Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

81–90 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#81
post #55

Earlier quoted context omitted.

Did the link take you to a site that auto-ran malware? Or did it take you to some kind of page that said "login to unsubscribe"? The latter is why password managers can be so valuable. I never type my passwords in so if my auto-fill doesn't activate I immediately become suspicious. If it's the former, it seems like your company must be using an insecure browser or the site was running some kind of 0-day? I never thin…

> I never think twice about clicking links. I hope you don't work for any sensitive position.

It's a valid comment, but if you're in a position where you are worried about 0-days from random web browsing then you should be using the internet on a fully segregated machine.

If Firefox or Chrome has an RCE + privilege escalation in it that can be triggered just from browsing to a page then, congrats, you got me.

Re: Should Failing Phish Tests Be a Fireable Offense?

#82

Earlier quoted context omitted.

I recently failed a suspicious email / phishing test for the first time, and I am also one of those people who never thought it would happen to me... The email was a newsletter I didn't care about, and the unsubscribe link was (fake) malicious. That one impressed me because it preyed on what is now a pure reflex to click the unsubscribe link.

> a pure reflex to click the unsubscribe link. That's a learned trait. I don't click unsubscribe links; I click "report spam" and "report phishing" button. If only Gmail would let me create filters to automatically mark entire domains as spam though. That would be nice...

I'm sure this [reporting spam rather than unsubscribing] happens all the time but it's sort of obnoxious if the email is legit and, especially, if it's a list you requested to get put on at some point.

Re: Should Failing Phish Tests Be a Fireable Offense?

#83

Earlier quoted context omitted.

Can't speak to whether a reprimand is warranted or not and I think many here will disagree, but unless your job is investigating phishing, you shouldn't do this because you ARE ultimately putting the corporate network at risk unnecessarily - what if it was a real link and happened to exploit a zero day on your box? Management wouldn't accept your reasoning for following the link I suspect.

The risk of hitting an exploit on the command line, especially with something like wget, is enough orders of magnitude lower that I think it falls under acceptable. The standard cannot be zero risk because that's impossible. Even shutting off the internet link doesn't get you all the way to zero.

The issue isn't how much risk there is in opening it. The problem is that regardless of how much or little risk there is in opening the link, it wasn't op's job to examine it. It was unnecessary risk to open the link.

Re: Should Failing Phish Tests Be a Fireable Offense?

#84

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

I work at a financial company and we have a similar policy around phishing email. Embarrassingly, I failed this once and then created an email rule which filters out the fake Phish. No idea if it gets real Phish.

...and now we see why such policies are bad, and it's even covered in the article: while people falling for phishing are bad, what's even worse is when they fall for it and don't report. Creating a culture where the security is the enemy is _not_ good.

I mean, sure, if it's 20 times, we're getting into outrageous territory and you have reasons to suspect employee is trolling you. But other than that, the reality is that your employees _will_ get phished eventually. Reduce the risk and work on reducing the harm caused when it happens, instead of antagonising your workforce.

Edit: also, if you could just "filter out" the test means that the tests were about as good as most corporate "compliance" training is. Just as the firings, it feels designed more to coddle the C-levels than actually achieve anything.

Re: Should Failing Phish Tests Be a Fireable Offense?

#85
post #7

Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative consequences for employees who repeatedly fall for phishing tests usually create tension and distrust between employees and the company’s security team. This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days.…

When a new phishing test goes out everyone in my department announces to everyone else to watch out for it. So it's a bonding experience of the non-security people against the security people.

It's silly to do it inhouse.

It creates distrust.

That is why you pay consultants. They send out the phishing test, and hopefully regular people bond with the security people in an effort to pass it.

I mean, after all, security and regular people in the company should want the same thing (company success... which implies not giving away things to phishing probes)

Re: Should Failing Phish Tests Be a Fireable Offense?

#86
post #4

How hard is it to make people understand what a business email should or shouldn't include? If you're being asked for data by someone you don't know, either ask a manager or someone connected to the account in question. Are people really so gullible & trusting?

> If you're being asked for data by someone you don't know, either ask a manager or someone connected to the account in question.

Most cases I've seen of successful (or nearly successful) spearphishing would have been solved by someone picking up a phone and calling their co-worker.

"I know you sent me an email, but can you just explain again why you want me to buy $1000 in iTunes gift cards and email them to you?"

"I got that invoice you sent. Just wanted to confirm the amounts -- $50k wire transfer?"

Re: Should Failing Phish Tests Be a Fireable Offense?

#87
post #74

I see this a lot as a security guy. There has to be a healthy medium. Users can be fired, sure, but this should be a last resort. It's not really fair to say "you're fired" when you don't have DKIM/SPF/DMARC, you haven't tagged external emails as such, you haven't provided here awareness training, you have provided training but not in a gradual form (ie. From Nigerian prince emails right the way through to sophistica…

Your organization becomes more secure if people aren't afraid of revealing their mistakes.

Seriously, you should give people who fail phishing tests cupcakes and additional future phishing tests. If there is a continued failure or inability to learn then there is a problem to be fixed perhaps with firing.

Cultures of fear breed disaster.

Re: Should Failing Phish Tests Be a Fireable Offense?

#89

Earlier quoted context omitted.

I recently failed a suspicious email / phishing test for the first time, and I am also one of those people who never thought it would happen to me... The email was a newsletter I didn't care about, and the unsubscribe link was (fake) malicious. That one impressed me because it preyed on what is now a pure reflex to click the unsubscribe link.

From this and other comments in this thread it seems you have failed these phishing tests as soon as you click a link. Is the assumption here that you are completely pwned as soon as you visit an url controlled by an attacker? I can't imagine myself compromising company data/funds via a website where I ended up through a newsletter unsubscribe link so this seems quite unfair on the part of the phish-testers.

If you think visiting a webpage in Chrome, or any other browser, even inside a VM, is totally safe, especially against a nation-state level actor, I have some bad news for you.

Re: Should Failing Phish Tests Be a Fireable Offense?

#90

Earlier quoted context omitted.

I work at a financial company and we have a similar policy around phishing email. Embarrassingly, I failed this once and then created an email rule which filters out the fake Phish. No idea if it gets real Phish.

> Embarrassingly, I failed this once and then created an email rule which filters out the fake Phish. how did it get you, if you don't mind sharing? It seems if someone who works in IT (guessing you do) and is very careful fails it, this is an impossibly high standard to meet. curious how they got you.

I nearly fell for a real fishing link once recently, due to changes that have been made by our IT department.

Firstly all external senders have the mail reformatted with a red bar at the top and some text, and secondly all hyperlinks are forced through a proxy, which makes it effectively impossible to know what the URL is from the email.

I'd received a (rare to my work account) fishing email and I was about to click on a link in there just before I started thinking. I'd been trained to trust emails with the red bar, as most external mail I get is trustworthy, and I reflexively check links before I click them but this was just another going through the proxy.

I'm not sure how much these changes help less technical users, but it made me less secure.

Post reply on HN