Live data from Hacker News

Out-Of-Office Messages Are a Security Risk

lonesysadmin.net

21–30 of 93 posts

Re: Out-Of-Office Messages Are a Security Risk

#21
post #11

Earlier quoted context omitted.

So the attacker gets autoresponse. What's next? What is the attack vector here? UPD: also, I guess any attacker could just assume that you're Out of Office at night time.

EDIT: To be clear, I don't think this is a serious threat whatsoever, and went through the exercise as an explanation. Go easy on my comments, just having fun thinking it through. Impersonate the person out of town to escalate to their privilege level. Imposter: "My password isn't working, can you help me reset it?" Yes, this is unlikely to to work in smaller orgs where you know people face to face. It is more likely…

I agree with you that under these circumstances autoresponses could be a security risk. But then I'd better fix the underlying security problem(s) and let everyone use autoresponders if they wish to.

Re: Out-Of-Office Messages Are a Security Risk

#23
post #11

Earlier quoted context omitted.

So the attacker gets autoresponse. What's next? What is the attack vector here? UPD: also, I guess any attacker could just assume that you're Out of Office at night time.

EDIT: To be clear, I don't think this is a serious threat whatsoever, and went through the exercise as an explanation. Go easy on my comments, just having fun thinking it through. Impersonate the person out of town to escalate to their privilege level. Imposter: "My password isn't working, can you help me reset it?" Yes, this is unlikely to to work in smaller orgs where you know people face to face. It is more likely…

> Impersonate the person out of town to escalate to their privilege level.

> Imposter: "My password isn't working, can you help me reset it?"

This doesn't have anything to do with being out of town or autoresponses.

Re: Out-Of-Office Messages Are a Security Risk

#24
post #16

Out of office? Its an invitation to a thief with the address attached in the signature.

Is it? If I leave for a week is it assumed all of my coworkers also leave, our doors unlock and alarms are off?

Maybe that's a risk for a single person working in a coworking space. Probably less so for companies that have >1 employee.

Re: Out-Of-Office Messages Are a Security Risk

#25
post #14

Stuff like this is what keeps organizations from taking corpsec guidance seriously. Whatever the infinitesimal risk you accept by setting an autoresponder, it's dwarfed by the risk of convincing the rest of your team that you're a crank, and that what you have to say about phishing and email attachments isn't to be taken seriously.

I agree absolutely. It's similar to previous companies I've worked at that do phishing test emails for all their employees (usually at 9am on a Monday). There's little evidence it works, it is security theater and generally harms productivity. Knowing when not to bother people about security can be really helpful.

Re: Out-Of-Office Messages Are a Security Risk

#26

> Don’t tell people anything more than they need to know. Does everybody really need to know where you’ve gone and how long? Probably not. You’re just gone. Set some expectations around response time, though. That's a borderline contradiction.

True -- fixed. Thanks.

Re: Out-Of-Office Messages Are a Security Risk

#27
post #25
post #14

Stuff like this is what keeps organizations from taking corpsec guidance seriously. Whatever the infinitesimal risk you accept by setting an autoresponder, it's dwarfed by the risk of convincing the rest of your team that you're a crank, and that what you have to say about phishing and email attachments isn't to be taken seriously.

I agree absolutely. It's similar to previous companies I've worked at that do phishing test emails for all their employees (usually at 9am on a Monday). There's little evidence it works, it is security theater and generally harms productivity. Knowing when not to bother people about security can be really helpful.

Followed immediately by HR sending an unsigned email about critical deadlines for benefits or something, telling you to click a link and/or a PDF attachment.

Re: Out-Of-Office Messages Are a Security Risk

#28
post #25

Earlier quoted context omitted.

I agree absolutely. It's similar to previous companies I've worked at that do phishing test emails for all their employees (usually at 9am on a Monday). There's little evidence it works, it is security theater and generally harms productivity. Knowing when not to bother people about security can be really helpful.

Followed immediately by HR sending an unsigned email about critical deadlines for benefits or something, telling you to click a link and/or a PDF attachment.

So the real issue here is not emails or autoresponders, but lack of IT security knowledge among employees. Hence, do (mandatory) trainings or something.
Post reply on HN