Live data from Hacker News

We Got Phished

exploratorium.edu

1–10 of 156 posts

Re: We Got Phished

#2
It's worth nothing the new user-image-before-password-input for Google is an anti-phishing feature. Of course, most people won't think that deeply when prompted with a password request and a similar UI.

Re: We Got Phished

#3
Many people won't check the url when signing in if everything looks to be on the up and up. This is why I really liked one of the things Yahoo did which was create a sign-in seal. Every time you signed in Yahoo would display a custom image that you set and if that image wasn't there then something was probably wrong.

Re: We Got Phished

#7
We also got hit by this a few months back. It also got send to all of your company's contact. We had to mail all of them back and lost face.

One hour in or so Google made it so that the emails (even those already received and opened) were blocked. It helped to mitigate the issue. Most of the outside contact that would have received the mail received it in their spam.

We learned from it and have better security now.

Re: We Got Phished

#8

Many people won't check the url when signing in if everything looks to be on the up and up. This is why I really liked one of the things Yahoo did which was create a sign-in seal. Every time you signed in Yahoo would display a custom image that you set and if that image wasn't there then something was probably wrong.

Here's some more info on that: http://security.stackexchange.com/questions/19155/effectiven...

Re: We Got Phished

#9

2-factor would have prevented this - no ?

Yep. This same phishing attack reached our office a few months back - it was a good motivating force for the whole office to enable 2FA. Probably an overall net positive for the company :)

Re: We Got Phished

#10
This article seems great at describing how phishing actually works in practice, especially to people without much exposure to technology. I've gone through at least a couple of training emails from IT departments about phishing, and this was way more effective. A realistic case-study with a really clear description is valuable!

This article could definitely augment the anti-phishing education at your organization—the only downside is that it's a bit long, so busy people probably won't want to read it :/.

Post reply on HN