Live data from Hacker News

Out-Of-Office Messages Are a Security Risk

lonesysadmin.net

71–80 of 93 posts

Re: Out-Of-Office Messages Are a Security Risk

#72
post #11

Earlier quoted context omitted.

I think the point is that autoresponders will autorespond to legitimate business emails as well as phishing/scam/whatever other emails.

So the attacker gets autoresponse. What's next? What is the attack vector here? UPD: also, I guess any attacker could just assume that you're Out of Office at night time.

If attacker gets info you are out of office for 2 weeks it most likely also means you are traveling and out of home for 2 weeks. Perfect opportunity for burglary.

This is not a hypothetical scenario, almost every year there is some idiot saying they going for vacation in those mini-interviews in the local newspaper and then they get their house broken into.

However the probability that someone does email you and is a burglar at the same time is extremely small.

Re: Out-Of-Office Messages Are a Security Risk

#73
post #25

Earlier quoted context omitted.

I agree absolutely. It's similar to previous companies I've worked at that do phishing test emails for all their employees (usually at 9am on a Monday). There's little evidence it works, it is security theater and generally harms productivity. Knowing when not to bother people about security can be really helpful.

Corporate security theater in general is starting to get out of hand. I just had to take a yearly sec training, and the videos are absurdly over-the-top. I can imagine them being quite alarming for people who don't have the technical background to know what is actually important. Just a series of videos trying to conjure up this strange sense of paranoia -- telling us that "HACKERS" are CONSTANTLY trying to 'break in…

A lot of financial related phishing emails use info gathered from social networks. The attackers use it to see who does what in the company and to come up with a nice email to someone in the finance department.

Sure there is a lot of security theater but I think its important to understand that for attackers its definitely worth to spend a couple of hours on research. A successful email can quickly reach a 5 figures reward.

Source: I work in email security

Re: Out-Of-Office Messages Are a Security Risk

#74
post #42
post #39

Earlier quoted context omitted.

In my company a lot of systems like HR have gone from internal servers to cloud so E-mails come from a lot of different URLs as sender. I consider myself pretty savvy but if a mail looks halfways plausible I don't really know how to tell if it's legitimate or not. The only way to fix this would be to sign E-mails so we can verify authenticity. I think it shouldn't be too hard to write an Outlook plugin to do this.

If I am not sure whether an email is legitimate or not, then I just ignore it assuming that if it is something real and important, then the other party will find a way to contact me (send another email, call me, approach me in person etc.).

I just flat out don't read work email anymore. Everything gets deleted. If it is important someone has mentioned it in slack, came over to my desk to tell me or it was publically abounced

Re: Out-Of-Office Messages Are a Security Risk

#75
post #7

As always with security the first thing to ask is "What is your threat model?" This person's threat model seems to be people who email him for a legitimate business reason, but see that he's away & take the opportunity to attack him? I just don't buy it - I think there is nothing wrong with always setting an autoresponder.

Maybe his threat model is an attack to his position/team from within the corp. Should also apply to politicians within the party :-) Then it of course makes sense to not send these mails and read and answer them.

Re: Out-Of-Office Messages Are a Security Risk

#76
post #14

Stuff like this is what keeps organizations from taking corpsec guidance seriously. Whatever the infinitesimal risk you accept by setting an autoresponder, it's dwarfed by the risk of convincing the rest of your team that you're a crank, and that what you have to say about phishing and email attachments isn't to be taken seriously.

Totally agree. I've never been on an engagement and found an auto responder with useful information.

I already have your team structure from LinkedIn. I probably know about your trip from Facebook or Instagram. I don't really care when you get back, because i'll be stealthy either way.

Re: Out-Of-Office Messages Are a Security Risk

#77
post #7

As always with security the first thing to ask is "What is your threat model?" This person's threat model seems to be people who email him for a legitimate business reason, but see that he's away & take the opportunity to attack him? I just don't buy it - I think there is nothing wrong with always setting an autoresponder.

Still, I’d rather just forward my email to my assistant while I’m gone. If it’s urgent it’ll get handled. If not, it’ll wait.

Can we all forward our email to your assistant too?

Re: Out-Of-Office Messages Are a Security Risk

#78
post #67

Earlier quoted context omitted.

Possibly stupid question: Is there any fundamental reason your corporate email system couldn't, for example, just not interoperate with the rest of the Internet, at least by default? I understand if this doesn't work for people in sales or consulting or whatever, but 90-99% of my work email is entirely within the same company, and I think it would be less onerous and more secure to just block external email by defaul…

What we do (and a lot of companies do) is append [EXT] to the subject line of any incoming message from outside the org. Blocking external email by default will drive people to use their personal gmail for work.

Clearly denoting if the email is unsafe is great. If there is a lot of communication with a few outside orgs then a whitelist could be used

Re: Out-Of-Office Messages Are a Security Risk

#80

Earlier quoted context omitted.

Followed immediately by HR sending an unsigned email about critical deadlines for benefits or something, telling you to click a link and/or a PDF attachment.

The most obvious phishing email I ever received was from some random domain informing me I had not take the required anti-phishing tracking and to please click the link to take it. Like a good employee, I sent the email to our spam@ account and didn't give it any more thought. A month later, my manager comes in and informs me that the anti-phishing training is not optional and I had a week to complete it.

Back when I worked at HP, our anti-phishing training even had a joke in it about how, yes, all HP URLs look exactly like the phising URLs they were describing...

What's with https://h20195.www2.hpe.com/? Why?

Post reply on HN