Live data from Hacker News

Out-Of-Office Messages Are a Security Risk

lonesysadmin.net

11–20 of 93 posts

Re: Out-Of-Office Messages Are a Security Risk

#11
post #7

As always with security the first thing to ask is "What is your threat model?" This person's threat model seems to be people who email him for a legitimate business reason, but see that he's away & take the opportunity to attack him? I just don't buy it - I think there is nothing wrong with always setting an autoresponder.

I think the point is that autoresponders will autorespond to legitimate business emails as well as phishing/scam/whatever other emails.

So the attacker gets autoresponse. What's next? What is the attack vector here?

UPD: also, I guess any attacker could just assume that you're Out of Office at night time.

Re: Out-Of-Office Messages Are a Security Risk

#12
post #7

As always with security the first thing to ask is "What is your threat model?" This person's threat model seems to be people who email him for a legitimate business reason, but see that he's away & take the opportunity to attack him? I just don't buy it - I think there is nothing wrong with always setting an autoresponder.

I think the point is that autoresponders will autorespond to legitimate business emails as well as phishing/scam/whatever other emails.

Not all of them do. Gmail can be set to only respond to people who you've had contact with before.

Re: Out-Of-Office Messages Are a Security Risk

#13
post #11

Earlier quoted context omitted.

I think the point is that autoresponders will autorespond to legitimate business emails as well as phishing/scam/whatever other emails.

So the attacker gets autoresponse. What's next? What is the attack vector here? UPD: also, I guess any attacker could just assume that you're Out of Office at night time.

EDIT: To be clear, I don't think this is a serious threat whatsoever, and went through the exercise as an explanation. Go easy on my comments, just having fun thinking it through.

Impersonate the person out of town to escalate to their privilege level.

Imposter: "My password isn't working, can you help me reset it?" Yes, this is unlikely to to work in smaller orgs where you know people face to face. It is more likely to work as the org scales up in size (think enterprises with their own helpdesk).

Once you have email and/or other federated access, you have a toehold. Bonus points if you've cloned their work cell SIM or have rerouted SIP for their desk phone to keep them out of the loop. I have seen weaker phishing attacks on financial/accounting staff who have the authority to move millions of dollars of corporate funds.

EDIT:

> Whom the would-be attackers send this email to?

Phishing target

> Do they send this email from their own email address?

Throw away address or spoofed address from a familiar-to-the-business domain.

> Is there an assumption that sysadmin/support team will blindly reset a password on someone else's request?

This is one assumption.

> How do attackers bypass corporate VPN?

VPN access might not be required to obtain the level of access desired. Do all of your SaaS providers require 2FA? Your business bank accounts?

Re: Out-Of-Office Messages Are a Security Risk

#14
Stuff like this is what keeps organizations from taking corpsec guidance seriously. Whatever the infinitesimal risk you accept by setting an autoresponder, it's dwarfed by the risk of convincing the rest of your team that you're a crank, and that what you have to say about phishing and email attachments isn't to be taken seriously.

Re: Out-Of-Office Messages Are a Security Risk

#15
post #3
post #2

Or you just check the box that says "only send to people at my organization".

What if you are working mainly with customers? BTW, the article says: > Set the autoresponse to the smallest group possible. In many cases you can narrow it down to coworkers, and/or have a different message for people inside your organization than outside your organization.

I think the context of the blog post, "the lonely sysadmin", means "working mainly with customers" isn't its target audience.

Bikeshedding for a moment, I suspect the right response for people "working mostly with customers" is for the CRM to automatically re-route known-customer and cold-call emails to someone else on the "working mostly with customer" team, instead of first up telling customers or leads "Sorry, Bob's away for 2 weeks", which is _never_ going to be the message you want to be sending there...

Re: Out-Of-Office Messages Are a Security Risk

#17
post #11

Earlier quoted context omitted.

So the attacker gets autoresponse. What's next? What is the attack vector here? UPD: also, I guess any attacker could just assume that you're Out of Office at night time.

EDIT: To be clear, I don't think this is a serious threat whatsoever, and went through the exercise as an explanation. Go easy on my comments, just having fun thinking it through. Impersonate the person out of town to escalate to their privilege level. Imposter: "My password isn't working, can you help me reset it?" Yes, this is unlikely to to work in smaller orgs where you know people face to face. It is more likely…

Sorry, still not clear to me.

- Whom the would-be attackers send this email to?

- Do they send this email from their own email address?

- Is there an assumption that sysadmin/support team will blindly reset a password on someone else's request?

- How do attackers bypass corporate VPN?

Re: Out-Of-Office Messages Are a Security Risk

#19
post #11

Earlier quoted context omitted.

So the attacker gets autoresponse. What's next? What is the attack vector here? UPD: also, I guess any attacker could just assume that you're Out of Office at night time.

EDIT: To be clear, I don't think this is a serious threat whatsoever, and went through the exercise as an explanation. Go easy on my comments, just having fun thinking it through. Impersonate the person out of town to escalate to their privilege level. Imposter: "My password isn't working, can you help me reset it?" Yes, this is unlikely to to work in smaller orgs where you know people face to face. It is more likely…

Any organisation where “hey I forgot my password, can you reset it?” from an unknown email address is an attack that has chance of success is an organisation where there’s dozens of major problems long before you get to auto-responders identifying who is away from the office.

Re: Out-Of-Office Messages Are a Security Risk

#20

Earlier quoted context omitted.

EDIT: To be clear, I don't think this is a serious threat whatsoever, and went through the exercise as an explanation. Go easy on my comments, just having fun thinking it through. Impersonate the person out of town to escalate to their privilege level. Imposter: "My password isn't working, can you help me reset it?" Yes, this is unlikely to to work in smaller orgs where you know people face to face. It is more likely…

Any organisation where “hey I forgot my password, can you reset it?” from an unknown email address is an attack that has chance of success is an organisation where there’s dozens of major problems long before you get to auto-responders identifying who is away from the office.

You're assuming I can't hop on the phone (appearing to come from a known number using Caller ID spoofing, using LinkedIn to get a general idea of the org chart) and bluff my way through it with your underpaid, overworked help desk staff. People are the weakest link.

This is only a few steps above Indian scammers taking remote control of users’ computers and convincing those users to send them hundreds of dollars of gift cards to prevent legal action by the IRS. Consider your average user, not the HN participant.

https://www.youtube.com/watch?v=YVqurfWzB-Q (Hacking Humans : Social Engineering Techniques and How to Protect Against Them - Stephen Haunts)

Post reply on HN