My suggestion to solve SMS scam problem

  • Have you been Scammed?
    Follow this advisory from National Crime Prevention Council (NCPC) or call ScamShield Helpline 1799. More info

GoodBetterBest

Supremacy Member
Joined
Jan 23, 2019
Messages
6,236
Reaction score
2,119
I have a suggestion. I'm not sure if it will solve the problem. I just bounce it off here. See if anyone has the expertise to develop it.

One of the issues is that the user get a scam message and click on the link. Even if the banks don't send SMS with link, scammer might. In anycase, we shouldn't be licking on the links in SMS whether it comes from the banks or elsewhere.

Why not develop a SMS app that does not allow the user to click on the link ? And get the people to switch over. For mobile phone sold by telco, they can actually install it on the phone sold through them. Or may be IMDA will enforce phone sold in Singapore not allow to have SMS app that you can click on the link.

I don't have the expertise to develop this. May be somebody here might be interested.
 

davidktw

Arch-Supremacy Member
Joined
Apr 15, 2010
Messages
13,550
Reaction score
1,301
I have a suggestion. I'm not sure if it will solve the problem. I just bounce it off here. See if anyone has the expertise to develop it.

One of the issues is that the user get a scam message and click on the link. Even if the banks don't send SMS with link, scammer might. In anycase, we shouldn't be licking on the links in SMS whether it comes from the banks or elsewhere.

Why not develop a SMS app that does not allow the user to click on the link ? And get the people to switch over. For mobile phone sold by telco, they can actually install it on the phone sold through them. Or may be IMDA will enforce phone sold in Singapore not allow to have SMS app that you can click on the link.

I don't have the expertise to develop this. May be somebody here might be interested.

Apply this to emails, prevent links on email too? Scammers also scam thru emails.

It can be effective, but too draconian. The fault is not with sms, it’s onus is ultimately still on the end-users.

SMS is still a very affordable communication tool for a lot of purposes, not just limited to financial use. Going the way you proposed would first heavily limit the interaction and increase the cost of all other usages that may depend on links to create usage flows continuations. Not all services that depend on using SMS have the right budget to twist their way around having SMS limiting the use of hyperlinks.

For financial institutions, first they can heavily promote the use of mobile apps of their own. The app stores do have certain control which can prohibit using of app names that resemble legitimate institutions. All notifications will only be sent thru their mobile apps, but this will obviously at this point of time only tackle iOS and Android apps for best coverage.

Of course end-users will still need to be aware and be vigilant.

:)
 

GoodBetterBest

Supremacy Member
Joined
Jan 23, 2019
Messages
6,236
Reaction score
2,119
Apply this to emails, prevent links on email too? Scammers also scam thru emails.

It can be effective, but too draconian. The fault is not with sms, it’s onus is ultimately still on the end-users.

SMS is still a very affordable communication tool for a lot of purposes, not just limited to financial use. Going the way you proposed would first heavily limit the interaction and increase the cost of all other usages that may depend on links to create usage flows continuations. Not all services that depend on using SMS have the right budget to twist their way around having SMS limiting the use of hyperlinks.

For financial institutions, first they can heavily promote the use of mobile apps of their own. The app stores do have certain control which can prohibit using of app names that resemble legitimate institutions. All notifications will only be sent thru their mobile apps, but this will obviously at this point of time only tackle iOS and Android apps for best coverage.

Of course end-users will still need to be aware and be vigilant.

:)

David, thank you for your feedback. Two responses:

1. Emails and SMS are of different nature. Currently, I think Singapore usage of SMSs are going down. Most people uses Whatsapp, not that SMS are not useful.

Attacks comes from all angles, not SMS/Emails alone. We may not have a all-in-one solution but we can certainly block off threats from certain directions. That would help. Then scammers have fewer avenues and we can focus more on those avenues that are still open. We may also have another solution for email, in fact, we do: Anti-virus. Email scamming can be prevented / reduced by anti-virus. If we can get the anti-virus companies to build for SMS, then it would also be a potential solution, though I have doubts over the currency of their threats database, esp when Singapore has such a small user based compared to the rest of the world.

2. As for the suggestion that Telco/IMDA enforce this solution is a secondary suggestion. Primarily, my idea is there be a SMS app that does not allow people to click the links on it. The option is for the user to make that choice, esp for people who seldom use SMS except for banking, online purchase, OTP, etc, ie people who had already switched to Whatsapp/Telegram for their communications.

Applying the idea that security is about risks, conveniences & probabilities, and not absolutes, if everybody switches over to such an SMS app, the probability of scamming through SMS links is reduced to zero and if not, then the probability is "inversely" proportional to the number of uptakes.

I really do hope to see such a SMS app on the market. I hope somebody here values this idea and develop such a SMS app. It may not benefit technical people that much considering if they are very security savy, but certainly will help our elderlies who tend to be less on guard and has the greatest to lose.
 

davidktw

Arch-Supremacy Member
Joined
Apr 15, 2010
Messages
13,550
Reaction score
1,301
David, thank you for your feedback. Two responses:

1. Emails and SMS are of different nature. Currently, I think Singapore usage of SMSs are going down. Most people uses Whatsapp, not that SMS are not useful.

Attacks comes from all angles, not SMS/Emails alone. We may not have a all-in-one solution but we can certainly block off threats from certain directions. That would help. Then scammers have fewer avenues and we can focus more on those avenues that are still open. We may also have another solution for email, in fact, we do: Anti-virus. Email scamming can be prevented / reduced by anti-virus. If we can get the anti-virus companies to build for SMS, then it would also be a potential solution, though I have doubts over the currency of their threats database, esp when Singapore has such a small user based compared to the rest of the world.

2. As for the suggestion that Telco/IMDA enforce this solution is a secondary suggestion. Primarily, my idea is there be a SMS app that does not allow people to click the links on it. The option is for the user to make that choice, esp for people who seldom use SMS except for banking, online purchase, OTP, etc, ie people who had already switched to Whatsapp/Telegram for their communications.

Applying the idea that security is about risks, conveniences & probabilities, and not absolutes, if everybody switches over to such an SMS app, the probability of scamming through SMS links is reduced to zero and if not, then the probability is "inversely" proportional to the number of uptakes.

I really do hope to see such a SMS app on the market. I hope somebody here values this idea and develop such a SMS app. It may not benefit technical people that much considering if they are very security savy, but certainly will help our elderlies who tend to be less on guard and has the greatest to lose.

I don’t recognise SMS and Email are of different nature in this context. They are communication tools to reach out to the users. Therefore for the effort you are going through to block certain things or so call provide protection. It is like blocking the front door but letting the back door wide open. Since you identify that SMS usage are going down, then this quest won’t be commercially sensible either. You have even pointed out theta are Whatsapp, Telegram, and other such messaging applications. So again your SMS is merely a small window compared to other more obvious entrances to your house. Putting a padlock there is not effective from my POV.

Of course you are free to venture. So all the best to your idea.

:)
 

GoodBetterBest

Supremacy Member
Joined
Jan 23, 2019
Messages
6,236
Reaction score
2,119
I don’t recognise SMS and Email are of different nature in this context. They are communication tools to reach out to the users. Therefore for the effort you are going through to block certain things or so call provide protection. It is like blocking the front door but letting the back door wide open. Since you identify that SMS usage are going down, then this quest won’t be commercially sensible either. You have even pointed out theta are Whatsapp, Telegram, and other such messaging applications. So again your SMS is merely a small window compared to other more obvious entrances to your house. Putting a padlock there is not effective from my POV.

Of course you are free to venture. So all the best to your idea.

:)

Side issue. Could you quote me a foolproof security solution to solve all weakness at once ? Like I've said.. security is about risks, conveniences & probabilities, and not absolutes.

Yes, I'm just passing on the idea. I don't develop mobile apps myself, so have no ability to deliver it. I just drop an idea here, see if anyone wants to pick it up and try it out. I guess if we already had such a SMS app, then the OCBC scam won't have happened... well may be other scams... then have close off the loopholes one by one.
 

davidktw

Arch-Supremacy Member
Joined
Apr 15, 2010
Messages
13,550
Reaction score
1,301
Side issue. Could you quote me a foolproof security solution to solve all weakness at once ? Like I've said.. security is about risks, conveniences & probabilities, and not absolutes.

Yes, I'm just passing on the idea. I don't develop mobile apps myself, so have no ability to deliver it. I just drop an idea here, see if anyone wants to pick it up and try it out. I guess if we already had such a SMS app, then the OCBC scam won't have happened... well may be other scams... then have close off the loopholes one by one.

There is no foolproof security solution. I don’t think I have suggested there is. The most holistic one is *Education*.

You have your view, I have mine. If you don’t like what I have said, feel free to ignore it.

:)
 

peterchan75

Supremacy Member
Joined
Apr 26, 2003
Messages
6,757
Reaction score
533
App that delete SMS with url link, loan, soccer betting is very much welcome.
I was so hopeful that telcos will remove SMS with url link. My hope was dashed when one SMS with url link appeared. :mad: Any app to exterminate these pesky SMS ?
 

GoodBetterBest

Supremacy Member
Joined
Jan 23, 2019
Messages
6,236
Reaction score
2,119
App that delete SMS with url link, loan, soccer betting is very much welcome.
I was so hopeful that telcos will remove SMS with url link. My hope was dashed when one SMS with url link appeared. :mad: Any app to exterminate these pesky SMS ?

my phone can detect spams thought it probably wont work in OCBC case.
I'm thinking of turning url link to text so it becomes un-clickable.
 

wolfrage89

Junior Member
Joined
Apr 30, 2012
Messages
14
Reaction score
1
I think telecos should assign "static" phone numbers to banks so the source of the sms can be verified. For the bank side, OTP request should be tag with the action the user wants to perform. for example," as per your request to <transfer money of XXXX>, this is the <OTP>"
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top