Earlier quoted context omitted.
I agree absolutely. It's similar to previous companies I've worked at that do phishing test emails for all their employees (usually at 9am on a Monday). There's little evidence it works, it is security theater and generally harms productivity. Knowing when not to bother people about security can be really helpful.
Followed immediately by HR sending an unsigned email about critical deadlines for benefits or something, telling you to click a link and/or a PDF attachment.
Out-Of-Office Messages Are a Security Risk
41–50 of 93 posts
Re: Out-Of-Office Messages Are a Security Risk
#42Earlier quoted context omitted.
Followed immediately by HR sending an unsigned email about critical deadlines for benefits or something, telling you to click a link and/or a PDF attachment.
In my company a lot of systems like HR have gone from internal servers to cloud so E-mails come from a lot of different URLs as sender. I consider myself pretty savvy but if a mail looks halfways plausible I don't really know how to tell if it's legitimate or not. The only way to fix this would be to sign E-mails so we can verify authenticity. I think it shouldn't be too hard to write an Outlook plugin to do this.
Re: Out-Of-Office Messages Are a Security Risk
#43Re: Out-Of-Office Messages Are a Security Risk
#44Earlier quoted context omitted.
What if you are working mainly with customers? BTW, the article says: > Set the autoresponse to the smallest group possible. In many cases you can narrow it down to coworkers, and/or have a different message for people inside your organization than outside your organization.
I think the context of the blog post, "the lonely sysadmin", means "working mainly with customers" isn't its target audience. Bikeshedding for a moment, I suspect the right response for people "working mostly with customers" is for the CRM to automatically re-route known-customer and cold-call emails to someone else on the "working mostly with customer" team, instead of first up telling customers or leads "Sorry, Bob…
Re: Out-Of-Office Messages Are a Security Risk
#45As always with security the first thing to ask is "What is your threat model?" This person's threat model seems to be people who email him for a legitimate business reason, but see that he's away & take the opportunity to attack him? I just don't buy it - I think there is nothing wrong with always setting an autoresponder.
Re: Out-Of-Office Messages Are a Security Risk
#46A "well, i was out of office. jamaica is amazing... have you been"
Q "No, uhm, so the thing is that we are going to lose 5 bajillion dollars if this is not done by 2 pm"
A "jerk chicken. its just like my mind opened up to a whole new way of seeing the world.... "
Q "Right so.. .. will we be able to have that paper by noon maybe? Then I can get it signed and we can rush it back to the.."
A "no, sorry, it takes 3 days to send it through Central, then West has to backsearch the kumquats, its not something i really have control over"
Q ".... was your out of office not working? i couldnt see it.. i mean i thought you were there..."
A "no, thats a security risk. i wouldnt want us to lose money due to some scammer"
Q "what.. is that some new IT policy? i dont remember seeing that..."
A "no, no, i read about it on this site for experts in computer stuff, its called Hacker News, you should check it out"
Re: Out-Of-Office Messages Are a Security Risk
#47As always with security the first thing to ask is "What is your threat model?" This person's threat model seems to be people who email him for a legitimate business reason, but see that he's away & take the opportunity to attack him? I just don't buy it - I think there is nothing wrong with always setting an autoresponder.
Re: Out-Of-Office Messages Are a Security Risk
#48As always with security the first thing to ask is "What is your threat model?" This person's threat model seems to be people who email him for a legitimate business reason, but see that he's away & take the opportunity to attack him? I just don't buy it - I think there is nothing wrong with always setting an autoresponder.
This is an interesting discussion. I can see the author's point - maybe, as a thought experiment, an attacker could latch onto the fact that someone is out of the office and use that as a wedge. Along the lines of "John and I had a payment planned, but he's out of the office, can you send it to [fake destination]?" But, like other people have noted, you also have to weigh the chance of that happening in real life. It…
If you're some outsider you don't know if that person is really unreachable or if their colleagues can easily reach them on Slack/send them a text/whatever if they have some important question.
And if you are internal/close enough to know their time off plans and that they're going backpacking in the Canadian Arctic, you didn't need the message to tell you they're out of office.
Re: Out-Of-Office Messages Are a Security Risk
#49Earlier quoted context omitted.
Any organisation where “hey I forgot my password, can you reset it?” from an unknown email address is an attack that has chance of success is an organisation where there’s dozens of major problems long before you get to auto-responders identifying who is away from the office.
You're assuming I can't hop on the phone (appearing to come from a known number using Caller ID spoofing, using LinkedIn to get a general idea of the org chart) and bluff my way through it with your underpaid, overworked help desk staff. People are the weakest link. This is only a few steps above Indian scammers taking remote control of users’ computers and convincing those users to send them hundreds of dollars of g…
Re: Out-Of-Office Messages Are a Security Risk
#50Earlier quoted context omitted.
You're assuming I can't hop on the phone (appearing to come from a known number using Caller ID spoofing, using LinkedIn to get a general idea of the org chart) and bluff my way through it with your underpaid, overworked help desk staff. People are the weakest link. This is only a few steps above Indian scammers taking remote control of users’ computers and convincing those users to send them hundreds of dollars of g…
We are arguing different points. I’m saying _if_ an organisation _is_ insecure enough for social engineering to work then a vacation auto-responder is not going to represent any meaningful increase in risk.