Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

261–270 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#261
post #52
post #37

Earlier quoted context omitted.

Presumably you were able to explain your case and have the reprimand expunged from your record. As long as they are reasonable in that way I don't think occasionally testing the people handling sensitive data is a bad idea.

Should it be expunged though? They've indicated they were aware it was quite clearly a phishing attempt, but they still accessed the link. If the test was to see if a user would try accessing the link, then this user failed the test. Why should that be expunged? Curiosity shouldn't preclude security, and intent shouldn't preclude policy if the operator operated knowingly. This isn't to attack maxk42, but to engage th…

> intent shouldn't preclude policy

Oh boy, I hope I never work in this kind of organization.

Re: Should Failing Phish Tests Be a Fireable Offense?

#262
post #68

Earlier quoted context omitted.

Considering that from what I recall Lynx doesn't execute javascript, it would have to be one esoteric zero-day

Lynx has still had remote code execution CVEs in the past. It's probably a smaller attack surface than a regular browser, but far from nonexistent.

It's been over a decade since there was an RCE for Lynx. The difference between the attack surface of Lynx compared to a regular browser is several magnitudes. No code is safe, but giving someone grief over following a link using Lynx is security theater at its worst.

Re: Should Failing Phish Tests Be a Fireable Offense?

#263

Earlier quoted context omitted.

If I’m curious I’ll open the link off the company network. Easiest way I can think of is just opening with a browser on my private iPhone while on a 4G connection.

It would still trigger the fail. Typically the link contains an identifier and the landing page is hosted on a public facing web server.

I wonder what happens when a bot crawls one of the phishing sites and triggers all the unique links...

Re: Should Failing Phish Tests Be a Fireable Offense?

#264

Earlier quoted context omitted.

The city of Toronto would like to hear from you. Our Subway turnstiles keep breaking. And since they’re entry and exit, there’s many methods to enter by triggering the exit side, from umbrellas to a small dog.

The German U-Bahn has a brilliant solution to this. No turnstiles or gates, you're just expected to have a ticket. The penalty for getting caught without a ticket is considered sufficiently high to make "Schwarzfahren" statistically more expensive.

"Screw 'em hard enough for breaking the rules and they'll follow the rules out of fear" is generally not considered to be a good model for organizational policy.

Re: Should Failing Phish Tests Be a Fireable Offense?

#265

Earlier quoted context omitted.

> We expect tiny people making minimum wage to ask thieves to pay for the cheese they’re shoplifting. We don't actually. All sane employers have them record and report the incident and not engage , because petty shoplifting isn't worth somebody getting shot and it's built into the margins anyway. If the store is big enough, they may have "loss prevention", who are people who are very much not tiny and will verbally e…

I’ve heard of policies that cashiers are not to chase, let alone fight, but never that they’re not even supposed to ask someone to pay. Is that really true?

It might vary by chain, but everywhere I'm familiar with you're not supposed to accuse people of stealing, which has the same effect, perhaps for different reasons.

Re: Should Failing Phish Tests Be a Fireable Offense?

#266
post #94

Earlier quoted context omitted.

Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.

> Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? I have zero experience with this, but I imagine the policy would be "Don't enter the building if someone is too close behind you." If you don't feel comfortable asking for space (fine!), turn around, go back to your car, and call building se…

I would also expect that if you immediately reported that someone tailgated to security, that it is no longer a fire-able offence.

Re: Should Failing Phish Tests Be a Fireable Offense?

#267
The fortune 50 company I work for sends out what I must consider the stupidest phishing test emails I've seen. They are blatantly simplistic and transparent.

I have had this fantasy of trying to see if I could trick the IT people who send them with a phishing attempt. It would involve perhaps reporting that my virus scanner had reported something suspicious in an email to get them to open something.

Or maybe register mimecastprotection.com, then send out a fake email to IT as if it was a big marketing announcement from Mimecast that "We've changed our name! We are now Mimecast Protection as part of our commitment to serving you!"

My theory is that a really well crafted phishing email is going to be very hard to avoid.

Re: Should Failing Phish Tests Be a Fireable Offense?

#268
post #231

I might consider this - if my employer gave me tools to deal with looking at email headers, etc etc etc. That means iff I have to use Outlook/Exchange, and nobody will tell me what the external SMTP server IP address is (and other information) this is unreasonable. I've had two different large, corporate employers do the phishing training thing. I've failed occasionally at both of them. You can make a phish as close…

> 2. Enthusiastic reporting of false positives I used to work in a casino that sent out a notice to all employees urging them to report more suspicious activity. There was no information or training given on what specifically to look for. After some time the initiative was deemed a great success. Although there had been zero improvement in the rate of dangerous activity stopped or prevented, there had been a giant in…

We just implemented the Phishhook Outlook addon. I'm sure our Security team will love getting 9000 emails a day to sort through (3 per day per employee).

Re: Should Failing Phish Tests Be a Fireable Offense?

#269
post #83

Earlier quoted context omitted.

The risk of hitting an exploit on the command line, especially with something like wget, is enough orders of magnitude lower that I think it falls under acceptable. The standard cannot be zero risk because that's impossible. Even shutting off the internet link doesn't get you all the way to zero.

The issue isn't how much risk there is in opening it. The problem is that regardless of how much or little risk there is in opening the link, it wasn't op's job to examine it. It was unnecessary risk to open the link.

  it wasn't op's job to examine it
Your brand of narrow minded thinking is... Well? Let's just call it pathetic.

A brain dead employee, following the letter of the law, by the book, to the bitter end, is, by many orders of magnitude, a greater liability than one that assesses risk and adopts personal responsibility to further investigate a hazard, before taking additional action.

Let's say you have an employee, and they smell smoke, but they aren't the fire warden so they ignore it. Not their responsibility. Instead, they go on lunch break. The fire spreads. The building burns to the ground. Would you be happy that they stayed in their little box, kept their head down, and avoided engaging with a potential hazard?

Before you answer, I bet you're already locked and loaded to distinguish "fire" as a completely different class of circumstances. And you know what?

You'll be completely fucking wrong about that, no matter how you try to twist words and wriggle out of the truth.

Post reply on HN