Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

21–30 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#21
A few years ago I received one of these at work, before I even knew they were a thing. I would have been very annoyed if they'd taken any action against me for following the link in it.

The email itself looked like a standard spam email, but the link was really weird, having a few tokens as part of a query string. Normally fishing emails have simple URLs in them.

So I did the obvious thing of opening the link in a fresh, zero data, locked-down VM just to see where it would take me.

I got the message that I was an idiot, and my company also was notified that I'm clueless about information security.

I can only imagine how difficult it might be to explain to someone what I had done, and why I probably shouldn't have to go on some tedious training course let alone be fired. Luckily all I saw was an increase in the number of these emails I received.

Re: Should Failing Phish Tests Be a Fireable Offense?

#22
post #10
post #4

How hard is it to make people understand what a business email should or shouldn't include? If you're being asked for data by someone you don't know, either ask a manager or someone connected to the account in question. Are people really so gullible & trusting?

What about an email from someone you know (coworker, relative) via a spoofed or compromised account?

I learned to look at reply-to back when I used Juno & Netscape Communicator. Heck, Communicator used to warn you if reply-to differed from the displayed name.

Re: Should Failing Phish Tests Be a Fireable Offense?

#23

Repeat after me: Everyone can be spearphished. I mean it. Everyone.

Introducing an attack vector to get arbitrary people fired by policy can't possibly go wrong!

That should be an Internet rule: Don't set up any mechanism that puts severe power in the hands of anonymous strangers. It will get exploited!

Re: Should Failing Phish Tests Be a Fireable Offense?

#24
post #16

Earlier quoted context omitted.

> If you're being asked for data by someone you don't know That's not how spear phishing or even phishing works. The email looks like it came from a fellow employee/boss/trusted party.

What about the sending and reply-to address? If the account is actually compromised at a system level, that is an IT issue. Again, are people so trusting that they don't check when asked for confidential data?

Sending addresses can be spoofed.

Re: Should Failing Phish Tests Be a Fireable Offense?

#25
I'm a tech professional and security is a regular part of my jobs. At one point -- while contracting for a Fortune 500 client that shall remain unnamed -- I received an email that was quite clearly phishing. Curious as to what the payload was and whether it was worth reporting, I fired up lynx and followed the link in the email from the command line.

I was promptly informed that I had failed the test and I would be receiving a formal reprimand.

Did that make the company more secure?

Re: Should Failing Phish Tests Be a Fireable Offense?

#27

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

This is a great idea for defense contractors, and (probably) an exceptionally draconian idea for most other workplaces.

Re: Should Failing Phish Tests Be a Fireable Offense?

#28
post #14
post #4

How hard is it to make people understand what a business email should or shouldn't include? If you're being asked for data by someone you don't know, either ask a manager or someone connected to the account in question. Are people really so gullible & trusting?

> Are people really so gullible & trusting? Yes, and it is not a “bad” thing outside the niche of security I think. We should all hope to live a life where we can implicitly trust other human beings.

In small town America in the 70's and 80's of my childhood, life was pretty darn close to this.

Re: Should Failing Phish Tests Be a Fireable Offense?

#30
Is someone trying to apply AI and Deep Learning to phishing attacks? One of the things which PG noted in "A Plan for Spam" back in the day, was that the Bayes classifier found markers of Spam he never would have thought of.

http://www.paulgraham.com/spam.html

If Phishers are concentrating on fooling human beings in the same way that spammers were back in the day, they might be vulnerable to such techniques.

Post reply on HN