Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

321–330 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#321
In the real world, i.e. Evolution, if you fall for the predator’s camouflage, you help your species thrive by removing yourself from the gene pool. If your fellow herd-members see you being taken down, that has a tendency to raise their awareness. If not then they follow the same evolutionary path…

Re: Should Failing Phish Tests Be a Fireable Offense?

#322

Phish tests need to be fair to people who actually understand something about security. "Opening an email" is not actually an issue (spearphishers that sit on drive-by 0-days in current browsers or email programs are not a threat model that most orgs can possibly defend against). Opening attachements is hard to measure and again needs context: What kind of software and sandbox was the attachement opened with? Attacke…

This definitely needs to be considered. I open WSL and use curl on suspicious looking email links. I've been logged as doing so before. I'd hate for that log to actually go somewhere significant.

Re: Should Failing Phish Tests Be a Fireable Offense?

#323

Earlier quoted context omitted.

The German U-Bahn has a brilliant solution to this. No turnstiles or gates, you're just expected to have a ticket. The penalty for getting caught without a ticket is considered sufficiently high to make "Schwarzfahren" statistically more expensive.

"Screw 'em hard enough for breaking the rules and they'll follow the rules out of fear" is generally not considered to be a good model for organizational policy.

I feel you've made a huge blanket statement here. Militaries are one organisation where the rules have really sharp teeth and it works well enough. In fact, military organisations have had strong selection pressure applied to them over the past few thousand years and heavy-handed punishments are the norm.

Re: Should Failing Phish Tests Be a Fireable Offense?

#324
post #79

Earlier quoted context omitted.

Downloading and executing code is only one way a browser session can be abused. At the very least you're giving away everything your browser (even Lynx) puts in the headers of a request. That's often a heck of a lot of useful information for an attacker. Lynx supports cookies too so it would be possible to track a user between sessions. I don't know how that might benefit an attacker but I'm not an attacker[1]. I thi…

>At the very least you're giving away everything your browser (even Lynx) puts in the headers of a request. Which you're giving away any time you browse any external web site. >Lynx supports cookies too so it would be possible to track a user between sessions. You're downloading cookies for most external web sites. If the worst you do is the same as going to espn.com, then reprimand people for going to any external w…

The point is that you're giving data to a known phishing site by visiting the link in a phishing email. It's true that ESPN might also be a phishing site but it's less likely.

Re: Should Failing Phish Tests Be a Fireable Offense?

#325
post #240

Earlier quoted context omitted.

> Your attitude doesn't account for the possibility that since you do business with somebody, you need or want to receive some of their emails. You are incorrect and interpreting my comments very narrowly. Doing specific business with somebody should not give that somebody carte blanch to use my email address for whatever reason they wish. I absolutely can be ruthless in eliminating aspects I don't like and if busine…

And, assuming there are clear and reasonable ways to inform them that you don't wish further communications (as there should be with any professional marketing), you should take that route. Otherwise anything is fair game. But I attended an event and got a follow-up email? Calling that spam is mostly being an asshole.

Why is obtaining a follow-up email from an event impervious to being spam? Attending an event is not consent for marketing. Marking spam as spam is not being an asshole.

I know it sucks when an IP gets burned, but when you're acting in good faith it's a rarity - or has been in my experience.

Re: Should Failing Phish Tests Be a Fireable Offense?

#326

Earlier quoted context omitted.

From this and other comments in this thread it seems you have failed these phishing tests as soon as you click a link. Is the assumption here that you are completely pwned as soon as you visit an url controlled by an attacker? I can't imagine myself compromising company data/funds via a website where I ended up through a newsletter unsubscribe link so this seems quite unfair on the part of the phish-testers.

If you think visiting a webpage in Chrome, or any other browser, even inside a VM, is totally safe, especially against a nation-state level actor, I have some bad news for you.

A nation state level actor will always get in.

Re: Should Failing Phish Tests Be a Fireable Offense?

#327
post #235

Earlier quoted context omitted.

> Embarrassingly, I failed this once and then created an email rule which filters out the fake Phish. how did it get you, if you don't mind sharing? It seems if someone who works in IT (guessing you do) and is very careful fails it, this is an impossibly high standard to meet. curious how they got you.

I guy I worked with fell for one when he was selling his car online, he got an email from an interested buyer (car thief) the linked to a very good replication of the site he was selling it on. The car thief turns up and scouts the location but the give away was that he showed little interest in the car, at which point he went back and checked the email to discover the phishing. Even trained intelligent people have m…

My address bar only disappears when I scroll down. I prefer that.

Re: Should Failing Phish Tests Be a Fireable Offense?

#328
It depends on the industry and their regulatory obligations as well as their risk tolerance. Defense and Finance should have a 3 strikes rule for specific role within their orgs that produce the greatest risk. Health care would be next up and may or may not benefit from a 3 strike rule.

I think a better question would be is Sr Leadership supporting the security and risk mgmt teams in developing proper training as well as implementing and spending the money on the proper controls to help reduce the risk to the end user of being spear phished?

Re: Should Failing Phish Tests Be a Fireable Offense?

#329

Earlier quoted context omitted.

The city of Toronto would like to hear from you. Our Subway turnstiles keep breaking. And since they’re entry and exit, there’s many methods to enter by triggering the exit side, from umbrellas to a small dog.

The German U-Bahn has a brilliant solution to this. No turnstiles or gates, you're just expected to have a ticket. The penalty for getting caught without a ticket is considered sufficiently high to make "Schwarzfahren" statistically more expensive.

While I agree that the solution is brilliant (and obvious), I'd like to note that freeriding (Schwarzfahren) is not statistically more expensive in monetary terms (the fine is not that large, controls are not that frequent and tickets are not that cheap).

The social stigma, unpredictability and inconvenience of having to pay the fine is a big part of it (not having a ticket is just stressful). Another part is that you don't need to prevent freeriding, nor recoup all the lost ticket sales. You just need enough of a nudge to keep most people honest most of the time.

Re: Should Failing Phish Tests Be a Fireable Offense?

#330

Earlier quoted context omitted.

You can wave any object at the sensor. Maybe an unauthorized tag will yield a different beep or make the light flash a different color. Maybe the person in front of you will be in a position to see the light on the reader, maybe they'll notice, and maybe they'll consider it odd. Getting that far, and then actually deciding to challenge you or report it, is a vanishingly small chance. There is no point in badging an u…

Agree. The whole idea of 'challenging tailgating' falls apart because someone walking in after you is not performing a strange act. You would have to actively close the door _on_ people, including your colleagues, which goes against social norms to such an extreme extent that it's just not happening.

With my apartment block people sometimes follow in and I'll ask can I help you or similar if they look iffy.
Post reply on HN