Solved A good amount of money has been stolen from my bank account bypassing the double factor authentication.

Since you don't have access to the OS guts you really don't know what was deleted. Once installed assume infection. Worse case scenario.
This is like assuming that every new lock sold is going to be picked because the Swiss government actually provides state-sponsored lock-picking classes as part of standard education curriculum.
 
Yeah, and if you don't actually take those strides, you'll be robbed blind of that very money.

I have a question to ask. Again, specifying that the attacker disabled the bank's Android app from my phone and he activated it on his phone, if instead of authorizing the payment via app, I had set up a biometric fingerprint, would the attacker still have been able to withdraw the money without my consent ?
 
Again, specifying that the attacker disabled the bank's Android app from my phone and he activated it on his phone
For starters, if the phone number on file with the bank is not yours - that is a problem. This is why you should keep your eyes peeled and make sure the details on your profile are correct, and make corrections ASAP. And yeah, that's on you. Yeah, it needs to be done from time to time.

If the bank's phone app does offer a biometric fingerprint authentication - I think it may be worth trying out. That kind of stuff usually requires very nice and expensive phones, the kind that retail for $800 USD and up for just the device. And it takes some time to set up correctly.

Even then, you gotta be careful with the phone, don't give out personal details unless you absolutely have to. Even good locks are useless if you are tricked into giving out keys to miscreants.
 
You know,I clicked on that email when I was already logged inside the bank,so I've been very unlucky,and for the attacker has been easier to intercept the credentials.
this is 100% your fault, you have acted quite carelessly. It's like you left your car keys at the bar in a restaurant to go to the toilet and then complain someone stole your car.
 
this is 100% your fault, you have acted quite carelessly. It's like you left your car keys at the bar in a restaurant to go to the toilet and then complain someone stole your car.

I disagree partially with you. As I said before, the fact that I *unknowingly* clicked on a fake link doesn't erase the theft I suffered, nor the fact that the bank has a low level of security. Or rather, in my opinion, they could, if they want, have a higher level of security and better protect customers who, like me, have been deceived and robbed. If they don't, it's because they have to invest more money to improve it. Thus, the unbridgeable contradiction inherent in how the capitalistic society works today, arises. Investments aren't always aimed at serving the interests of customers. They only do so IF their own interests are protected first. In short, the two types of interests don't always coincide. This logic reminds me a lot the Adam Smith's economic theory, that's wrong,as explained in the movie "A Beautiful Mind" with Russell Crowe, a movie that talks about the games theory. I want to propose you to give a look at this little piece of the movie,to understand what I mean :

View: https://www.youtube.com/watch?v=otXcQfzLC5M
 
I disagree partially with you. As I said before, the fact that I *unknowingly* clicked on a fake link doesn't erase the theft I suffered, nor the fact that the bank has a low level of security. Or rather, in my opinion, they could, if they want, have a higher level of security and better protect customers who, like me, have been deceived and robbed. If they don't, it's because they have to invest more money to improve it. Thus, the unbridgeable contradiction inherent in how the capitalistic society works today, arises. Investments aren't always aimed at serving the interests of customers. They only do so IF their own interests are protected first. In short, the two types of interests don't always coincide. This logic reminds me a lot the Adam Smith's economic theory, that's wrong,as explained in the movie "A Beautiful Mind" with Russell Crowe, a movie that talks about the games theory. I want to propose you to give a look at this little piece of the movie,to understand what I mean :

View: https://www.youtube.com/watch?v=otXcQfzLC5M
What you are continuously fail to understand is the fact that there is no protection against yourself. This is 100% your fault, and your fault only.
 
I'm sad for your excessive tendency to blame yourself and feel overly responsible. I believe that maintaining a bit of self-love, especially when you make mistakes, helps you get through them without feeling overly overwhelmed and helps you make fewer mistakes later. If, on the other hand, you demand a sort of perfectionism, as you are asking of yourself, well, I believe this is not very positive for those who demand so much to themselves. After all, we are not perfect. We can all make mistakes. To avoid repeating them, it is important to reflect on the emotions we feel and the ones others would like us to feel. Emotions that are too focused on guilt undermine mental clarity. I am struggling not to feel overwhelmed by your harsh and uncompromising judgments.
 
