Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

161–170 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#161

Earlier quoted context omitted.

From this and other comments in this thread it seems you have failed these phishing tests as soon as you click a link. Is the assumption here that you are completely pwned as soon as you visit an url controlled by an attacker? I can't imagine myself compromising company data/funds via a website where I ended up through a newsletter unsubscribe link so this seems quite unfair on the part of the phish-testers.

This is exactly the case. If you click on a link in the fake phishing email you've failed the test. It does not require you to install anything, open an attachment, etc.

I was once at a place where the company homepage was owned. Fun times.

Just starting your web-browser would exécuté some Java vuln and scareware you.

Re: Should Failing Phish Tests Be a Fireable Offense?

#162
post #71

As an employee education campaign, my last Bigco employer started sending out their OWN phishing emails, and if you clicked a link in one of them, you'd be taken to a page explaining how you got tricked and what not to do. Pretty good way of targeting the message to those who need it most.

That's pretty standard. The problem is that they don't actually attempt to phish you. These emails are only good if your security model is that you can't click untrusted links (i.e. you want to defend against browser 0-days). If that's the security model, why do I even have a browser on my computer? In fact, my organization's policy says that I'm allowed to use my work computer for personal business (like reading a HN article while I'm taking a break)... If they have no problem with me browsing reasonable parts of the public internet, they have no business failing me on a phishing test that never even asks for any credentials.

Re: Should Failing Phish Tests Be a Fireable Offense?

#163
post #134

Earlier quoted context omitted.

That's the point. I was in the infantry, am 6'2, and a guy. I don't have a problem with challenging folks who are tailgating. That is not the case for everyone. Do you expect disabled folks to challenge tailgaters? What about physically small people? Setting aside the office dynamics around discrimination issues, how many people actually have the confidence to challenge an unknown person who is tailgating, knowing th…

You are getting really hung up on a very tiny edge case. No reasonable manager would punish you for being physically overpowered. That doesn't mean you should encourage people to ignore the security policy. 99.99% of the time, saying to the tailgater "you need to swipe" is enough. If you do work somewhere where people are physically trying to break in often, then you ought to have real security personnel.

It's not about being punished for being physically overpowered - it's about being a five foot 3 intern and having someone 6'1 250 lbs, in a suit and in a hurry, behind you, tailgating.

The implications are enough to make it a shitty situation for such a person have to turn around and say "sorry person that looks c-suite, you can't come in with me."

Re: Should Failing Phish Tests Be a Fireable Offense?

#164
post #81

Earlier quoted context omitted.

> I never think twice about clicking links. I hope you don't work for any sensitive position.

It's a valid comment, but if you're in a position where you are worried about 0-days from random web browsing then you should be using the internet on a fully segregated machine. If Firefox or Chrome has an RCE + privilege escalation in it that can be triggered just from browsing to a page then, congrats, you got me.

The recent CPU-level vulnerabilities have exploits that can run in the browser. See https://www.zdnet.com/article/intel-cpus-impacted-by-new-zom... for pointers to video evidence. They're not zero-day attacks once they're made public, just the same as Meltdown and Spectre. Go download the PoC code, switch calc.exe to something useful, and phish away.

https://news.ycombinator.com/item?id=20028108 from earlier this week shows that just loading a page can lead to network information disclosure or other compromise / attack vectors. It's not a zero-day, it's a feature.

Re: Should Failing Phish Tests Be a Fireable Offense?

#165

Is someone trying to apply AI and Deep Learning to phishing attacks? One of the things which PG noted in "A Plan for Spam" back in the day, was that the Bayes classifier found markers of Spam he never would have thought of. http://www.paulgraham.com/spam.html If Phishers are concentrating on fooling human beings in the same way that spammers were back in the day, they might be vulnerable to such techniques.

That is such a fascinating document. Back in late 2002 or early 2003 I did an implementation of the algorithm in that document in C (because I didn't understand Lisp) with the help of a more senior programmer at my company.

Once my implementation started to work I was really amazed how such a simple algorithm could be so successful.

Re: Should Failing Phish Tests Be a Fireable Offense?

#166
post #4

How hard is it to make people understand what a business email should or shouldn't include? If you're being asked for data by someone you don't know, either ask a manager or someone connected to the account in question. Are people really so gullible & trusting?

Have you ever worked for a big company? (Think several US offices, half a dozen European and Asian offices, 500m in revenue). Someone forwards me an e-mail from our Dutch office that says, essentially, "The world is burning down, we are boarding a plane in a couple of hours to go to IFA (show), and we don't have the latest copy of product X to demo for customers." I do builds by hand of this product because I can't g…

Maybe that's how it is at your big organization. I'm sure glad my big organization is different.

Re: Should Failing Phish Tests Be a Fireable Offense?

#167
post #4

How hard is it to make people understand what a business email should or shouldn't include? If you're being asked for data by someone you don't know, either ask a manager or someone connected to the account in question. Are people really so gullible & trusting?

I suspect hiring practices and company culture may be selecting for gullability either accidentally or deliberately in many cases (cynically the gullible are easier to motivate cheaply). Like how "being a team player" is used to refer to willingness to work unpaid overtime as opposed to actual ability to cooperate.

If they value "responsiveness to their authority over procedure" then people will send the entire financial records to "the CEO" for fear of getting fired otherwise.

Re: Should Failing Phish Tests Be a Fireable Offense?

#168

Earlier quoted context omitted.

> a pure reflex to click the unsubscribe link. That's a learned trait. I don't click unsubscribe links; I click "report spam" and "report phishing" button. If only Gmail would let me create filters to automatically mark entire domains as spam though. That would be nice...

One of the reasons you'll pry Evolution from my cold dead hands is Right Click -> Create Filter -> @domain.co.uk and done. I have filters for almost everything, my boss goes into one folder and gets set one color, automated notifications from my internal system another (green if everything is OK, orange if there is something I really need to look at). What I really* want is a desktop client that exposes a nice clean…

What happens when one of those blocked domains becomes a vendor for your org?

Re: Should Failing Phish Tests Be a Fireable Offense?

#169

Earlier quoted context omitted.

Did you alter the URL at all? Every phishing test campaign I've seen has a URL in the form of like http://totallylegit.your-company.com/somePath/login?id=12345... . I'd change the id= to some other value before testing to mess with their tracking.

Unless you're certain how that ID is generated and/or linked to your identity, you've probably just put someone else at your company on the naughty list.

Seems like you should just hit all the IDs to be safe. Or put your own personalized message in the ID parameter.

id=SSBsaWtlIFN3ZWRpc2ggUGhpc2g

Re: Should Failing Phish Tests Be a Fireable Offense?

#170
post #94
post #58

Earlier quoted context omitted.

I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…

Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.

> Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building?

I have zero experience with this, but I imagine the policy would be "Don't enter the building if someone is too close behind you."

If you don't feel comfortable asking for space (fine!), turn around, go back to your car, and call building security as necessary.

Is this shortsighted?

Post reply on HN