Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

91–100 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#91
post #25

I'm a tech professional and security is a regular part of my jobs. At one point -- while contracting for a Fortune 500 client that shall remain unnamed -- I received an email that was quite clearly phishing. Curious as to what the payload was and whether it was worth reporting, I fired up lynx and followed the link in the email from the command line. I was promptly informed that I had failed the test and I would be r…

Counting opening a mail as failing is ridiculous. A a phising test should only count captured logins.

Re: Should Failing Phish Tests Be a Fireable Offense?

#92

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

This is a great idea for defense contractors, and (probably) an exceptionally draconian idea for most other workplaces.

Seagate had all of its employees W2s phished because someone in HR messed up badly. If you have access to PII or other confidential information, phishing is a big deal.

Re: Should Failing Phish Tests Be a Fireable Offense?

#93
post #58

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…

If you really don't want tailgating, put in a man trap.

Re: Should Failing Phish Tests Be a Fireable Offense?

#94
post #58

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…

Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building?

Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.

Re: Should Failing Phish Tests Be a Fireable Offense?

#95

Earlier quoted context omitted.

From this and other comments in this thread it seems you have failed these phishing tests as soon as you click a link. Is the assumption here that you are completely pwned as soon as you visit an url controlled by an attacker? I can't imagine myself compromising company data/funds via a website where I ended up through a newsletter unsubscribe link so this seems quite unfair on the part of the phish-testers.

If you think visiting a webpage in Chrome, or any other browser, even inside a VM, is totally safe, especially against a nation-state level actor, I have some bad news for you.

With that logic just having your mail client/web mail parse a malicious mail from a nation-state level actor is enough to compromise your machine.

Re: Should Failing Phish Tests Be a Fireable Offense?

#96
post #16

Earlier quoted context omitted.

What about the sending and reply-to address? If the account is actually compromised at a system level, that is an IT issue. Again, are people so trusting that they don't check when asked for confidential data?

Sending addresses can be spoofed.

But wouldn't you reply to the address it specified instead of the source of the spoofing? I thought that was why most phishing emails include a link rather than asking you to reply.

Re: Should Failing Phish Tests Be a Fireable Offense?

#97
post #25

I'm a tech professional and security is a regular part of my jobs. At one point -- while contracting for a Fortune 500 client that shall remain unnamed -- I received an email that was quite clearly phishing. Curious as to what the payload was and whether it was worth reporting, I fired up lynx and followed the link in the email from the command line. I was promptly informed that I had failed the test and I would be r…

Can't speak to whether a reprimand is warranted or not and I think many here will disagree, but unless your job is investigating phishing, you shouldn't do this because you ARE ultimately putting the corporate network at risk unnecessarily - what if it was a real link and happened to exploit a zero day on your box? Management wouldn't accept your reasoning for following the link I suspect.

I doubt most if not all exploits would work in lynx/links.

But your point is spot on, don't take it upon yourself to do things that aren't in your job description. Otherwise you become that person who takes it upon themselves to "fix" things and makes the problem worse for the people responsible for fixing things.

Re: Should Failing Phish Tests Be a Fireable Offense?

#98

Earlier quoted context omitted.

I recently failed a suspicious email / phishing test for the first time, and I am also one of those people who never thought it would happen to me... The email was a newsletter I didn't care about, and the unsubscribe link was (fake) malicious. That one impressed me because it preyed on what is now a pure reflex to click the unsubscribe link.

> a pure reflex to click the unsubscribe link. That's a learned trait. I don't click unsubscribe links; I click "report spam" and "report phishing" button. If only Gmail would let me create filters to automatically mark entire domains as spam though. That would be nice...

Heh, you could make a phishing attempt that looks like a really bad phishing attempt, and inside of it have a link that says "CLICK HERE TO REPORT SUSPECTED PHISHING ATTEMPT TO IT"
Post reply on HN