Live data from Hacker News

Out-Of-Office Messages Are a Security Risk

lonesysadmin.net

81–90 of 93 posts

Re: Out-Of-Office Messages Are a Security Risk

#81
post #67

Earlier quoted context omitted.

Possibly stupid question: Is there any fundamental reason your corporate email system couldn't, for example, just not interoperate with the rest of the Internet, at least by default? I understand if this doesn't work for people in sales or consulting or whatever, but 90-99% of my work email is entirely within the same company, and I think it would be less onerous and more secure to just block external email by defaul…

What we do (and a lot of companies do) is append [EXT] to the subject line of any incoming message from outside the org. Blocking external email by default will drive people to use their personal gmail for work.

This is a problem with a lot of security people. They want to forbid everything to make it safe. But you need to let people do what they want to do, otherwise they will find way more unsafe ways to do it.

A friend of mine works in industrial safety. He sees this a lot. He told me the rule "Jedes Verbot braucht ein Gebot", which roughly translated means "Every thing that is forbidden should be accompanied by a permission". So you can't just forbid people to smoke somewhere, you have to find a place where they can smoke. Otherwise they might find one themselves.

Re: Out-Of-Office Messages Are a Security Risk

#82
post #7

As always with security the first thing to ask is "What is your threat model?" This person's threat model seems to be people who email him for a legitimate business reason, but see that he's away & take the opportunity to attack him? I just don't buy it - I think there is nothing wrong with always setting an autoresponder.

Yeah, this is a stretch... I'm getting pretty tired of this kind of thing. It's pretty clear to me that the infosec industry (within appsec and netsec at least, not risk and compliance) is bifurcated into two distinct groups. The first group consists of people who have real technical expertise, find serious vulnerabilities and make concrete suggestions about legitimate issues. The second group, and the one I see more…

I've had a member of the second group, describing himself as a "certified white hat hacker", sign up for a small SAAS product I'm involved with, mess around a bit and then file a slew of "urgent vulnerability reports" of supposed security issues, all of them profoundly so-whattish in the context of a niche business SAAS. When I closed them all without further action, the chap then had the gall to demand payment - or at least a "certificate of appreciation" he could parlay into future business. Needless to say we declined.

This lack of any concept of a threat model was precisely why his (considerable) effort was totally wasted and I can imagine similar "researchers" giving the industry as a whole a bad name.

Re: Out-Of-Office Messages Are a Security Risk

#83
post #39

Earlier quoted context omitted.

Followed immediately by HR sending an unsigned email about critical deadlines for benefits or something, telling you to click a link and/or a PDF attachment.

In my company a lot of systems like HR have gone from internal servers to cloud so E-mails come from a lot of different URLs as sender. I consider myself pretty savvy but if a mail looks halfways plausible I don't really know how to tell if it's legitimate or not. The only way to fix this would be to sign E-mails so we can verify authenticity. I think it shouldn't be too hard to write an Outlook plugin to do this.

The Corporate Overlords hired a company to send us fake phishing emails to test us peons. I found out that this company will set a header saying it's a fake phishing email, probably to get it past our spam firewall.

Re: Out-Of-Office Messages Are a Security Risk

#84

Earlier quoted context omitted.

The most obvious phishing email I ever received was from some random domain informing me I had not take the required anti-phishing tracking and to please click the link to take it. Like a good employee, I sent the email to our spam@ account and didn't give it any more thought. A month later, my manager comes in and informs me that the anti-phishing training is not optional and I had a week to complete it.

At a large company, shouldn't someone be monitoring the address where people report phishing, who can tell you if a reported message is legitimate? I work at a small company, so I don't know if this is how any IRL organizations work, but it's how I assumed the procedure went.

Anecdote time:

At one of my previous jobs, there was this big part of intranet that was used by sysadmins, and various other people from fields other than software development. My team didn't have to deal with it, so we weren't even aware of it, much less had access to it. One day, however, someone wanted me to review a document from there. I bounced off the "Unauthorized" error, and dutifully followed the instructions to fill in an appropriate box with a justification, and send a request to be granted access.

The issue wasn't critical, so I didn't pester anyone about it, just patiently waited for the access, re-filing my request every other month. Many months later, with me still not getting access, I eventually brought this up to my boss, who then smiled and told me that this access request form literally goes to /dev/null. Apparently after some software migration, no one bothered to connect this to anything.

Re: Out-Of-Office Messages Are a Security Risk

#85
post #41

Earlier quoted context omitted.

Followed immediately by HR sending an unsigned email about critical deadlines for benefits or something, telling you to click a link and/or a PDF attachment.

Our security team makes their phishing emails look way too professional.

Targeted phishing for corporate espionnage would look very professional. Even regular bank phishing is getting very pro these days. https://krebsonsecurity.com/2018/10/voice-phishing-scams-are...

Re: Out-Of-Office Messages Are a Security Risk

#86
post #25

Earlier quoted context omitted.

I agree absolutely. It's similar to previous companies I've worked at that do phishing test emails for all their employees (usually at 9am on a Monday). There's little evidence it works, it is security theater and generally harms productivity. Knowing when not to bother people about security can be really helpful.

Corporate security theater in general is starting to get out of hand. I just had to take a yearly sec training, and the videos are absurdly over-the-top. I can imagine them being quite alarming for people who don't have the technical background to know what is actually important. Just a series of videos trying to conjure up this strange sense of paranoia -- telling us that "HACKERS" are CONSTANTLY trying to 'break in…

It's because phishing works, and the success rate is a combination of the right message and the number of attempts. Of course smart people will notice right away, but how to discern who is smart and who is not before the incident happens? To make sure you make everyone undergo the training.

As for the smartphone example: they could just have said to make sure you always have the most recent version of the OS, which is quite easy if you own a certain brand of smartphones, and can be frustratingly difficult if you use something else. I'm sorry to say but they were right: most vendors don't care for customers who have devices older than a few years because they don't bring them any money. It's a general problem in the industry, nothing surprisingly new.

Re: Out-Of-Office Messages Are a Security Risk

#87
I haven’t seen any mention of his other point.

“If you’re gone be gone.”

I don’t respond to emails on vacation or after I get off of work. Not even meeting invites. If I happen to be working late trying to figure out something, I make it a point not to let anyone know. I don’t want to set the expectation that I’m always reachable.

I have a project manager and a QA person who will send me messages on our Slack channel. They ask me did I see it I tell them when I’m home I’m home.

One exception is that I will answer an email to our offshore team, but even then I take the local developers and manager off of the email list.

Re: Out-Of-Office Messages Are a Security Risk

#89

Earlier quoted context omitted.

Indeed - who has an answering machine these days?

Most people have voicemail which is pretty much the same thing.

In general, touche. For this context, there's a meaningful difference: voicemail, unlike an answering machine, is accessible from anywhere, so there's no reason to set a "we're out of town" message.

Re: Out-Of-Office Messages Are a Security Risk

#90
post #67

Earlier quoted context omitted.

Possibly stupid question: Is there any fundamental reason your corporate email system couldn't, for example, just not interoperate with the rest of the Internet, at least by default? I understand if this doesn't work for people in sales or consulting or whatever, but 90-99% of my work email is entirely within the same company, and I think it would be less onerous and more secure to just block external email by defaul…

What we do (and a lot of companies do) is append [EXT] to the subject line of any incoming message from outside the org. Blocking external email by default will drive people to use their personal gmail for work.

> Blocking external email by default will drive people to use their personal gmail for work.

But how? They could only email with other people who also used their personal gmail for work—they couldn’t book conference rooms or look up anyone they hadn’t emailed before.

Post reply on HN