Out-Of-Office Messages Are a Security Risk
31–40 of 93 posts
Re: Out-Of-Office Messages Are a Security Risk
#32Earlier quoted context omitted.
I agree absolutely. It's similar to previous companies I've worked at that do phishing test emails for all their employees (usually at 9am on a Monday). There's little evidence it works, it is security theater and generally harms productivity. Knowing when not to bother people about security can be really helpful.
Followed immediately by HR sending an unsigned email about critical deadlines for benefits or something, telling you to click a link and/or a PDF attachment.
Re: Out-Of-Office Messages Are a Security Risk
#33As always with security the first thing to ask is "What is your threat model?" This person's threat model seems to be people who email him for a legitimate business reason, but see that he's away & take the opportunity to attack him? I just don't buy it - I think there is nothing wrong with always setting an autoresponder.
Yeah, this is a stretch... I'm getting pretty tired of this kind of thing. It's pretty clear to me that the infosec industry (within appsec and netsec at least, not risk and compliance) is bifurcated into two distinct groups. The first group consists of people who have real technical expertise, find serious vulnerabilities and make concrete suggestions about legitimate issues. The second group, and the one I see more…
Re: Out-Of-Office Messages Are a Security Risk
#34Re: Out-Of-Office Messages Are a Security Risk
#35https://twitter.com/natashenka/status/974822101067612161
Re: Out-Of-Office Messages Are a Security Risk
#36Earlier quoted context omitted.
Followed immediately by HR sending an unsigned email about critical deadlines for benefits or something, telling you to click a link and/or a PDF attachment.
So the real issue here is not emails or autoresponders, but lack of IT security knowledge among employees. Hence, do (mandatory) trainings or something.
Re: Out-Of-Office Messages Are a Security Risk
#37As always with security the first thing to ask is "What is your threat model?" This person's threat model seems to be people who email him for a legitimate business reason, but see that he's away & take the opportunity to attack him? I just don't buy it - I think there is nothing wrong with always setting an autoresponder.
Along the lines of "John and I had a payment planned, but he's out of the office, can you send it to [fake destination]?"
But, like other people have noted, you also have to weigh the chance of that happening in real life. It seems like the amount of planning on the attacker's part would be significant enough that if they could pull it off, they would have found easier targets by then.
Re: Out-Of-Office Messages Are a Security Risk
#38Re: Out-Of-Office Messages Are a Security Risk
#39Earlier quoted context omitted.
I agree absolutely. It's similar to previous companies I've worked at that do phishing test emails for all their employees (usually at 9am on a Monday). There's little evidence it works, it is security theater and generally harms productivity. Knowing when not to bother people about security can be really helpful.
Followed immediately by HR sending an unsigned email about critical deadlines for benefits or something, telling you to click a link and/or a PDF attachment.
I think it shouldn't be too hard to write an Outlook plugin to do this.
Re: Out-Of-Office Messages Are a Security Risk
#40Stuff like this is what keeps organizations from taking corpsec guidance seriously. Whatever the infinitesimal risk you accept by setting an autoresponder, it's dwarfed by the risk of convincing the rest of your team that you're a crank, and that what you have to say about phishing and email attachments isn't to be taken seriously.
I agree absolutely. It's similar to previous companies I've worked at that do phishing test emails for all their employees (usually at 9am on a Monday). There's little evidence it works, it is security theater and generally harms productivity. Knowing when not to bother people about security can be really helpful.