Skip to content

Comment on Measuring the impact of AI scams on the elderly

Comments

You don't need this, just say you're John from Microsoft as Jim Browning has shown

Seriously.

To pretend that you need the advanced capabilities of an AI in order to trick older people by email is somewhere between ludicrous and clickbait.

My father in law just bought a car online this weekend on accident. And nobody was even trying to trick him.

There's a reason the Nigerian prince type stories are so low effort: you really don't need much more sophistication than that.

You agree that AI is used for amplification by attackers? they interviewed people who had worked at scam factories who clarified that they used LLMs in their work.

I do, of course. My point is that it is neither a tool unique to this scam nor an application of the tool that is particularly surprising.

In other words, if I can be a little histrionic, it seems to me like saying "using ELECTRICITY to scam old people".

To pretend that you need the advanced capabilities of an AI in order to trick older people by email is somewhere between ludicrous and clickbait.

The trick is being able to do it, on a convincingly personalized level, to a million old people at the same time.

How do you buy a car by accident? Like, put in a credit card and fully paid for one on Carvana or something?

Very good guess: it was actually exactly that. Carvana shopping for a used car.

He clicked on something and got charged the downpayment of the car to his CC. He got his money back, but I'll never not be surprised by what some older people can manage to do online left to their own devices.

To you and I, it seems impossible. For Larry, it's just Saturday.

It does not seem impossible to anyone who has watched someone use a computer for a few minutes... A bright green button from google pay saying "click here to secure your interest in this car" is easily mistaken to mean "save to my interested list" rather than "place a deposit on this".

We know how hard it is to even find the download button on a website: https://www.howtogeek.com/how-to-spot-the-real-download-butt...

You're right

We like to pretend that we are immune to that, but we've all made similar mistakes.

And there's an entire Internet of websites trying to trick us.

It's sad, but you need to browse almost any site assuming the company is an adversary. I register my domains through two decent registrars but I recently needed to help a client through using GoDaddy and NetSol. The up-sells and cajoling were relentless, vile and eye-opening.

To be fair, Amazon one click purchases got me once. The principle that no one button should cause a "dangerous" action (i.e. one where you can't escape or undo it easily, and especially with money and data) is sometimes violated when the action is only "dangerous" to the user and beneficial to the provider.

Usually the result of clicking such a "dangerous" button is the user gives the provider money or data. It's not common that the provider makes it easy to one-click-no-confirm a process that gives the user money or the provider's data.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.