Recovering From A Bank Hack

One of the downsides of technology is that it makes it easier for bad people in distant lands to do bad things. A couple of years ago we got hacked and learned some good security lessons as a result. They might help you avoid finding yourself in a similar situation.

The Backstory:

A couple of years ago, my mobile phone number and Chrissy’s mobile phone number were both fraudulently ported to another carrier – meaning somebody set up fake accounts with a phone carrier in our names, then requested that new carrier transfer our numbers over from our existing carrier. This is known as “number portability” and was set up years ago to make it easy for people to change service providers. Of course when they did that, nobody foresaw the day when mobile numbers would be used as authentication for bank accounts, etc. All they needed to provide to port our numbers was our mobile number, name, DOB and address. Pretty easy information to get, especially if they have access to your Facebook profile, etc. The number gets ported over to the new carrier within minutes and our phones were left with “SOS Only”. No signal. No carrier. If you’re lucky, you get a SMS message just before it happens. Chrissy got one – I didn’t. But it wouldn’t have mattered anyway, because we were camping and didn’t have much reception.

Once the hackers have access to your phone number, then any account where you have 2-factor authentication (2FA) connected to that number (eg bank accounts, email accounts, Dropbox, any cloud service) can be lost minutes later. The process is simple. They try to login to your online account (which requires them to know your email address or bank account number) – and check the “Forgot Password” box. That generates a six digit code which is sent to the mobile number as a text. They enter that number online and then create a new password. They can also change the email address on the account, the security questions, etc. And, of course, empty the bank accounts – which is what they did to us.

They also took over a couple of my email accounts which, of course, they use to try to find out things like your bank account number, family details (birthdays, names, passport numbers, etc). All of which they can use for further identity theft. All of this took a few minutes from start to finish.

Fortunately we got our money back quickly (although I had to play hardball with the bank). We also got our mobile numbers back, that took a few days. And with those I could retrieve the lost email accounts.

So that’s how it happens. Here’s what I did afterwards to try to prevent it happening again.

  1. Remove my public mobile number from all forms of 2FA.
  2. Where possible, use a physical security token for 2FA for things like bank accounts. I set up new accounts with a new bank, got tokens on our accounts, and locked the accounts down so the token is required for every login. It means always having the token on my person but that’s a small price to pay.
  3. Where a physical token isn’t possible, try to use a Time-based One-Time Password algorithm (TOTP) authentication app, like Google Authenticator. It works for Gmail, Dropbox, Evernote, Stripe, Facebook, Twitter, PayPal, etc. You need to provide a six digit code for every login and that code is provided the app on your phone (not the mobile number on the phone). An alternative is something like Yubikey, a USB-based physical token but support for Yubikey isn’t widespread yet.
  4. Where I can’t use a physical token or GA, I have set up a separate, totally secret mobile number. It’s on a SIM card which is sitting in an old iPhone 4 I had lying around which surprisingly still works. It’s only purpose now is to receive 2FA texts. The number will never be made public and therefore should be difficult to fraudulently port.

Hope you find that useful. I highly recommend setting something like this up. ID Fraud is apparently a lot larger (and easier) than I previously understood.

Do you think Trump is a psychopath?

As part of World Psychopath Day, we’re taking a poll on how many people think Donald Trump might be a psychopath.

Of course, this doesn’t suggest he *is* clinically diagnosed as a psychopath, it’s just a measure of public opinion.

And don’t forget to buy a copy of my new book The Psychopath Epidemic, out now!

DEAR CLIMATE CHANGE DENIALIST

I’m sure we’ve all seen some pretty dumb ass posts from Australians about our role in climate change over the last week. Just reading their arguments makes me think maybe climate change is a GOOD thing – not because their arguments hold any water, but because once we’re all dead, I won’t have to listen to their stupid shit any longer. These people are even dumber than anti-vaxxers.

But as an act of public service, I provide for you this rebuttal you can feel free to copy and paste, with or without attribution, as often as you like.

