Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

141–150 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#141
Phishing is frankly an embarrassment for the mainstream security community. The temptation is to "blame the stupid users" -- but the truth is that even a script kiddie can take a real email from a mainstream brand, "Save As HTML...", change one link, and resend... and snare even sophisticated victims. This BlackHat talk (https://www.youtube.com/watch?v=Z20XNp-luNA) shows just how easy it is to phish even users who think they are too good to be fooled.

At Inky (https://inky.com) we're using a combination of computer vision, anomaly detection, and domain-specific hacks to identify zero-day phishing emails "from first principles" (as I like to say). And it works! But the pushback from the security establishment is impressive. I like to say that there are two widely-held but false beliefs about phishing: 1) phishing is solved; 2) phishing is unsolvable.

The truth is that we can already see clearly that within 3-5 years machines will be good enough at identifying phishing emails that attackers will move to another vector... but you'd never know it listening to "Security Thought Leaders."

Re: Should Failing Phish Tests Be a Fireable Offense?

#142

I might consider this - if my employer gave me tools to deal with looking at email headers, etc etc etc. That means iff I have to use Outlook/Exchange, and nobody will tell me what the external SMTP server IP address is (and other information) this is unreasonable. I've had two different large, corporate employers do the phishing training thing. I've failed occasionally at both of them. You can make a phish as close…

>That is, I'm just not going to look for, or even open, emails.

How long do you think most people could get away with that without being fired? I'd guess I'd last about a week at most.

Re: Should Failing Phish Tests Be a Fireable Offense?

#143
I know no civilised country which law would allow such a thing. Maybe for military or something, but anything else would simply not fly as it instigated and fake. What if they responded OK in a real situation? Also it would completely kill your workforce morale. Do you really want to run a fear based organisation?

Re: Should Failing Phish Tests Be a Fireable Offense?

#144
post #25

I'm a tech professional and security is a regular part of my jobs. At one point -- while contracting for a Fortune 500 client that shall remain unnamed -- I received an email that was quite clearly phishing. Curious as to what the payload was and whether it was worth reporting, I fired up lynx and followed the link in the email from the command line. I was promptly informed that I had failed the test and I would be r…

If I’m curious I’ll open the link off the company network. Easiest way I can think of is just opening with a browser on my private iPhone while on a 4G connection.

It would still trigger the fail. Typically the link contains an identifier and the landing page is hosted on a public facing web server.

Re: Should Failing Phish Tests Be a Fireable Offense?

#145
post #134
post #104

Earlier quoted context omitted.

That’s not true. My workplace has employee only entrances where even visitor/temporary badges don’t work. No one is standing guard and they tell everyone to not allow tailgating.

That's the point. I was in the infantry, am 6'2, and a guy. I don't have a problem with challenging folks who are tailgating. That is not the case for everyone. Do you expect disabled folks to challenge tailgaters? What about physically small people? Setting aside the office dynamics around discrimination issues, how many people actually have the confidence to challenge an unknown person who is tailgating, knowing th…

You are getting really hung up on a very tiny edge case. No reasonable manager would punish you for being physically overpowered. That doesn't mean you should encourage people to ignore the security policy.

99.99% of the time, saying to the tailgater "you need to swipe" is enough. If you do work somewhere where people are physically trying to break in often, then you ought to have real security personnel.

Re: Should Failing Phish Tests Be a Fireable Offense?

#146

I was just talking to a coworker yesterday and at his previous job part of his security was to go out to the employee parking lot and dump thumbdrives, if they were plugged into the corporate network they would send a message to the security department on the terminal and user account. I actually said to him, no one would be stupid enough to do that, he told me they did this monthly and at least 2 to 3 people would g…

It’s like people don’t have (private) computers anymore. If you get caught doing that, or watching animal porn on your company laptop or whatever, the problem isn’t poor IT training, the problem is that you should have bought your own computer! How are people so eager to look at the thumb drive that they can’t wait until they get home?

Re: Should Failing Phish Tests Be a Fireable Offense?

#147
post #134
post #104

Earlier quoted context omitted.

That’s not true. My workplace has employee only entrances where even visitor/temporary badges don’t work. No one is standing guard and they tell everyone to not allow tailgating.

That's the point. I was in the infantry, am 6'2, and a guy. I don't have a problem with challenging folks who are tailgating. That is not the case for everyone. Do you expect disabled folks to challenge tailgaters? What about physically small people? Setting aside the office dynamics around discrimination issues, how many people actually have the confidence to challenge an unknown person who is tailgating, knowing th…

But you can report that it happened, taking silent note of their details, demeanor,direction, description. Nobody is challenging little Stacey from accounting to take on an intruder barehanded.

Re: Should Failing Phish Tests Be a Fireable Offense?

#148

Earlier quoted context omitted.

This is a great idea for defense contractors, and (probably) an exceptionally draconian idea for most other workplaces.

Seagate had all of its employees W2s phished because someone in HR messed up badly. If you have access to PII or other confidential information, phishing is a big deal.

That’s the problem with HR: the same role deals with lots of outside emails and lots of employee data.

They have to compromise between security and keeping it easy for people to apply.

The more companies that have complicated application portals, the fewer applicants they’ll have. Particularly from occasional job-seekers that already have other jobs.

Re: Should Failing Phish Tests Be a Fireable Offense?

#149
post #58

Earlier quoted context omitted.

I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…

I rather like my buildings' set up for this— We have passcarded doors and then inside we have gates like many subway stations do that are timed only long enough for one person to pass through. So I can hold the door open for someone on the way in—especially if they have their badge out— but there's nothing I can do about those giant plexi gates once inside. They have to swipe.

A company I worked for just had revolving doors for all entrances

Re: Should Failing Phish Tests Be a Fireable Offense?

#150
post #95

Earlier quoted context omitted.

If you think visiting a webpage in Chrome, or any other browser, even inside a VM, is totally safe, especially against a nation-state level actor, I have some bad news for you.

With that logic just having your mail client/web mail parse a malicious mail from a nation-state level actor is enough to compromise your machine.

It happens all the time.

https://thecoinshark.net/microsoft-email-clients-was-hacked-...

Post reply on HN