The $12,000 phone hack
There's a fascinating story today on Wired News about a new phone-phreak hack. Basically, it works like this:
Hackers locate someone who uses SBC voice-mail, but who's never changed his or her password from the basic default. Since default passwords are in a regularized format and easily guessed, the hackers can pretty easily break into their victim's voice mail. Then they change the outgoing message to say something like "yes, yes, I accept all long distance charges, yes, yes", with a few pauses in the middle.
Then the hackers place a long-distance call using AT&T's long-distance service. AT&T offers you the option of billing a long-distance call to a third party -- so long as that party answers the phone and agrees to accept the charges. And here's the catch: The AT&T system runs automatically, using voice-recognition software. So if a hacker places a call to Khazakstan, and gives the victim's number as the place to bill the call to, AT&T's little A.I. 'bot dutifully calls up the victim's number to check to see if they'll accept the charges. All it's doing is listening to make sure whoever picks up the phone says "yes". And bingo: Since the hackers have changed the voice mail to say "yes, yes, I accept all long-distance charges", the A.I. 'bot is fooled.
Wired found one woman who got dinged for a stratospheric $12,000 in long-distance. But AT&T won't let her get off. They reduced it to $8,000, but no more. And dig this:
"In the process of fighting this, I spoke to numerous people at AT&T and SBC. Not one sounded surprised when I told them about this scam," Runyon said. "I got the distinct impression that this scam is widespread and new victims are being exploited daily."
So AT&T knows about this, but still hasn't changed its incredibly dumb A.I. system. That's pretty remarkable -- because it wouldn't be that hard to do.
This is, after all, merely a reversal of the Turing Test. The original Turing Test was about whether a human could detect that a machine was a machine. In this case, the machine ought to be trying to detect whether it's talking to an actual, live human. Plenty of other companies have begun tackling this challenge. As I've written about in the past for Wired, Yahoo has implemented a very cool reverse Turing Test -- a test to prove whether the human is really human. And when I posted a while back about mobile-phone design, Franco wrote a comment that suggested an incredibly elegant reverse Turing Test that could be implemented over the phone:
You get a recording that asks you to pass some simple test, like dial a specific 2 digit number. However, the test is read by a stuttering drunk.
AT&T could easily do the same thing. Their 'bot could ask the question "do you accept these third-party long-distance charges" -- and then could get the person on the line to prove they're actually human, by asking a simple, random arithmetic question or something.
Not that anyone from AT&T is actually reading this blog, but if you are -- people, wake up! This stuff isn't hard to do. Thus, the fact that you're not doing it makes people suspicious that you just don't care about preventing fraud, so long as you can pass the buck.
Posted by Clive Thompson at April 17, 2003 06:17 PM
Trackback Pings
TrackBack URL for this entry: http://www.collisiondetection.net/mt3/mt-tb.cgi/308
Listed below are links to weblogs that reference The $12,000 phone hack:
Maybe the reason that the "people" at AT&T haven't donw this is that THEY aren't people. We should try the Turing test on them first.
Posted by: marc at April 17, 2003 8:40 PM
Posted by: Clive at April 17, 2003 11:31 PM
Hello this is the AT&T operator bot, you have been disconnected due to insulting me human.
Posted by: Real Estate Web Design at April 22, 2003 7:06 PM
Posted by: Clive at April 27, 2003 12:33 AM
I have been hacked for over $3,000 in charges Sprint says I owe. I am not paying them. I never accepted the calls. Never ever ever will they see a penny. Any suggestions on fighting to get the charges dropped and matter resolved as opposed to my company getting dinged on our credit rating and a collection agency coming after us?
Mike
Posted by: Mike at October 6, 2003 9:55 PM
Posted by: Online Casino at January 16, 2004 2:53 AM
Posted by: julia at January 24, 2004 8:47 PM
NICE SITE! YOU CAN FIND MORE IN GOOGLE.
Posted by: pocket bikes at February 7, 2005 7:36 PM
NICE SITE! YOU CAN FIND MORE IN GOOGLE.
Posted by: pocket bikes at February 7, 2005 8:07 PM
NICE SITE! YOU CAN FIND MORE IN GOOGLE.