I'm sad for your excessive tendency to blame yourself and feel overly responsible. I believe that maintaining a bit of self-love, especially when you make mistakes, helps you get through them without feeling overly overwhelmed and helps you make fewer mistakes later. If, on the other hand, you demand a sort of perfectionism, as you are asking of yourself, well, I believe this is not very positive for those who demand so much to themselves. After all, we are not perfect. We can all make mistakes. To avoid repeating them, it is important to reflect on the emotions we feel and the ones others would like us to feel. Emotions that are too focused on guilt undermine mental clarity. I am struggling not to feel overwhelmed by your harsh and uncompromising judgments.
This sounds like its written by AI, but ill bite anyway. Me, as well as everyone else in this thread, dont want to sugar coat it for you. Why ? Because we dont want you to get scammed again. It is simple as that. If these people dint care, they would not bother replying. Keep that in mind.
 
Paranoia at breakfast, lunch and dinner ?

Tor Security Alert

Hi, I am a cybersecurity researcher, investigative journalist, and whistleblower female.

I have studied networking, network security, cybersecurity, privacy and anonymity principles, and similar topics for over 10 years.

I became an investigative journalist then whistleblower to investigate crimes committed by various government persons.

I used Tor to leak information implicating various governments persons in various crimes.

I believe Tor was infiltrated and compromised, a backdoored was added, or Tor was made easier to trace, or similar, because I have survived a targeted assassination attempt. This was not a random occurrence, and not a theory, it was a confirmed, via laboratory analysis, an assassination attempt by criminal government agents to target a hero whistleblower human-rights defender in a covert assassination attempt.

We should not just do anything the Government asks just because of their title "the government", because sometimes real genuine bad criminals can be in government positions. We must respect the individual rights of each user, by ensuring the Tor software is fully secure.

I believe the criminals in the various governments, compromised Tor via bribing a Tor Dev, or making an excuse like "national security" or any other list of government talking points to compromise it, and the criminals added a backdoor, or made Tor easier to trace in some manner. So then, the criminals in the various governments, could identify me, locate me, and assassinate a hero whistleblower in a targeted manner.

If they could find me they could find any Tor user. I changed my writing style, had a firewall, fully updated system firmware and software, used a new operating system installation on new hardware, on public wifi etc to prevent side-channel exploits.

Thus I believe the vulnerability was within Tor itself.

Thus, I conclude various steps need to occur to re-secure Tor.

1. We must conduct a top-to-bottom/comprehensive code security audit for all of Tor Browser and Tor Relays code. We must find, patch, and secure any vulnerabilities, weaknesses, or backdoors and re-secure the Tor code.

2. We should introduce additional traffic-analysis resistance measures into Tor, such as circuit padding for all connections/more connections, random connection delays like iat-mode=1/2 for all connections, and possibly decoy traffic. I also think having a Snowflake-add-on-like option to make every Tor user a small relay would enhance traffic-analysis resistance.

Tor says it can't defend well against a global network observer. But we do have global network observers in the world, which we should build defenses against.

We also need to ensure the code is fully open source, because corrupted government agents can try to make excuses to compromise Tor and use their badge and title to try to compromise the network. The corrupt government persons could stage events to make Tor look bad to try to justify compromising it. We must have Tor be immune to such suggestions, by being outside of the reach of any corrupt governments influence.

If Tor is un-saveable, we should start a new Tor-like software, outside of the reach of any and all governments influence on a private island or small country or territory without any influence over our decision making.

We can start another, several new anonymity projects outside of the US, Canada, France, Germany, UK, NZ, AU. Away and immune from governments influence.

The criminals became donors of Linux kernel and Tor and other privacy projects and used their donor status to try to weaken the security. Beware any donors involved in c0v1d-19 contact tracing or similar topics. Beware donors who came in around 2019+. Thus we must check for and patch security vulnerabilities in Linux, Tor, and other privacy services.

Thus, in order to ensure Tor and every Tor user is safe and secure, we must never degrade, backdoor, weaken, or make more easily traceable, any aspect of Tors code. Tor must be fully secure, non-backdoored, private, secure, and anonymous for all Tor users benefit, as journalists, human rights defenders, and whistleblowers working for the common good, depend on Tor for their safety.

We should setup more relays in diverse locations/datacentres. We should reformat and re-install Tor relays to clear infections/exploits that might be currently running. We should enhance Tor Relays security by for example using a Firewall, HTTPS update servers, and perhaps additional hardening, and Intrusion Detection Systems like Snort and Suricata to detect exploit-like behavior, to secure the relays operating systems.

We should accelerate the codebase transition to Rust to be more exploit resistant.

We must keep Tor secure, for every user, we must check all of Tors entire codebase and re-secure it. For the benefit of every privacy-loving netizen,

Re-secure Tor,
With Love.
 
This sounds like its written by AI, but ill bite anyway. Me, as well as everyone else in this thread, dont want to sugar coat it for you. Why ? Because we dont want you to get scammed again. It is simple as that. If these people dint care, they would not bother replying. Keep that in mind.

no AI. It's my own work with some help from Google Translate. I'm not a native English writer / speaker. Sorry.
 
