I missed two: the "allow some random person to read your email" which I would never click on, and the one that had a PDF, even though they don't allow you to do anything with it. Just because someone sends you a PDF doesn't mean it's an attack vector. It would have been more helpful to say something like "this is someone you do business with as well, or someone you've never heard of." (which I find to be more useful…
Google Phishing Quiz
21–30 of 103 posts
Re: Google Phishing Quiz
#22Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now
Re: Google Phishing Quiz
#23Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now
The inclusion of that one kinda baffled me. No way for me to tell whether the app that's connecting would be one I'd want reading emails (I wasn't familiar with it) and without an address bar, hard to tell if it's a spoof or the real thing.
If I accidentally clicked on a link in my email and it brought that page up, could you call it phishing?
Also the email from the person with the PDF. Like, why is that phishing? What if I trusted the sender? People send pdfs all the time. are there no secure ways to read pdfs?
Re: Google Phishing Quiz
#24While the domain is a legit Google domain, I find it ironic that it’s hosted on “withgoogle.com”. If my parents followed my anti-phishing tips they would fail by clicking this link.
Re: Google Phishing Quiz
#25Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now
Re: Google Phishing Quiz
#26---
1) "Hey there. Here is the doc you asked for."
Did you ask for a doc? Do you know this person? If no, these facts alone should be giant warning signs.
---
2) Fax Message from efacks.com
Do you have an account with this service, where you explicitly signed up to receive faxes? If not, obviously you shouldn't be getting faxes from them so it's not legitimate.
---
5) "Please find attached the 2019 financial activity report for your perusal."
Aside from giving away the answer in the title [1], this isn't a good example.
First line of defense, once again: Do you have an account with "Westmount Day School", and are you expecting a "financial activity report"?
Also, spoofing "from" e-mail addresses is a thing, and completely trivial, so relying on that is not a way to verify authenticity.
What's not mentioned is being aware of what PDF reader you're using: eg, do you regularly make sure it's up to date? Personally, I use Chrome as my PDF reader as I'm not a fan of Adobe products or their security track record in general.
Also in my experience, these types of e-mails often come in with an attachment like "2019 F.A.R.pdf.exe" (or a zip file that contains an exe), and not an actual PDF file. This would have been a great way to train users on this point.
---
6) "Someone has your password"
The two reasons that this isn't legitimate are listed as "We don't use google.support to send emails" and "This link points to a subdomain of ml-security.org, not Google." [2]
So once again, spoofing "from" addresses is trivial -- so that is not a security measure. Secondly, how should I know what mail comes from? There was an earlier example of a legitimate message from Dropbox coming from a non-dropbox.com address (dropboxmail.com).
Also, the best defense against this is not mentioned: Never log into sites by clicking on links in e-mails! This includes changing your password. The only exception to this is a password reset mail when you explicitly just asked for a password reset.
---
7) "Government-backed attackers may be trying to steal your password"
Once again, "Change password" link in e-mail. Don't click it.
---
8) Tripit Security prompt [3]
Sorry, but this is a terrible example.
First of all, am I trying to perform some action with Tripit that this prompt is expected? If no, don't allow (in fact, just close the window)
Secondly, what does my browser window show? If you're on google.com (or gmail.com) and this appears, that's one thing, but if your browser is showing google.security-check.se then no, don't click anything and just close the window.
Third, even assuming this is all okay, do you want Tripit to have access to view email messages and settings? If all you were trying to do is use your Google account to authenticate, the fact it wants access to view all your messages is highly suspicious. In this particular case (because it's Tripit, a service that parses your email), this is probably your intention, but if it also asked for other permissions -- such as ability to manage contacts and send messages on your behalf -- you might want to think twice.
---
Training like this is good, but phishing e-mails can be very devious and training users on the wrong things -- such as trusting "from" addresses, not considering context, and not looking at actual attachment types -- is extremely dangerous. In the worst case, it can train users to click on things they otherwise wouldn't have, due to false confidence obtained by (inadequate) training.
[1] https://i.imgur.com/8mNePZS.png
Re: Google Phishing Quiz
#27I missed two: the "allow some random person to read your email" which I would never click on, and the one that had a PDF, even though they don't allow you to do anything with it. Just because someone sends you a PDF doesn't mean it's an attack vector. It would have been more helpful to say something like "this is someone you do business with as well, or someone you've never heard of." (which I find to be more useful…
Also, assuming that a message is phishing is usually not harmful in any way. If I got an email from dropbox.com (and were a Dropbox customer), I'd ignore the email, and just type "dropbox.com" in my web browser to see what's up. If you're paranoid, you don't need to be super smart about what exactly is phishing.
This isn't a fair test.
Re: Google Phishing Quiz
#28Re: Google Phishing Quiz
#29 Incorrect! Not everything is bad.
I think that is mistaken.Re: Google Phishing Quiz
#30I posted this here because I think it's great there's some effort being put into free training in this region.
I do however agree with some of the comments here. I had been hunting for something like this to use as our own training, but it won't be this because I don't agree with the TripIt example.
Edit: Maybe there should be a "maybe" or "consider" answer. "This is a legitimate company. However, their desire to access your email is something you should carefully consider".