Live data from Hacker News

Email from FBI Looks Odd

old.reddit.com

1–10 of 172 posts

Re: Email from FBI Looks Odd

#5
post #3

Would the FBI not establish first contact by mail, in person or at least on the phone? What kind of common sense thinks this is legit.

The news here is the headers look good.

The hackers have the ability to originate legit emails from ic.fbi.gov and they blow it on a spammy phishing campaign with broken English? what a waste..

Re: Email from FBI Looks Odd

#6
post #5
post #3

Earlier quoted context omitted.

The news here is the headers look good.

The hackers have the ability to originate legit emails from ic.fbi.gov and they blow it on a spammy phishing campaign with broken English? what a waste..

It doesn't even seem like phishing; there's no contact info and the sender bounces in a way that seems like it doesn't go to the one who sent it.

Is it general FUD (eroding FBI legitimacy) or a smear campaign against Vinny Troia..?

EDIT: Or it's a diversion of attention; there's something else going on somewhere else that they want to go unnoticed.

Re: Email from FBI Looks Odd

#7
post #3

Would the FBI not establish first contact by mail, in person or at least on the phone? What kind of common sense thinks this is legit.

The news here is the headers look good.

Except that the OP did not post all the information to verify.

The IP address does belong to the fbi.gov (both forward and reverse DNS lookups check out).

The DKIM public key does exist at the given selector [0], but without the complete raw message, it is not possible to verify the signature. He also excluded the authentication-result header from his post.

[0] https://www.mailhardener.com/tools/dkim-validator?domain=cji...

Re: Email from FBI Looks Odd

#8
post #7
post #3

Earlier quoted context omitted.

The news here is the headers look good.

Except that the OP did not post all the information to verify. The IP address does belong to the fbi.gov (both forward and reverse DNS lookups check out). The DKIM public key does exist at the given selector [0], but without the complete raw message, it is not possible to verify the signature. He also excluded the authentication-result header from his post. [0] https://www.mailhardener.com/tools/dkim-validator?domain…

[deleted]

Re: Email from FBI Looks Odd

#9
First reaction - if $Legit_and_Competent_Group believes that a bunch of my infrastructure is compromised, then why the h*ll would they alert me via e-mail? Especially an e-mail full of sensitive details, which has a fair chance of being read by the attackers first.

Re: Email from FBI Looks Odd

#10
post #5
post #3

Earlier quoted context omitted.

The news here is the headers look good.

The hackers have the ability to originate legit emails from ic.fbi.gov and they blow it on a spammy phishing campaign with broken English? what a waste..

Sounds about right. A blue chip I work with had a successful phish against them - the attacker ended up with access to the email inbox of an HR person.

So they tried basic, stupid 419 type scams, with broken English.

They could have pried the entire org wide open - she had masses of private data in her inbox, enough to impersonate or social engineer your way to anywhere.

But instead, they blew it - and blew it so badly the client spent days investigating what this could have been a distraction for, as they pretty much couldn’t believe their luck at the minimal severity of the attack.

It’s like breaking into the federal reserve, thinking it’s a 7/11, and then stealing the ballpoint pens from the cashiers desks.

Either way, it was a helpful experience for them - a vaccination against further stupidity, and they all of a sudden started engaging on their ISMS with gusto and panache.

Post reply on HN