
It appears there are scams circulating on Printables.
The well-known 3D model site is extremely popular and now holds millions of printable 3D models.
I’m reading a Reddit thread describing a peculiar situation that’s repeatedly occurring on Printables.
The scam goes something like this:
- Perps gain access to a legitimate Printables account.
- The account is used to send a private message to a number of other legitimate Printables accounts.
- The message pretends to be from Prusa Support and asks via a fake story for credit card information.
- Some accounts fall for the story and are thus scammed.
Sending private messages between Printables users seems like a reasonable function, since contributors might discuss models or other matters. It’s also a way to solidify the site as a proper community by generating social activity. So you don’t want to get rid of private messages entirely, just to solve the scammer problem.
In the Reddit thread, user yabluez proposes a solution:
“A limit is needed for the number of messages one user can send to different accounts per hour, to reduce this kind of scam.”
At first that might seem reasonable. But then there are probably legitimate reasons to send messages to larger groups of users. Consider a case where a designer has updated a complex 3D model and wants to notify all those who made it and provide new instructions. That is certainly one reason why you’d want to keep large-scale private messages.
Also, limiting the volume of messages does not eliminate the problem: it just happens on a smaller scale.
It seems that Prusa Research is doing nothing wrong here. Instead, it’s that Printables users are somehow losing control of their accounts.
This could be because they used the same password in multiple places: a compromised password from another site might work on Printables. That’s probably the most common scenario for hacking.
Another possibility is that the compromised Printables account was exposed by phishing, and that could be the first step to collecting all those juicy credit cards from unsuspecting Printables users. Get into one account, steal credit cards from other users.
Printables is only one of hundreds of sites that would have the same problem, because it’s not a problem with the site. It’s a problem with password security and trust. Variations of this situation could happen on any 3D model platform.
My recommendation is to always use a proper password manager for unique passwords on each site you make use of, and be very wary of anyone asking for important information. If so, confirm the request with the actual authorities on the site before doing anything else.
Via Reddit
