It's impossible to overestimate the power of expectations to create trust (even in the face of contrary indications). This just almost happened to me this week: A couple of days ago I wrote an email to a friend I hadn't been in touch with for several years. A day later I got a message from him on Facebook with what looked like a YouTube link and the cryptic message, "It's you?" I didn't want to see myself on a random…
Okay but let's be clear. Clicking a link won't steal your information. Going to a bad link and giving your details is how you are phished.
I was seven words away from being spear-phished
51–60 of 187 posts
Re: I was seven words away from being spear-phished
#52Earlier quoted context omitted.
To be honest, that's probably overboard. You're pretty much never liable for fraudulent fiat transactions. Crypto on the other hand...
Part of the fallout from fraud isn't being afraid of losing money. Banks and credit unions are generally on your side when it comes to disputing fraudulent charges. The hassle is getting it all sorted out - verifying identity with sometimes completely inept telephone reps, replacing cards, entering new payment information for recurring charges, etc.
Re: I was seven words away from being spear-phished
#53This is a fascinating story. It's funny though how, with compromised accounts at a highly reputable university and a 0-day exploit in one of the most-used pieces of software out there, they still managed to make basic grammatical errors in their phishing email. I mean, these people were clearly not messing around. Their attack(s) were highly targeted. And yet they still didn't check their written english! If it hasn'…
I once read a theory that poor grammar, particularly with 419 scams, acts as a sort of gullibility filter where only the most susceptible targets will respond.
Re: I was seven words away from being spear-phished
#54Earlier quoted context omitted.
I once read a theory that poor grammar, particularly with 419 scams, acts as a sort of gullibility filter where only the most susceptible targets will respond.
In this case though, since the zero day runs without consuming the attacker's time, what is to be gained by filtering out less-gullible people? If it's automated, why not cast as wide a net as possible?
Re: I was seven words away from being spear-phished
#55Earlier quoted context omitted.
I've also seen High School used in Scotland
Cane here to say the same thing, e.g. https://en.m.wikipedia.org/wiki/Inverkeithing_High_School Although, there's a subtle difference vs US usage: in Scotland High School is only used in the context of the name of a specific school, not as a term for the generic concept. E.g. "What secondary school did you attend?"; "I went to The High School" (meaning the Royal High School in Edinburgh). You'd never say "What high s…
Re: I was seven words away from being spear-phished
#56It's always nice to get a good healthy dose of paranoia in the morning. This makes me think back to how my sec professor had a separate system that he'd use to access his online banking.
Re: I was seven words away from being spear-phished
#57I suppose it's easy to "Monday Morning Quarterback" this one, especially after we now know it's a hoax, but honestly this is more fuel on the fire of: Never respond to random people on the internet asking you for information or to do something. Random people knocking on your door are almost always selling something, and random people contacting you over the Internet are almost always scammers. The story could have en…
I deal with this personally all the time, as the founder of a national conference series. We reach out to people cold all the time and invite them to prominent speaking roles. Sometimes people are surprised to hear from us or don't think of themselves as public speakers but we're most certainly real and serious.
I get it the other way all the time now too, people reaching out wanting to partner, work together, have us write articles about them, whatever.
These are all super common use cases. There's a lot of business that gets started by an introduction from a random person on the internet.
Re: I was seven words away from being spear-phished
#58Earlier quoted context omitted.
.ac.uk emails get spam filtered pretty harshly.
really? why?
Traditionally students got a lot of leeway with running their own stuff maybe there have been a few doing not-good-things?
Lots of academics who don't take security seriously have had more admin access to live servers than they should and then stuff like the article happens?
Re: I was seven words away from being spear-phished
#59Cool post. One small nitpick: > Neil describes his pre-university education as “High School”. We don’t have “High School” in the UK - we call it “Secondary School” Not true at all I'm afraid. Where I'm from (Norwich) we had First / Middle / High School / (Sixth Form or college) splits, alongside other schools that did the Primary / Secondary / 6th split.
Re: I was seven words away from being spear-phished
#60I presume that I can I take it from the lack of comment on the Firefox angle that there are no concerns that Firefox is inherently less secure than Chrome?
Really, the best way to protect yourself is to use an obscure OS, or a separate machine for web browsing. Sounds paranoid, but the web is THE main attack vector these days.