Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

431–440 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#431
post #417

Earlier quoted context omitted.

You're reminding me of the time I realized that Schwab (a massive American bank/broker) truncated all passwords to 8 characters.

Heh, that's the same company that sends physical mail to me every time I make a trade because they believe that email sent to my personal domain is "undeliverable" and automatically opt me out of e-statements no matter how many times I opt-back in. They have to be losing money on me by paying for so much postage at this point. (And no, nothing is wrong with my email, it's hosted by a professional email host with the…

Earlier this winter, I got a bunch of those letters completely out of the blue. I was also receiving emails from Schwab throughout the several weeks they were sending me a pile of letters saying they couldn't deliver emails to my address. Then the letters stopped.

Re: Thanks FedEx, this is why we keep getting phished

#432
post #243
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

Is it impressive though? They have about a 50% success rate delivering things to me across multiple addresses and I know other people who have had similar long term issues.

in my country fedex isn't popular, but I had one international package delivered by them and I was very positively surprised because they paid duties for me to speed up process and invoiced me that costs.

Re: Thanks FedEx, this is why we keep getting phished

#433

Earlier quoted context omitted.

I can’t believe it’s 2024 and we are still seeing bugs with handling “special” characters. Unicode has been here for how long? Robust string handling is supported in every language. There is no such thing as a special character. My name should be able to contain Chinese characters. My password should be able to contain emojis. What is this Stone Age shit still running on companies’ backends?

Companies aren’t rewriting their entire stack or even upgrading across major versions basically ever.

Alright cool but maybe they can put the exact phrase "IF you put an ampersand in your password, your account will be bricked and we wont help you with it" on the password form.

Re: Thanks FedEx, this is why we keep getting phished

#434
post #243
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

Is it impressive though? They have about a 50% success rate delivering things to me across multiple addresses and I know other people who have had similar long term issues.

That’s a bit better than my experience with DHL :) they’ve delivered packages to random people multiple times across the UK, France, Switzerland and South Africa. Important documents they’ve handed over to strangers, like my passport, for example…

Re: Thanks FedEx, this is why we keep getting phished

#435
post #343

Earlier quoted context omitted.

Not directly. However NIST is admissible in court and so if someone sues there is now evidence that they should have known better.

Anything is admissible in court, the judge merely has to allow it. There are 1000s of such organizations, and many conflict with each other. My point is, it's inaccurate to say you are liable for not following NIST. I could easily say you could be liable, for not following me. Does that make it so? No.

NIST SP 800-63B is informative, not normative. It codifies existing industry-standard best-practice, but is not in itself law. However, not following best-practices may be argued as negligence if it leads to a breach or decrease in shareholder value.

Re: Thanks FedEx, this is why we keep getting phished

#436
post #81

Earlier quoted context omitted.

Even worse, is where attempts to query that security is actively punished. like this case: https://news.ycombinator.com/item?id=37250024

My UK bank semi-regularly cold-calls me and ask me to authenticate by providing personal information. When I decline they readily tell me instead to call some number available on the bank website. So they not only are incompetent, they actually know it.

why? isn't getting the number from the website the right action? you can verify that you have the bank website, get the right number, and i presume even go to the bank branch to get the number in person, and then save the number as it should not change.

or are you referring to the call itself? i wonder why they need to do that.

Re: Thanks FedEx, this is why we keep getting phished

#437
post #332

Earlier quoted context omitted.

I assume you know that you can open a claim? They'll either find your package really fast, or will have to pay its full value. Often the vendor has to initiate the claim. If the vendor doesn't want to open a claim, refund. If the vendor doesn't want to refund, chargeback.

Be careful about those chargebacks. I bought two new pixel phones directly from Google and only one arrived. Google support was of course awful and Fedex did absolutely nothing outside of asking me what color the phone was. lol I ended up reversing charges for the missing phone and Google immediately wrecked me - I was using Fi at the time so they killed my cell service and killed my ability to use Google Pay for any…

Retaliation for charge back probably elevates this from a civil matter to a criminal one; you should totally contact your local DA. They might think it's fun.

Re: Thanks FedEx, this is why we keep getting phished

#438

Earlier quoted context omitted.

They ask for an ID whenever you use an account number. I have to FedEx stuff to my home address for work. The guy at the counter is always perplexed when I tell him the destination address is the same one as the one on my ID.

Maybe if you do it in person, but they must have direct shipping flows where nobody checks.

oh wow, that is incredibly dumb.

Re: Thanks FedEx, this is why we keep getting phished

#439
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

I bought an OP-1 from teenage engineering years ago and fedex delivered it inside of the mailbox. USPS removed the fedex package from the mailbox and impounded it at our local USPS post office without ever notifying me. After 1-2 months of waiting/assuming the package had been stolen, I call the USPS office and asked if they somehow had the package in their custody/possession and, lo-and-behold, they did (in the "undeliverable mail room") and started lecturing me about how it was illegal for fedex to deliver a package into the mailbox, which is usps/government property etc. etc.

I called Fedex to try to rectify this and, as far as I remember, they either never answered the phone or told me they had no way of contacting the delivery driver (??).

I've always avoided fedex (and UPS, for that matter, since they destroyed two antique lamps that I ordered through ebay) since then.

Re: Thanks FedEx, this is why we keep getting phished

#440
post #243

Earlier quoted context omitted.

Is it impressive though? They have about a 50% success rate delivering things to me across multiple addresses and I know other people who have had similar long term issues.

Can I ask where you live? I'm 40 and have never had anything get lost in the mail, ever. Is it a big city thing or something?

When we lived in San Jose, CA, we had stuff which never arrived quite often. Birthday cards and such especially.
Post reply on HN