attempt at least once. I'm still not sure if they block spoofed phone calls. I could try, we have a service that used to let you do that for some reason, but I really don't want to.

I saw on TV in the last week, ministers and advisers have been asked twice how we'll know it's a genuine call. And twice they've said more or less the same thing, that it'll be obvious you're talking to a professional. Sorry, UK_GOV but that IS NOT HOW SECURITY WORKS!!

The ripest fruit falls first.
-- William Shakespeare, "Richard II"