Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

131–140 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#131

Earlier quoted context omitted.

From this and other comments in this thread it seems you have failed these phishing tests as soon as you click a link. Is the assumption here that you are completely pwned as soon as you visit an url controlled by an attacker? I can't imagine myself compromising company data/funds via a website where I ended up through a newsletter unsubscribe link so this seems quite unfair on the part of the phish-testers.

If you think visiting a webpage in Chrome, or any other browser, even inside a VM, is totally safe, especially against a nation-state level actor, I have some bad news for you.

You would literally have to never click on any link that isn't 100% under your own control in that case. Yes 0-days exist, but if I'm in an environment where that level of security is necessary, why do I even have access to a web browser?

Re: Should Failing Phish Tests Be a Fireable Offense?

#132

Earlier quoted context omitted.

I recently failed a suspicious email / phishing test for the first time, and I am also one of those people who never thought it would happen to me... The email was a newsletter I didn't care about, and the unsubscribe link was (fake) malicious. That one impressed me because it preyed on what is now a pure reflex to click the unsubscribe link.

From this and other comments in this thread it seems you have failed these phishing tests as soon as you click a link. Is the assumption here that you are completely pwned as soon as you visit an url controlled by an attacker? I can't imagine myself compromising company data/funds via a website where I ended up through a newsletter unsubscribe link so this seems quite unfair on the part of the phish-testers.

That's exactly how my organization does it as well. I had to go to an incredibly asinine training because I clicked on a fake phishing link after verifying that the domain was owned by a computer security company that sold phishing prevention services. The link just went to a static "you could have been phished" page and a few weeks later I got an email telling me that I had to got to a phishing awareness training. There was no attempt at all to actually collect any credentials from me.

Re: Should Failing Phish Tests Be a Fireable Offense?

#133

Earlier quoted context omitted.

I work at a financial company and we have a similar policy around phishing email. Embarrassingly, I failed this once and then created an email rule which filters out the fake Phish. No idea if it gets real Phish.

...and now we see why such policies are bad, and it's even covered in the article: while people falling for phishing are bad, what's even worse is when they fall for it and don't report. Creating a culture where the security is the enemy is _not_ good. I mean, sure, if it's 20 times, we're getting into outrageous territory and you have reasons to suspect employee is trolling you. But other than that, the reality is t…

This can be equalized by having a perk or bonus on reporting phishing attacks to IT. Anything from casual Friday (for offices that are not relaxed wear) to a Starbucks card or whatever. IMHO the act of timely reporting the click on a phishing email should negate the email click penalty. The idea is make the wanted behavior pleasurable and the unwanted ones painful.

Re: Should Failing Phish Tests Be a Fireable Offense?

#134
post #104
post #94

Earlier quoted context omitted.

Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.

That’s not true. My workplace has employee only entrances where even visitor/temporary badges don’t work. No one is standing guard and they tell everyone to not allow tailgating.

That's the point. I was in the infantry, am 6'2, and a guy. I don't have a problem with challenging folks who are tailgating. That is not the case for everyone. Do you expect disabled folks to challenge tailgaters? What about physically small people? Setting aside the office dynamics around discrimination issues, how many people actually have the confidence to challenge an unknown person who is tailgating, knowing that there are practically no repercussions for allowing it, versus the fallout of alienating coworkers, potentially senior folks who might react negatively?

It's one thing to say "don't let people tailgate", it's quite another to actually enforce a policy that says that unless you provide proper physical security onsite. During security awareness training I always stress that people know who to notify onsite as well as telling them that they can choose to challenge them directly if they encounter someone tailgating.

Re: Should Failing Phish Tests Be a Fireable Offense?

#135
post #55

Earlier quoted context omitted.

I recently failed a suspicious email / phishing test for the first time, and I am also one of those people who never thought it would happen to me... The email was a newsletter I didn't care about, and the unsubscribe link was (fake) malicious. That one impressed me because it preyed on what is now a pure reflex to click the unsubscribe link.

Did the link take you to a site that auto-ran malware? Or did it take you to some kind of page that said "login to unsubscribe"? The latter is why password managers can be so valuable. I never type my passwords in so if my auto-fill doesn't activate I immediately become suspicious. If it's the former, it seems like your company must be using an insecure browser or the site was running some kind of 0-day? I never thin…

When my organization does these, the link just goes to a static page that says "you could have been phished". The fact that in fact no serious attempt at phishing has yet taken place and that my work machine is far too insecure if they're worried about browser 0-days seems totally lost on them.

Re: Should Failing Phish Tests Be a Fireable Offense?

#136

Earlier quoted context omitted.

Sure, that's an explanation for those sorts of jobs, but they aren't usually a target of phishing attempts.

I'm pretty sure something like phone banks (in or out-bound) are filled with low-skill workers whose credentials would be valuable to data thieves. I've worked low wage jobs for the Government and Private Industry where we were hit with ransomware and phishing attacks. I think you are underestimating how many workers are really in that position. I'm not sure if you're American, but it's very common in America.

I claim: Out of the fraction of jobs that fit the description you gave, fewer than half are realistic targets to phishing. Of the fraction of jobs that are realistic targets to phishing, fewer than half fit the description you gave. That's more than is necessary to make my question relevant.

Re: Should Failing Phish Tests Be a Fireable Offense?

#137
post #44

Earlier quoted context omitted.

There's was the general "don't follow links in unknown emails" but nothing about what to do if you're sure it's a bad email but terminally curious. As far as I could tell nothing bad could happen (even JS was off in the browser I used to open it) when I followed the link, but is there something I should be aware of?

Worry about CSS-based exfil. https://www.mike-gualtieri.com/posts/stealing-data-with-css-... The security teams are correct in the training they run about these: report the suspicious email and leave the investigation to them, don't try to DIY the investigation. Note you aren't penalized for false positives (reporting a legitimate email as a phishing attempt).

I don’t understand this attack: if attacker can control CSS on the page - then they probably can also control javascript. Which means they can extract any data from it.

Re: Should Failing Phish Tests Be a Fireable Offense?

#138
post #94
post #58

Earlier quoted context omitted.

I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…

Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.

Tailgating is a problem when you must keep a log of employee entries (and possibly exits).

If you’re just trying to ensure only employees are on-site, tailgating is less of an issue (unless somebody got fired but their colleagues were never told).

Re: Should Failing Phish Tests Be a Fireable Offense?

#139
post #25

I'm a tech professional and security is a regular part of my jobs. At one point -- while contracting for a Fortune 500 client that shall remain unnamed -- I received an email that was quite clearly phishing. Curious as to what the payload was and whether it was worth reporting, I fired up lynx and followed the link in the email from the command line. I was promptly informed that I had failed the test and I would be r…

If I’m curious I’ll open the link off the company network. Easiest way I can think of is just opening with a browser on my private iPhone while on a 4G connection.

Re: Should Failing Phish Tests Be a Fireable Offense?

#140
post #58

Earlier quoted context omitted.

I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…

I rather like my buildings' set up for this— We have passcarded doors and then inside we have gates like many subway stations do that are timed only long enough for one person to pass through. So I can hold the door open for someone on the way in—especially if they have their badge out— but there's nothing I can do about those giant plexi gates once inside. They have to swipe.

The city of Toronto would like to hear from you. Our Subway turnstiles keep breaking.

And since they’re entry and exit, there’s many methods to enter by triggering the exit side, from umbrellas to a small dog.

Post reply on HN