DEAR CLIMATE CHANGE DENIALIST:

First of all, stop pretending you have any respect for science. You don’t. Here’s how I know – people who respect science, listen to scientists. Not the fringe dwelling kind living under a bridge somewhere, but the consensus of scientists working in a field. Yes yes, we all understand that scientists on the fringes sometimes have good ideas – that is, in fact, how science works. But just because an idea is on the fringe doesn’t mean it’s correct. Before we accept it as being correct, it has to first be vetted by the majority of the scientists working in the field.

And the vast majority of climate scientists say your arguments about climate change are stupid. And you aren’t listening to them. So shut the fuck up and stop pretending that you give a shit about science. Fuck me sideways.

Second – we all know the human contribution to CO2 is small. And if you had paid ANY attention to the scientists, you would know that our small contribution is too much for the planet to handle. It’s like filling a bathtub to the brim with water… and then adding a small amount. The atmosphere is now, thanks to humans, overflowing with CO2. And that “small” amount has enormous consequences to life on this planet. It’s like if the overflowing bathtub was sitting on a live wire and you are standing on the floor beside it. But how did I get electrocuted? I ONLY ADDED A SMALL AMOUNT. How come you people are too stupid to STILL not know this? Fuck me sideways again.

Third – as for Australia’s contribution to CO2 levels, yes, it’s relatively small, because we have a relatively small population. But we’re also one of the largest producers of CO2 per capita. We are only 0.3% of the world’s population, yet we’re produce 1.1% of the CO2. The argument “oh we’re so small so it doesn’t matter what we do” is simply psychopathic. It’s like saying “I only committed 1% of the murders last year out of the total number of murders, so what does it matter?” If you had been around in the 1930s, I’m sure you’d be saying “we’re such a small country, what can we do about Hitler?” Fuck me sideways. You people. Listen – some Australians think we, as a nation, have a responsibility to be ethical. We aren’t great inventors – Australia didn’t invent the iPhone or Facebook – but we are a highly educated people with a lot of advantages. We’re fairly rich per capita and we have a pretty good life compared to most people on the planet. We also are the one of the world’s largest producers of coal, you know, that stuff that produces a lot of CO2. We also have a large coastline and lots of sun, hot rocks and wind that could be used to generate LOTS of green energy. So maybe we should try to pull our weight. And if we aren’t out there leading the world, showing them how it’s done, standing up and being counted, being as proud of ourselves as innovators on the climate change front as we were when we nailed a secret fin to a fucking sailboat, then we are part of the problem. YOU are part of the problem. And FUCK YOU for being that. Psychopaths.

Fourth – don’t fucking talk to me about the economic affects of trying to do something about climate change, you stupid fucking cunt. Just what do you think the fucking economic impact of the decline of coal as an export is going to be? Or the economic impact of rising temperatures and rising sea levels? Our current bushfires are NOTHING compared to what’s coming down the pipe. What is the cost of complete ecological collapse going to be? Coastlines under water. Farming completely fucked. Tourism fucked. The air and water will be fucked. How the fuck do you think the economy is going to work when we’re all fighting over the vehicle Max passed two days ago that could haul that tanker? Oh wait, you probably think you’re going to be Humungus in this scenario. But in reality you’re already proving yourself to be Toadie, Humungus’ sycophantic suck-ass. You’re already sucking on the engorged, dripping cock of the Murdoch press, so you won’t need to learn any new skills.

Fifth – you ask what could Australia’s government have done to prevent all of this? For a start, they could have taken the Garnaut report seriously. Then they could have tried to act like world leaders, not a bunch of numbnuts, sticking their heads in the sand. They could have helped the country prepare for the increasing heat and drought that Garnaut successfully predicted – you know, investing in fire-fighting and water infrastructure, that kind of stuff, instead of spending all of their energy trying to stop five people and a blind dog from getting into the country on a boat. They could have been ringing the alarm bells, at home and around the world, fighting the good fight against psychopathic behaviour from people like Trump, Murdoch and the fossil fuel industry. But they didn’t. Moron after moron has sat in the PM’s chair and done nothing, absolutely nothing, to prepare this country for the coming storm. Instead they have sucked on Murdoch’s dick. It must be getting crowded in Murdoch’s pants.