This sounds like its written by AI, but ill bite anyway. Me, as well as everyone else in this thread, dont want to sugar coat it for you. Why ? Because we dont want you to get scammed again. It is simple as that. If these people dint care, they would not bother replying. Keep that in mind.

I know that you want to genuinely help me. I say a very nice thank you to everyone for this. But the point that I wanted to focus my energy was different. I just wanted to encourage you to reflect to the consequences that can be felt, both for you and others, when ideas (correct in principle) can almost become a form of self-hatred because you didn't do enough to prevent the worst. As I repeat, spreading such intransigent judgments, which leaves no room for mitigating circumstances, can lead to feelings of guilt, and when excessive, this clouds reason's clarity. Because when you are in this mental scenario you have troubles to forgive yourself. And forgiveness is important for starting over.
 
I know that you want to genuinely help me. I say a very nice thank you to everyone for this. But the point that I wanted to focus my energy was different. I just wanted to encourage you to reflect to the consequences that can be felt, both for you and others, when ideas (correct in principle) can almost become a form of self-hatred because you didn't do enough to prevent the worst. As I repeat, spreading such intransigent judgments, which leaves no room for mitigating circumstances, can lead to feelings of guilt, and when excessive, this clouds reason's clarity. Because when you are in this mental scenario you have troubles to forgive yourself. And forgiveness is important for starting over.
You should not be so emotional about all this. Instead, try understanding technical stuff that everyone was pointing out in this thread. This will help you to never make same mistake again. Remember this. Security ALWAYS starts with you. There are no mechanisms that can protect you against yourself. Never sacrifice security for convenience. Use password managers, use security keys. Always inspect email headers and the links in your emails. Never save passwords and cookies for your banking stuff. Use separate browser for banking, and configure it to clean history and cookies as soon as you close it. Always log out ouf your banking session. Same rules apply for your phone. Dont install applications you dont need. Dont install games or any uneccessary garbage on your phone. Dont click random links. Never give your phone to anyone. Including your kids. If you must use public wifi, always use vpn. Do not use public charging ports or charging cables that are not yours. Same goes for charges and laptops. Unless they are yours, avoid them. Always keep in mind, bank has zero responsibility. Even when they are fully responsible. They are scumbags, there is no arguing with them, you cant win. Stay safe and take it easy.
 
Paranoia at breakfast, lunch and dinner ?
this is a serious question: do you seriously believe this email??? And then you clicked on some random link? Whoever accuses an open source project to be infiltrated should at least provide evidence, because, well, the source is out there and there is nothing easier to verify such bold claims.
 
Whoever accuses an open source project to be infiltrated should at least provide evidence, because, well, the source is out there and there is nothing easier to verify such bold claims.
Until you read about the University of Minnesota Linux Kernel debacle. Even Open Source is not immune to miscreants creating a mess. This is why you gotta keep your eyes peeled for signs of trouble no matter where you are.

Paranoia at breakfast, lunch and dinner can be exhausting, but yeah, there are people who actually do that for fun, and know a lot about it.
 
Until you read about the University of Minnesota Linux Kernel debacle. Even Open Source is not immune to miscreants creating a mess. This is why you gotta keep your eyes peeled for signs of trouble no matter where you are.

Paranoia at breakfast, lunch and dinner can be exhausting, but yeah, there are people who actually do that for fun, and know a lot about it.
It seem like XZ scandal passed unnoticed by some people.
 
I consider all operating systems compromised. Except the hobby projects.
Heck, we even have CPU backdoors nowadays.

And never forget
and

Operating systems are a battle field. If you need privacy, be offline.
 
this is a serious question: do you seriously believe this email??? And then you clicked on some random link? Whoever accuses an open source project to be infiltrated should at least provide evidence, because, well, the source is out there and there is nothing easier to verify such bold claims.

I don't know what to think about that. But I'm very curious to read what you think.
 
You should not be so emotional about all this. Instead, try understanding technical stuff that everyone was pointing out in this thread. This will help you to never make same mistake again. Remember this. Security ALWAYS starts with you.

I'm not so self centered. In my vision,security should start and end with us. I mean,it should be a common problem and threated as a social problem. I mean,responsability is mine for sure for what concerns how I keep secure my system,but it is also of the webmasters,app creators,system admins and so on,concerning how much energy,competence,money they put to secure their systems. If you just want to hold me accountable, you're forgetting that there's a world out there made up of people, organizations, and institutions who also need to be held accountable. And many of them are reading or will read this.
 
Back
Top