Live data from Hacker News

Out-Of-Office Messages Are a Security Risk

lonesysadmin.net

51–60 of 93 posts

Re: Out-Of-Office Messages Are a Security Risk

#53
post #7

As always with security the first thing to ask is "What is your threat model?" This person's threat model seems to be people who email him for a legitimate business reason, but see that he's away & take the opportunity to attack him? I just don't buy it - I think there is nothing wrong with always setting an autoresponder.

Yeah, this is a stretch... I'm getting pretty tired of this kind of thing. It's pretty clear to me that the infosec industry (within appsec and netsec at least, not risk and compliance) is bifurcated into two distinct groups. The first group consists of people who have real technical expertise, find serious vulnerabilities and make concrete suggestions about legitimate issues. The second group, and the one I see more…

At some point we just can't do more to thwart every possible threat. What are we going to be told to sneak out the back door of our house and walk 3 blocks to where we parked our car?

Re: Out-Of-Office Messages Are a Security Risk

#54

Earlier quoted context omitted.

Followed immediately by HR sending an unsigned email about critical deadlines for benefits or something, telling you to click a link and/or a PDF attachment.

The most obvious phishing email I ever received was from some random domain informing me I had not take the required anti-phishing tracking and to please click the link to take it. Like a good employee, I sent the email to our spam@ account and didn't give it any more thought. A month later, my manager comes in and informs me that the anti-phishing training is not optional and I had a week to complete it.

That's amazing.

Re: Out-Of-Office Messages Are a Security Risk

#55
post #2

Or you just check the box that says "only send to people at my organization".

Or? That's one of the strategies that the article states for managing the risk:

> Set the autoresponse to the smallest group possible. In many cases you can narrow it down to coworkers, and/or have a different message for people inside your organization than outside your organization.

Re: Out-Of-Office Messages Are a Security Risk

#56

Earlier quoted context omitted.

Followed immediately by HR sending an unsigned email about critical deadlines for benefits or something, telling you to click a link and/or a PDF attachment.

The most obvious phishing email I ever received was from some random domain informing me I had not take the required anti-phishing tracking and to please click the link to take it. Like a good employee, I sent the email to our spam@ account and didn't give it any more thought. A month later, my manager comes in and informs me that the anti-phishing training is not optional and I had a week to complete it.

At a large company, shouldn't someone be monitoring the address where people report phishing, who can tell you if a reported message is legitimate?

I work at a small company, so I don't know if this is how any IRL organizations work, but it's how I assumed the procedure went.

Re: Out-Of-Office Messages Are a Security Risk

#57
post #42
post #39

Earlier quoted context omitted.

In my company a lot of systems like HR have gone from internal servers to cloud so E-mails come from a lot of different URLs as sender. I consider myself pretty savvy but if a mail looks halfways plausible I don't really know how to tell if it's legitimate or not. The only way to fix this would be to sign E-mails so we can verify authenticity. I think it shouldn't be too hard to write an Outlook plugin to do this.

If I am not sure whether an email is legitimate or not, then I just ignore it assuming that if it is something real and important, then the other party will find a way to contact me (send another email, call me, approach me in person etc.).

With stuff like information about health insurance or 401k information there won't be any follow-up but it's very important to me.

Re: Out-Of-Office Messages Are a Security Risk

#58
post #7

As always with security the first thing to ask is "What is your threat model?" This person's threat model seems to be people who email him for a legitimate business reason, but see that he's away & take the opportunity to attack him? I just don't buy it - I think there is nothing wrong with always setting an autoresponder.

This is an interesting discussion. I can see the author's point - maybe, as a thought experiment, an attacker could latch onto the fact that someone is out of the office and use that as a wedge. Along the lines of "John and I had a payment planned, but he's out of the office, can you send it to [fake destination]?" But, like other people have noted, you also have to weigh the chance of that happening in real life. It…

I actually did see a situation just like that, and it amounted to lucky diligence on the part of a third-party that the situation was detected before it was too late.

A guy in an Accounts Receivable role got phished. He went on a two week vacation, and bright-and-early on the first day he was out the phisher sent out emails as the vacationing AR person to a number of Customers advising them that remittance processing was being handled by a new third-party. They directed all the Customers to that third-party's "new" bank account. The attacker helpfully put a rule on the guy's Inbox to move new messages from every domain that the attacker emailed directly to "Deleted Items".

One of the Customers thought it seemed a bit fishy and called-in to confirm that very first day.

Re: Out-Of-Office Messages Are a Security Risk

#59
post #40
post #25

Earlier quoted context omitted.

I agree absolutely. It's similar to previous companies I've worked at that do phishing test emails for all their employees (usually at 9am on a Monday). There's little evidence it works, it is security theater and generally harms productivity. Knowing when not to bother people about security can be really helpful.

I've watched phishing exercise emails work (where by "work" I mean "marked increase in reports of real phishing attempts"), so I'm not sure that's the best example of theatrical corpsec practices.

Possibly stupid question:

Is there any fundamental reason your corporate email system couldn't, for example, just not interoperate with the rest of the Internet, at least by default? I understand if this doesn't work for people in sales or consulting or whatever, but 90-99% of my work email is entirely within the same company, and I think it would be less onerous and more secure to just block external email by default and use a separate, secured system when you had to email anyone outside the company.

Re: Out-Of-Office Messages Are a Security Risk

#60
post #14

Stuff like this is what keeps organizations from taking corpsec guidance seriously. Whatever the infinitesimal risk you accept by setting an autoresponder, it's dwarfed by the risk of convincing the rest of your team that you're a crank, and that what you have to say about phishing and email attachments isn't to be taken seriously.

my current job lets you set the autoresponder to only autorespond to people in the org. how is that such a bad risk?
Post reply on HN