Posted by: pocket bike at February 7, 2005 8:38 PM
Comments, on this topic are relevant and nice
Posted by: Wight loss at February 10, 2005 5:14 PM
I like getting emails from people I know, makes me feel better every morning
Posted by: Wight loss pill at February 10, 2005 5:22 PM
In your free time, check some information in the field of
Posted by: Anti aging at February 10, 2005 5:41 PM
people can take their favourite movies wherever they go.
Posted by: Dvd burner at March 7, 2005 8:41 PM
DVD\'s copy protection has been shot to pieces
Posted by: Burn DVD at March 7, 2005 8:46 PM
691 South Milpitas Boulevard, Milpitas, CA 95035
Posted by: DVD BURNER at March 7, 2005 8:52 PM
Releases Burn & Go Nitro CD/DVD Burning Software
Posted by: Burn dvd at March 7, 2005 8:59 PM
DVD\'s copy protection has been shot to pieces
Posted by: Burn dvd at March 7, 2005 9:04 PM
worldwide developer and publisher of interactive entertainment software
Posted by: Burn DVD Software at March 7, 2005 9:08 PM
This press release contains statements that are forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995.
Posted by: Dvd copying software at March 7, 2005 9:15 PM
DVD\'s copy protection has been shot to pieces
Posted by: CD DVD Duplication at March 7, 2005 9:21 PM
New features in version 5.0 include the ability to write to more than one recorder at the same time
Posted by: DVD copy at March 9, 2005 2:54 PM
Post a comment
Maybe the reason that the "people" at AT&T haven't donw this is that THEY aren't people. We should try the Turing test on them first.
Posted by: marc at April 17, 2003 8:40 PM
Ahahahahaha!
Posted by: Clive at April 17, 2003 11:31 PM
Hello this is the AT&T operator bot, you have been disconnected due to insulting me human.
Posted by: Real Estate Web Design at April 22, 2003 7:06 PM
The rise of the robots!
Posted by: Clive at April 27, 2003 12:33 AM
I have been hacked for over $3,000 in charges Sprint says I owe. I am not paying them. I never accepted the calls. Never ever ever will they see a penny. Any suggestions on fighting to get the charges dropped and matter resolved as opposed to my company getting dinged on our credit rating and a collection agency coming after us?
Mike
Posted by: Mike at October 6, 2003 9:55 PM
Nice site. thx.
Posted by: Online Casino at January 16, 2004 2:53 AM
Posted by: julia at January 24, 2004 8:47 PM
NICE SITE! YOU CAN FIND MORE IN GOOGLE.
Posted by: pocket bikes at February 7, 2005 7:36 PM
NICE SITE! YOU CAN FIND MORE IN GOOGLE.
Posted by: pocket bikes at February 7, 2005 8:07 PM
NICE SITE! YOU CAN FIND MORE IN GOOGLE.
Posted by: pocket bike at February 7, 2005 8:38 PM
Comments, on this topic are relevant and nice
Posted by: Wight loss at February 10, 2005 5:14 PM
I like getting emails from people I know, makes me feel better every morning
Posted by: Wight loss pill at February 10, 2005 5:22 PM
In your free time, check some information in the field of
Posted by: Anti aging at February 10, 2005 5:41 PM
people can take their favourite movies wherever they go.
Posted by: Dvd burner at March 7, 2005 8:41 PM
DVD\'s copy protection has been shot to pieces
Posted by: Burn DVD at March 7, 2005 8:46 PM
691 South Milpitas Boulevard, Milpitas, CA 95035
Posted by: DVD BURNER at March 7, 2005 8:52 PM
Releases Burn & Go Nitro CD/DVD Burning Software
Posted by: Burn dvd at March 7, 2005 8:59 PM
DVD\'s copy protection has been shot to pieces
Posted by: Burn dvd at March 7, 2005 9:04 PM
worldwide developer and publisher of interactive entertainment software
Posted by: Burn DVD Software at March 7, 2005 9:08 PM
This press release contains statements that are forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995.
Posted by: Dvd copying software at March 7, 2005 9:15 PM
DVD\'s copy protection has been shot to pieces
Posted by: CD DVD Duplication at March 7, 2005 9:21 PM
New features in version 5.0 include the ability to write to more than one recorder at the same time
Posted by: DVD copy at March 9, 2005 2:54 PM