You’re embarrassing yourself. And you’re embarrassing us as a nation, because people are watching to see what we do. And you are making us all look like the deformed love children of Pauline Hanson and David Icke.

So please – do us all a favour and shut the fuck up.

Boeing Goes Boing

Who gets fired after running a company whose products lead to the death of 346 people and still walks away a $62 million payout?

This guy does.

Talk about getting bounced.

I would argue that this kind of corporate behaviour is an example of a potentially psychopathic corporate culture. It is rewarding the wrong kind of people and the wrong kind of decisions. And yet it is all too common.

Most ordinary people would be too embarrassed to accept a $62 million payout under any circumstances, let alone circumstances like this. It’s not like this guy cured fucking cancer.

Psychopaths In The Military

What’s worse than your garden variety white collar psychopath? A psychopath trained and armed with the most sophisticated killing tools devised by humans. This Seal Team 7 platoon leader’s colleagues have accused him of being a psychopath:

In the leaked video interviews, SEAL Team 7 members described seeing Gallagher targeting civilians, including a 12-year-old child, and fatally stabbing a wounded captive with a hunting knife.

Despite the complaints of his own team members, a military jury acquitted him of murder and he got to meet Trump.

America Doesn’t Give A Fuck About Democracy

The current situation between Iraq and the US is quite revealing. In 2003, when the US illegally invaded Iraq, it initially pretended it was doing so to protect the world from Saddam Hussein’s WMD. When it became clear that he never had any WMD (as many Iraq analysts had already been saying before the invasion), the US pivoted to argue they were invading to remove Saddam and bring the gift of democracy to the Iraqi people.

Now we see the democratically-elected government of Iraq requesting the US remove all of its troops from their country – and the US is flatly refusing. We can infer from this that the US has no respect for democracy, or the government of Iraq or the Iraqi people or, by extension, any other government or people whose interests are in disagreement with those of the United States.

In essence, the US is forcing its military presence upon the Iraqi people – again. I’m pretty sure that’s tantamount to a declaration of war. But this time, there is no Saddam, no WMD mirage. The US’ interests are laid bare. They want a military presence in the world’s third oil-producing nations and they don’t give a flying fuck what the Iraq people think about it. And they don’t give a flying fuck about democracy, either. That’s always been a ruse.

Do you know what kind of person doesn’t care about the rights of others? Psychopaths.

When the government of a country doesn’t care about the rights of others, it is a psychopathic government.

Protecting Whistleblowers

In the book I praise whistleblowers who are prepared to expose the psychopathic behaviours of their employers and colleagues, knowingly putting themselves at risk – physically, emotionally and financially.

Actively working to spread misinformation about climate change is psychopathic behaviour. This News Corp employee deserves praise and respect and I would love to find a way where society can rally to support people like her.

And, of course, it’s difficult for most of us to understand why more News Corp employees don’t speak out about their employer’s support for climate denialism. I actually quote statistics in the book comparing News Corp’s coverage of climate issues to other Australian papers.

A 2013 study of major Australian newspapers by the Australian Centre for Independent Journalism at the University of Technology in Sydney found that one-third of articles in 2011 and 2012 did not accept the consensus of climate scientists. The study found that Australia’s two most prominent newspapers by circulation, the Daily Telegraph and the Herald Sun (both, unsurprisingly, owned by Rupert Murdoch’s News Corporation), published articles that were skeptical about anthropogenic climate change more than 60 percent of the time.

The Psychopath Epidemic, page 188

What we need to understand, however, is that people who work at places like News Corp have gone through several filters. They had to get through a hiring filter to work there. Then, if they don’t fit into the culture one they have a job, eg if they question too many things, or can’t accept the dominant culture, they either get filtered out (eg fired) or they filter themselves out (eg resign, like the woman in the above story did). The only people left are those that believe… or don’t care.

Cameron Reilly's Psychopath Hunters

If you want to receive updates on my efforts to put together a global force of psychopath hunters, as well as news about my books, films, podcasts, public appearances or notification of my ultimate demise, please sign up to this newsletter.