Earlier quoted context omitted.
I ordered a computer from Southern California, they shipped it to Texas, Florida, Maine, and then back to Northern California. My last two orders were just stolen from someone at FedEx. They got the shipment, but it never left the facility after that. Customer service is an offshore apology machine that can't help with anything. I used to prefer fedex, but the standard of service is so subpar I go out of my way to av…
I assume you know that you can open a claim? They'll either find your package really fast, or will have to pay its full value. Often the vendor has to initiate the claim. If the vendor doesn't want to open a claim, refund. If the vendor doesn't want to refund, chargeback.
Thanks FedEx, this is why we keep getting phished
361–370 of 576 posts
Re: Thanks FedEx, this is why we keep getting phished
#362Re: Thanks FedEx, this is why we keep getting phished
#363A while ago my wife applied for a home equity loan. At some point I got a call from someone claiming to be from the bank she had applied through (I forget which one), calling to make sure I approved the loan since the home is in both our names. He asked for my name, which I gave him, and then the last four digits of my social security number, which I also gave him. He then proceeded to ask for my full social security…
I'm super paranoid about even the last four. The first five digits of an SSN were algorithmic for most of US history, and still mostly are but a tiny bit more random entropy, and can be narrowed down with mostly only the city in which you were born and what year. You can often use basic k-means clustering to find it even without that information. More often than not entire families share the first five (or close to it) and you only need to phish one family member to k-means cluster the five digits for the rest.
The last four are more often than not the most significant digits in terms of identification and entropy. Masking the rest is almost silly for most Americans. Our masking schemes have actually made phishing easier because people feel safer sharing just the last four, when for most those are the only four that matter.
SSN was never intended to be a secret so its design is horrifyingly bad for something that has come to be a huge secret in banking and healthcare and so many other industries. Recent SSN changes have made it a little better for anyone born after roughly 2010, increasing somewhat the entropy in the first five, but the rest of us have problems that we can't solve easily and banks should be ashamed they helped lead us to these problems.
Re: Thanks FedEx, this is why we keep getting phished
#364These emails are the _exact same form_ that a phishing email would take.
Re: Thanks FedEx, this is why we keep getting phished
#365Earlier quoted context omitted.
> My password should be able to contain emojis. It's probably better if it shouldn't. It's generally better to prevent passwords from containing characters that can't be entered on a decent proportion of devices you may encounter. Emojis are particularly problematic because new ones keep being added which require OS upgrades, and you might find yourself needing to log in from another device that just doesn't support…
With built in emoji entry keywords in every modern OS how many devices are left that can't type emoji? Even if you plan to restrict to Unicode Version N - 1 or N - 2 where N is the current version to avoid "user can't type password on older hardware", the proportion of emoji you can reliably type today on just about any device is huge.
Emoji weren't officially supported until Unicode 6.0, though there are a subset of current emoji (less than a quarter) that work on Windows 7 in practice.
Meanwhile the current standard is 15.1.
There's no security or convenience necessity whatsoever for supporting emoji in passwords, but inconsistent OS support is an excellent reason against it.
Re: Thanks FedEx, this is why we keep getting phished
#366It's absurd.
Re: Thanks FedEx, this is why we keep getting phished
#367Wow, I thought this was a great post, and I'm just dumbfounded about how egregiously bad that first SMS was - FedEx might as well tell the recipient they want to customs duties wired to a Nigerian prince. But I also disagree with the general push of Troy Hunt's recommendations. That is, we should just take the base assumption that humans, generally, can't distinguish between real and phishing inbound messages. That's…
I don't think Troy Hunt is recommending what you're suggesting at all? The very beginning of the post starts with: > but I'm a smart human so I don't fall for this (that's a joke, read why humans are bad at URLs). It's clear that he thinks relying on heuristics to distinguish scammy URLs is not a scalable long term approach.
1. The entire article is about a (surprisingly) legit FedEx SMS looking totally spammy. My point is that we should take "looking totally scammy" completely out of our vocabulary, and pointing out similarities or differences in scam vs real notifications only furthers the notion that they're distinguishable in the first place. Again, to emphasize, I still think this overall was a great article highlighting the ineptitude of FedEx sending such egregiously bad notifications in the first place
2. Hunt says exactly this in the article "But if I were to take a guess, they've merely blocked the tip of the iceberg. This is why in addition to technical controls, we reply [sic] on human controls which means helping people identify the patterns of a scam: requests for money, a sense of urgency, grammar and casing that's a bit off, add [sic] looking URLs." My point is we should stop "helping people identify patterns of a scam". We should instead just teach people to treat all incoming notifications as suspect and to never follow a link/phone number from an incoming message.
Re: Thanks FedEx, this is why we keep getting phished
#368A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…
Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…
Combined with the fact that the largest single source of spam I'm seeing right now is also coming from random tenant GUIDs .onmicrosoft.com (is Azure really missing that much SMTP security for random M365 tenants?) and this sort of corporate anti-training users to follow bad transactional email links, it certainly feels like we are in a perfect storm of M365 phishing.
Re: Thanks FedEx, this is why we keep getting phished
#369Earlier quoted context omitted.
If you give me your mailing address, I'll arrange it that the bank will mail you one, too. Just be sure to use the included NOTVIRUS.EXE viewer for best experience.
In your fantasies. It is of course in the responsibility of the bank to check if this is virus free. I am using Linux anyway.. No autorun.exe here. Is this still a thing with Windows?
Hyperbole, but it's like a bank employee calling you from an unknown number and asking for your email password so they can make sure their communications about your mortgage application don't go to the spam folder.
Re: Thanks FedEx, this is why we keep getting phished
#370I called my provider. Turns out the actual insurance is handled by a sub-provider that works for a different (major) insurance... WTF