Skip to content

Scam near-miss: the 'account verification' that wasn't

General Discussion by carlos2 29 replies 3.4K views
#11

In France we have a government service called Signal Spam that you can forward phishing to. I do not know if they do anything. I have forwarded forty Hetzner clones this year.

The best protection is still my bank's app refusing to let me authorize payments from desktop browsers. They force mobile confirmation for everything.

2 #12

Tanie serwery to moja pasja ale tanie to nie znaczy bezpieczne.

I use Contabo from Wrocław. Their email is so ugly that any clone looks better than the real thing. This is actually a security problem. Real Contabo mail looks like phishing, so users ignore the warnings.

I pay 4 EUR for VPS in Nuremberg. For this price I do not complain about email formatting.

#13
polskiegsm said:
Real Contabo mail looks like phishing, so users ignore the warnings.

This. So much this. I got a real Vultr abuse notice last month and almost deleted it because the formatting was worse than the fake Carlos got. Plain text, broken wrapping, no logo.

If these companies spent half as much on email design as phishers do, we would all be safer.

#14

Oh no~~~ very much true~~~

I get real email from my host in Vietnam, look very bad, same same scam email~~~ I do not know which is real~~~

Now I login only from bookmark, never from email link~~~ very safe~~~

But I want to know: Hetzner have datacenter in Vietnam? No? Only Germany and Finland and some place, no?

#15
minhdock said:
Hetzner have datacenter in Vietnam? No?

No. Falkenstein, Nuremberg, Helsinki, Ashburn, Hillsboro, Singapore. Singapore is the closest to you but latency will still be 30-40ms.

I run my stuff in Hillsboro for the privacy laws, not for ping.

not your keys, not your coins
#16

São Paulo here. Vultr has a datacenter here, which is why I use them. Hetzner does not. Contabo does not. Local latency matters when you are managing servers by SSH.

I have never gotten a phishing email pretending to be Vultr Brazil. Maybe the scammers do not know we exist.

#17

Vultr São Paulo is real but their routing to domestic ISPs is terrible. I get better latency to Miami sometimes. The datacenter exists on paper but the peering is lacking.

I use Vultr for the block storage API, not for compute in South America.

1 #18
carlos2 said:
Which providers take XMR for verification-resistant accounts?

Nobody good for compute. Njalla as you said. There is a reseller market where people rent servers and sublet for crypto, but you are trusting an individual with root on your box.

For inference workloads I run at home on consumer GPUs. No KYC, no phishing email, no datacenter. The power bill is the only tracking.

CUDA cores are my love language
8 #19

Following this thread. I got the same Hetzner clone last week, did not notice the domain mismatch because I was on mobile and the URL bar was hidden by the fullscreen phishing UI.

Mobile browsers are the real attack surface now. Chrome hides everything until you scroll. Safari too.

#20
pro10 said:
Mobile browsers are the real attack surface now.

This is why I use Firefox on Android with the URL bar fixed at top. No hiding. Also uBlock Origin works properly, which it does not on Safari.

The phishing sites also detect mobile and serve a different, simpler page that looks more "app-like" to bypass user suspicion.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft