if there is one thing i have _never_ done to my parents, or _anyone_ for that matter, is make fun of them if they call me and ask me for my professional opinion in tech matters. this has extended to situations when they think the situation is shoddy like they are being taken in a scam. i think _this_ is the single reason why my parents have never fell victim to scams. i feel that _most_ parents, or elderly people for that matter, fall victim cause they feel pressure from both ends... the first being the scammers themselves, the second being scared to ask _anyone_ if the situation is legit for fear of being made fun of.
_noone_ should feel scared of being ridicule when asking any question regarding their safety or well-being.
2. Set their phone to send everything to voicemail that isn't a contact. Many scams don't leave one & if they do it can be discussed with appropriate people first.
3. Install a browser like Brave or extensions that block most garbage on the internet.
4. Setup their important files & pictures to be backed up automatically to one or more cloud services.
5. Not related to tech scammers, but more the ransom scammers or your grandchild needs money scammers - Always have some type of secret agreed upon phrases or questions that no one would ever know or be able to find out. Even better, make it a question someone could easily search for but have a ridiculous answer that is an inside joke between the two of you.
6. (Geek Bonus) - Enjoy watching social engineering videos together! They're entertaining, informative & I personally think more enjoyable than most of the stuff that passes for movies, sports & TV shows. Ok, this last one is probably not for everyone.
She got a fake virus alert on some skeezy website, and she immediately called the number, without checking with me.
They tried to talk her through enabling remote access so they could get in and do whatever horrible thing they intended, but they had to get her to identify her IP address and type a few commands first.
She tried going back and forth from the telephone to the computer in another room, and the scammer finally got angry and screamed at her, "can't you borrow a cellphone from one of your neighbours?" When she told him she couldn't, the man just hurled obscenities and hung up.
These guys really depend upon you being able to talk to them while typing and clicking.
No tech company these days will ever call a customer, especially not Microsoft.
If you do receive a call from a more traditional institution like a bank, don't divulge any information. All banks have strong identity theft protections in place, but you haven't authenticated the caller. Ask for a reference id so that you can call the company back using a phone number that you yourself looked up on their company web page.
If the caller has any reason not to comply (and they will have plenty of reasons why they can't), or they insist you use a number that they provide, hang up and forget about it.
That being said, getting my parents from Windows to Mac was to biggest ROI. Before, with Windows and even Malware Bytes Anti-Malware, I had to literally drive home hours for emergency tech support.
However, I’ve educated them against popup clicking now so much that they pointedly ignore Mac update popup notifications. Oh well, it is what it is. And what it is is much better now in Mac land.
We've moved them to all Apple devices. Locked down everything (the account on the Mac is "standard" not Administrator level). Set up a G Suite account with restricted access (cannot install apps, cannot install extensions into Chrome). Use 1Password for passwords, 2FA for all accounts that allow it. Removed Flash early on, removed Java runtime. Turned off auto–update on the Mac and iPhone/iPad.
I initially tried parental controls on the Mac but found it was a nightmare for even their limited use of apps outside of Chrome.
Still after 10+ years of “training” this person to call me for any technical issues I get surprises like yesterday when they wanted to install an “ad blocker that keeps popping up in Chrome”, which was, of course, malware.
Probably will ditch the Mac and switch to a Chromebook later this year.
Passwords are as private as the most embarrassing thing you can imagine. Never give them out to anyone. Ever.
No financial institution will randomly call you unless its a fraud alert. Even then, ask to call back and then call the company using their direct number to verify. Anyone trying to keep you on the line is suspect. You have a right to hang up at any time.
Treat your email address like your home address. Would you randomly give your home address to strangers?
Phone numbers are so easy to fake you could do it on your cell phone. Do not trust caller ID.
If in doubt call your children.
And I do get a lot of calls about everything but I'm glad my mother calls to verify instead of taking a chance. So many older parents stay in parental mode when their children are well into adulthood and tend to trust their judgement before their children's. That or they don't want to bother them or even admit they know less. Hubris and ignorance are the problem.
I think there's probably two prongs of attack. Helping them manage their IT and Scam prevention. Scam prevention covers cold calls "from your bank", random letters in the post, people knocking on the door etc. IT competence is supplementary and confidence here helps prevent the former. e.g. If you've installed every toolbar offered to your browser, then a) You shouldn't be in charge of a browser and b) Are more likely to need the help of MS when they call.
Things I've done, in no particular order:
Offered to be their IT support. If in doubt over anything, please call me first. I don't mind, it's how I can be helpful and show gratitude. If I've called them, I've normally got free time, so good time to ask if there's anything they want me to look at whilst I'm here.
Added their machines to my Google One Backup (or whatever your backup solution of choice is with an online family plan). I've tried leaving them with USB drives to plug in and local backup scheduled, but never seems to work out.
Accept some people shouldn't own a PC. Chromebook/ipad provide most of what they need and are relatively sheltered.
Push them towards online services for say email. Yes, they might be used to Thunderbird that you initially set them up with - but de-corrupting local storage, missing emails from that time they accidentally used POP, hooking in AV, anti-spam etc etc. Gmail (or your provider of preference) handles that for you (and you can just use thunderbird with that if you insist - and it will grab mails from that ISP account you mysteriously are attached to).
Education. Quite surprisingly my PC-cautious relative (never messes up, but refuses to embrace) decided to take a "Computer Driving License" course. I was slightly disparaging to be honest, but she found it interesting - and started realizing what she could do. e.g. Address book previously a txt file (kept on a USB stick for security, naturally), made the switch to Excel and mail-merged the envelopes for the Christmas letter.
I've also noticed that installing adblock helps, since there's less shady stuff to click.
- I buy them Apple devices. n=4 here, but it really seems when my family (mom, father-in-law, mother-in-law, and older brother who is borderline tech illiterate) made the switch from Android to iOS devices or even PC to Mac, they just had less of an issue with this. It's anecdotal, I am not a diehard Apple fanboy, but take it for what it is.
- I tell them to always close any and all popups. Point blank, carte blanche, doesn't matter how sincere it seems, or if it even is legitimate, just close it. If there's something she ends up not being able to do eventually she just calls me.
My rules for them: 1. If someone calls you from the bank, hang up and call them back from their phone number listed on their website. 2. If a pop-up comes up warning for viruses, call me immediately. 3. If a pop-up comes up warning about governments coming for you, call me immediately. 4. No one on Earth is going to try to give you money for free online.
I've had to answer plenty of calls about online bullshit, but I prefer that than having to try to deal with the Bank after they get scammed.
Recently featured on ProductHunt: https://www.producthunt.com/posts/phonescreen
Their website: https://www.phonescreen.co
"Can you come here the computer/phone/ipad is saying something, have I been hacked"
- no, it's telling you that you have an email, no it's telling you that you are getting a call, no that's your other son asking you a question...
"How do I save something again"
- you've been working with computers longer than I've been alive... click the save button "where" the disk "where" or go to file save "where is file" points "I don't see it" my finger is touching it!!!
- Are you ^(!@#$@ kidding me
- Look at your paper, you've written this down three times
"How do I save something to my zip disk"
- You don't have a zip disk, you have a usb drive or a thumb drive, you've never had a zip disk, I've never had a zip disk, zip disks were stupid and still are and I don't understand why Amazon has them for sale for so much!
"can you print this for me at work"
- no, I've told you this 37 times, go to FedEx office with your usb drive, I'm not printing 173 pages of whatever that is and risk getting fired
I promise you, it's all a con. There's no way she doesn't know exactly what she's doing and just likes messing with me. I've showed her how to turn the volume up and down on her iPhone at least 100 times. You've got 3 buttons, figure it out mom! I swear I'm going to have a stroke or a heart attack one of these days while showing her how to do something for the 97th time.
My brother on the other hand... when he still lived close it felt like every other week I was reinstalling windows for him. He'd torrent everything, click any link, open ever attachment... eventually I just blocked obscene numbers of domains and ran him through a 'family safe' DNS filter. I don't know what he does now, I guess his teenage step son has to suffer through helping him.
This is an obvious scam, but for people who aren't up on this and fearful of "the man" I expect these kinds of scams work for every 1 in 100k people at best and are still probably lucrative enough for them to keep going.
The answer for the OP problem and the Canadian problem are the same: the government never calls you, Microsoft never calls you, no tech company will ever call you.
https://www.aarp.org/money/scams-fraud/
877-908-3360
AARP puts serious resources into scam prevention. Print the hotline number and tape it up next to their screens and/or land-line phones.
Obviously this doesn't protect them against the complete set of problems but it is quick to implement and keeps me from being the personal security manager of those I care about.
At the end of the day if someone is running a sophisticated phishing scam some savvy people are going to fall for it - I think the name of the game is damage mitigation not prevention. As long as you can mitigate people from losing a life changing amount of money I think you've won here.
I have installed ChromeOS on her laptop, uBlock in Chrome, set router DNS to my own (which filters out spam, malware, ads etc.).
Set an iPhone option to accept only calls from Contacts. I am also going through call lists periodically and block marketing calls etc.
I have also cut the cord on land line.
https://github.com/StevenBlack/hosts
Disclosure: there are many like it, but this one's mine.
1. Never provide anyone any information on a call you receive. If you receive a call, go wit the expectations that it is a scam/spam. If it seems genuine, you call them back using a number from their website. Don't call back on a number provided by the caller.
2. Don't pick up unknown numbers.Let them leave a voicemail.
3. Most Govt. orgs or banks will not call you to request personal information over phone at least in the United States.
4. There are common scams/spams including Windows/Tech Support, IRS, You have won a vacation scam etc. Don't ever believe those. They are always a scam.
5. Never ever click/download a link/attachment on an email that you are not sure about.
6. Teach everyone how to read email headers if possible to verify the sender. It is too easy to spoof the from name/email. Fun fact: my wife recently received emails from ME (obviously not) asking her to wire money for some urgent need. lol. But she almost fell for it and I was shocked. The reason was email spoofing. I immediately showed her how to check the headers.
Most importantly, teach your parents or other non tech savvy friends/family to never trust anyone over the phone or email even if it seems like someone they know. Always be suspicious. It is ok to do so.
Oh and as the tax season approaches, the IRS scammers will be out in full force. Make sure that everyone knows IRS NEVER CALLS you especially to ask for money. IRS will always send you a registered letter in mail, always.
I happen to be known as a nice sysadmin and therefore people call me so I got a number of stories.
Many of my older friends and relatives are somewhat immune as their technical English just isn't good enough.
I find the persons who call are mostly 25-35 year olds (I had one older acquaintance who taught highly technical subjects at university level who installed various cleaners that were clearly scams to me but I'll leave him out and focus on the telephone tech support scams.)
Most of the cases we've managed to stop somehow. The one were I didn't manage to stop it in time or get the money back was actually a young accountant who got his personal checkings account emptied.
One thing I've noticed is that several of the people who fall for it are surprisingly smart.
In the last case I interviewed the victim for 20 minutes afterwards and what shook me was how she had no recollection of anything between the start of the call and when she was pulling out her second credit card.
This suggests to me that the best scammers are kind of good with something NLP-line or something.
(FTR: I do also pretend to be a victim everytime they call me both to annoy them for my own entertainment and to learn what they do so I have a fair idea of the first part of the scam.)
Inter-networking computers is fraught with danger: criminals are attacking your loved ones.
I think it's time for a reboot of the Internet.
The one we have now looks like Disney Land but acts like a back alley in a bad part of Bangkok (apologies to residents of that city, I mean no disrespect.)
I removed the Flash player from her machine some time ago, because it now seems to be completely obsolete. (I liked Flash in its day, but it's time has passed.)
AARP still requires Flash for one of its online "Safe Driver" courses. So my mom followed the advice in an AARP User Forum and, of course, got a adware malware installed in her browser.
No matter how many times I tell her to never install _anything_ she'll still wants to prove that she is capable of doing things and gets viruses/malware.
She also gets confused by Google ads. She wanted to add AT&T minutes to her pay-as-you-go phone, searched, and clicked on an ad for a third party minutes reseller (which was filled with AT&T logos) and bought it there. It wasn't such a bad deal, but when she calls me about a message she's getting on her flip phone and mentions company names I've never heard of, I can't help her.
The criminals who prey on the elderly using tech scams (I just need your credit card number to deposit the funds) use the same emotional cons and tactics as those who prey on kids (can you help me find my lost puppy) and they ought to be handled the same.
I've found the best way to address this is to deflect the request. Give me your phone number and I'll call you back or let's report the lost puppy to that policeman over there. And, also practice con-like scenarios. Make a game out of it.
If there's really an issue with your device/account/whatever, you'll know about it.
No legitimate business will threaten and cut you off if you don't do what they're asking right now. Your bank wants your business. They won't just cut you off because you didn't verify your social security number. A legitimate institution will bend over backwards to let you make things right, eventually. Not threaten you right now.
But really, being savvy with tech scams is just being savvy with society in general. So the usual anti-aging, keeping your body and brain active advice apply here as well as anywhere.
Otherwise, he basically tells every "seller" to eff off so he probably wouldn't be scammed anyway.
I understand that’s not an option for everyone. But no amount of education, new devices, etc are going to solve this issue past a certain age/cognitive decline.
Has a lovely web interface too.
I wouldn't be surprised if there's a blocklist for scams to be included directly as well.
1. Don't act immediately (no matter how urgent matter seems to be).
2. When in doubt, check with someone you trust (and first reaction should be 'doubt').
Beyond that, any of following are worthy of being flagged as scam automatically -
1. Call/email from IRS or any other government agency
2. Easy money offers
3. (unfortunately) Anyone asking for help, specifically involving money, that too urgently
4. Anyone asking for password, SSN, financial record acess
Bottomline is that in online world, start point should be doubt followed by questions which help build your trust.
In addition: their passwords are all shared with me so that when they die or become otherwise incapable I can still manage their affairs.
I started this practice when my stepfather got a fraudulent email pretending to be from me, claiming that I had been arrested in a foreign country and needed him to send a few thousand dollars. He called me, as he was confused about why I left the country without telling anyone, and I straightened him out.
[0]https://www.youtube.com/channel/UCBNG0osIBAprVcZZ3ic84vw/vid...
I recently got a PC for my youngest because some games he wants to play around't available on OSX. I was amazed, virtually every site and app is constantly trying to trick him into signing up, downloading, or changing security settings. PC's are bad news.
Maybe NLP will get to the point that an automated answering service would pass for human, and screen callers effectively and cheaply.
It's 2020 and the "Personal Computer" paradigm is past its expiration date.
Want to keep hobbying with Windows and manage your "PC" like a pet, good luck with that!
Hardware should be managed like cattle with a cloud native setup if you ask me.
Racehorse owners loose 90 cent on every dollar invested, cowboys fly helicopters.
a couple of weeks ago, so I told them to call me before they make any technical purchase/decision.
Still worried though when their SIM cards got cloned. (banks use cell OTP for 2fa)
Workes as a universal solution. Don’t remember where I learned it.
No one asks for your credit card numbers through phone. Every one has a payment gateway now a days
Get a Logitech external keyboard for it.
I'm not just talking tech scammers. It's just harder to "mess up" the ipad for anyone.
Is there a cellphone equivalent?
Or an easy-to-manage whitelist?
Not a primary solution, but definitely a secondary safeguard.