Out-Of-Office Messages Are a Security Risk
61–70 of 93 posts
Re: Out-Of-Office Messages Are a Security Risk
#62Stuff like this is what keeps organizations from taking corpsec guidance seriously. Whatever the infinitesimal risk you accept by setting an autoresponder, it's dwarfed by the risk of convincing the rest of your team that you're a crank, and that what you have to say about phishing and email attachments isn't to be taken seriously.
my current job lets you set the autoresponder to only autorespond to people in the org. how is that such a bad risk?
Re: Out-Of-Office Messages Are a Security Risk
#63Earlier quoted context omitted.
We are arguing different points. I’m saying _if_ an organisation _is_ insecure enough for social engineering to work then a vacation auto-responder is not going to represent any meaningful increase in risk.
I am arguing that _most_ organizations are insecure enough for social engineering to work, and that autoresponders are yet another vector. Orgs that observe proper operational security are still a minority.
Re: Out-Of-Office Messages Are a Security Risk
#64As always with security the first thing to ask is "What is your threat model?" This person's threat model seems to be people who email him for a legitimate business reason, but see that he's away & take the opportunity to attack him? I just don't buy it - I think there is nothing wrong with always setting an autoresponder.
Yeah, this is a stretch... I'm getting pretty tired of this kind of thing. It's pretty clear to me that the infosec industry (within appsec and netsec at least, not risk and compliance) is bifurcated into two distinct groups. The first group consists of people who have real technical expertise, find serious vulnerabilities and make concrete suggestions about legitimate issues. The second group, and the one I see more…
Re: Out-Of-Office Messages Are a Security Risk
#65Earlier quoted context omitted.
I've watched phishing exercise emails work (where by "work" I mean "marked increase in reports of real phishing attempts"), so I'm not sure that's the best example of theatrical corpsec practices.
Possibly stupid question: Is there any fundamental reason your corporate email system couldn't, for example, just not interoperate with the rest of the Internet, at least by default? I understand if this doesn't work for people in sales or consulting or whatever, but 90-99% of my work email is entirely within the same company, and I think it would be less onerous and more secure to just block external email by defaul…
Re: Out-Of-Office Messages Are a Security Risk
#66Stuff like this is what keeps organizations from taking corpsec guidance seriously. Whatever the infinitesimal risk you accept by setting an autoresponder, it's dwarfed by the risk of convincing the rest of your team that you're a crank, and that what you have to say about phishing and email attachments isn't to be taken seriously.
I agree absolutely. It's similar to previous companies I've worked at that do phishing test emails for all their employees (usually at 9am on a Monday). There's little evidence it works, it is security theater and generally harms productivity. Knowing when not to bother people about security can be really helpful.
The kicker was when they told us that, if our mobile devices become more than a few years old, we just had to buy new ones in order to stay secure. I was flabbergasted. This is speaking about our own personal devices, not company-issued ones. Seriously, the gall to make people think the only way to be safe is to spend hundreds of dollars on new phones every 2 years.
It's just bizarre, and it's never been applicable in any of my workplaces. And I have worked for large, global law firms on quite famous litigation with huge international conglomerates as clients -- as a poorly paid grunt, not an associate, but that just meant I had more direct access to sensitive documents. I've probably received ~100 "phishy" emails over the years, and zero of them have been actual phishing attempts. Just more of that "the molesters are waiting around every corner and hiding behind every tree" nonsense, now migrated into the workplace.
Re: Out-Of-Office Messages Are a Security Risk
#67Earlier quoted context omitted.
I've watched phishing exercise emails work (where by "work" I mean "marked increase in reports of real phishing attempts"), so I'm not sure that's the best example of theatrical corpsec practices.
Possibly stupid question: Is there any fundamental reason your corporate email system couldn't, for example, just not interoperate with the rest of the Internet, at least by default? I understand if this doesn't work for people in sales or consulting or whatever, but 90-99% of my work email is entirely within the same company, and I think it would be less onerous and more secure to just block external email by defaul…
Re: Out-Of-Office Messages Are a Security Risk
#68Earlier quoted context omitted.
I agree absolutely. It's similar to previous companies I've worked at that do phishing test emails for all their employees (usually at 9am on a Monday). There's little evidence it works, it is security theater and generally harms productivity. Knowing when not to bother people about security can be really helpful.
I've watched phishing exercise emails work (where by "work" I mean "marked increase in reports of real phishing attempts"), so I'm not sure that's the best example of theatrical corpsec practices.
I suppose it depends on how we measure effectiveness. What was the false positive rate you observed in addition to the marked increase in reports of real phishing attempts? It would be interesting to see what impact the "blame and train" internal phishing has on overall company productivity compared to just not doing it.
Re: Out-Of-Office Messages Are a Security Risk
#69Earlier quoted context omitted.
Yeah, this is a stretch... I'm getting pretty tired of this kind of thing. It's pretty clear to me that the infosec industry (within appsec and netsec at least, not risk and compliance) is bifurcated into two distinct groups. The first group consists of people who have real technical expertise, find serious vulnerabilities and make concrete suggestions about legitimate issues. The second group, and the one I see more…
I have heard the term "security vultures" being applied to the second group, and wish it was more common (the term, not the group...)
Re: Out-Of-Office Messages Are a Security Risk
#70Earlier quoted context omitted.
If I am not sure whether an email is legitimate or not, then I just ignore it assuming that if it is something real and important, then the other party will find a way to contact me (send another email, call me, approach me in person etc.).
With stuff like information about health insurance or 401k information there won't be any follow-up but it's very important to me.
Imagine if someone from your benefits provider called and asked for your social security number or other PII for confirmation. Would you give it to them? I hope not. You should ask (as I always do) for their name and extension and tell them that you'll return their call through a published telephone number. Never once have I had someone balk at that, and I've done it countless times for many years.
For a link to a benefits provider, it's trivial to log into the portal through a known good domain and look around for whatever piece of information or news they were trying to communicate.
The hard issues come with all the random services HR contracts for stuff like harassment training, etc. If I can't corroborate a link myself then as a last resort I can simply ask HR (or w'ever department) directly, or as previously said just ignore it and wait for someone to say something.
At some point the usage of so many third-party services is just an insane security risk. It's almost comical when the corp security team runs a phishing test and on the same day you get a half-dozen e-mail messages from other departments with twice as many links to random domains. At some point you're just like, "fsck 'em" and have half a mind to not bother caring anymore. But it's not just their security on the line, it's yours, too.
I still use mutt for personal e-mail so maybe this is all easier for me. I've yet to become accustomed to hidden links or embedded multimedia in e-mail.