Fascinating article. I wonder if this is always true though:
> We consider a population of N users, which contains M viable targets. By viable we mean that these targets always yield a net profit of G when attacked, while non-viable targets yield nothing. Each attack costs C; thus attacking a non-viable target generates a loss of C
This supposes that the viability of targets is boolean: you're either gullible or you're not. But isn't it possible that targets' viability (or profit potential) is a function of the sophistication of the attack?
The sophistication of attacks increases in relation to expected payout. My aunt fell "victim" to one of these scams after winning the lottery. It started off with the standard spam, then when she responded the scammer became more personal, learned about her, and after the initial "investment" began an online romantic relationship with her.
After the family learned that she had given $250k to this guy, we stepped in and put a stop to it. She was embarrassed, and ashamed... and kept talking to him. We found out later that she had given him more money, after their "relationship" had continued for a number of months.
FTA, unsophisticated attacks select for unsophisticated targets. As the likelihood of a payday from a given target increases, so too does the sophistication until an equilibrium is reached and increased effort no longer yields increased rewards.
I believe it is a mistake to see the victims of cons as unsophisticated. Or rather, doing so makes one more susceptible to being taken - consider how Madoff operated.
I watched a coworker send money to Nigeria once for a Teacup Yorkie - $900 for a pedigreed dog including air transport seemed like proof of the victim's internet shopping savvy and unsolicited warnings from the workplace were ignored.
What was amazing was how well the scammer read the victim. The dog was to board a 10 am flight and arrive in ATL at 2:30. The email arrived at about 10:15 notifying the victim that another $400 was needed for customs but that the dog could still make the flight.
Two of us working hard managed to convince the victim not to send the money - I think that the possibility of a dog flying from Nigeria to a baggage carousel in Atlanta in three hours finally made it through the filter. But it was a close call.
The victim was a savvy college graduate with a good job which required a lot of responsibility and hard knuckle negotiations with contractors and vendors on a regular basis. The attacker was extremely sophisticated in their pitch. It's why the victim trusted them and didn't verify anything.
> I believe it is a mistake to see the victims of cons as unsophisticated. Or rather, doing so makes one more susceptible to being taken - consider how Madoff operated.
Exactly. There's so much social stigma attached to being a scam victim that it literally disables one of our defenses: self-doubt.
Gullibility is a game-theoretic state that you may wander in and out of as you play more "rounds," so it's actually quite hard to model.
Presumably it's possible to compile a statistic that factors in all the game-theoretic elements, so that on a per-attack basis the population can be assumed static like this, even if actual targets are changing over time.
Further on in the article, they talk about statistic x. They explain that it is variable, but that the boolean model represents a worse case scenario where all gullible people buy in.
> We consider a population of N users, which contains M viable targets. By viable we mean that these targets always yield a net profit of G when attacked, while non-viable targets yield nothing. Each attack costs C; thus attacking a non-viable target generates a loss of C
This supposes that the viability of targets is boolean: you're either gullible or you're not. But isn't it possible that targets' viability (or profit potential) is a function of the sophistication of the attack?