Live data from Hacker News

Out-Of-Office Messages Are a Security Risk

lonesysadmin.net

1–10 of 93 posts

Re: Out-Of-Office Messages Are a Security Risk

#3
post #2

Or you just check the box that says "only send to people at my organization".

What if you are working mainly with customers? BTW, the article says: > Set the autoresponse to the smallest group possible. In many cases you can narrow it down to coworkers, and/or have a different message for people inside your organization than outside your organization.

Re: Out-Of-Office Messages Are a Security Risk

#4
post #3
post #2

Or you just check the box that says "only send to people at my organization".

What if you are working mainly with customers? BTW, the article says: > Set the autoresponse to the smallest group possible. In many cases you can narrow it down to coworkers, and/or have a different message for people inside your organization than outside your organization.

[deleted]

Re: Out-Of-Office Messages Are a Security Risk

#7
As always with security the first thing to ask is "What is your threat model?"

This person's threat model seems to be people who email him for a legitimate business reason, but see that he's away & take the opportunity to attack him? I just don't buy it - I think there is nothing wrong with always setting an autoresponder.

Re: Out-Of-Office Messages Are a Security Risk

#8
post #7

As always with security the first thing to ask is "What is your threat model?" This person's threat model seems to be people who email him for a legitimate business reason, but see that he's away & take the opportunity to attack him? I just don't buy it - I think there is nothing wrong with always setting an autoresponder.

I think the point is that autoresponders will autorespond to legitimate business emails as well as phishing/scam/whatever other emails.

Re: Out-Of-Office Messages Are a Security Risk

#9
post #7

As always with security the first thing to ask is "What is your threat model?" This person's threat model seems to be people who email him for a legitimate business reason, but see that he's away & take the opportunity to attack him? I just don't buy it - I think there is nothing wrong with always setting an autoresponder.

Yeah, this is a stretch...

I'm getting pretty tired of this kind of thing. It's pretty clear to me that the infosec industry (within appsec and netsec at least, not risk and compliance) is bifurcated into two distinct groups. The first group consists of people who have real technical expertise, find serious vulnerabilities and make concrete suggestions about legitimate issues.

The second group, and the one I see more and more often (especially in bug bounties), consists of people who find ridiculous "security" "risks" in all manner of things. They're not appsec or netsec people but they think they're identifying actual security issues. Sometimes they point out superfluous implementation issues but more often than not they're writing articles like this - nitpicking the design of a thing without clarifying their threat model and with only a vague grounding in the potential risk of compromise.

I mean did we really need a security PSA about the risk of email autoresponders? Come on.

Re: Out-Of-Office Messages Are a Security Risk

#10
post #2

Or you just check the box that says "only send to people at my organization".

Or, you could have a system that only responds this way to e-mails to which you had already responded in the past.

But why? At that point I might as well turn off the feature...I can't know everyone who will try to get in touch with me while I'm out of the office. If I could, I'd just tell those people ahead of time. If someone tries to reach me for something unanticipated and I've never responded to them before, they won't receive a notification.

This "threat" is a fugazzi. Honestly I can't believe this hit the front page of HN. What a ridiculous "security risk."

Post reply on HN