Live data from Hacker News

Want to piss off your IT department? Are the links not malicious looking enough?

phishyurl.com

11–20 of 335 posts

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#12
I know it's a joke and I had a sensible chuckle, but if you want to routinely use it at work, just keep in mind that it's probably gonna make things worse.

Since you can't exhaustively enumerate every good thing or every bad thing on the internet, a lot of security detection mechanisms are based on heuristics. These heuristics produce a fair number of false positives as it is. If you bring the rate up, it just increases the likelihood that your security folks will miss bad things down the line.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#16

I know it's a joke and I had a sensible chuckle, but if you want to routinely use it at work, just keep in mind that it's probably gonna make things worse. Since you can't exhaustively enumerate every good thing or every bad thing on the internet, a lot of security detection mechanisms are based on heuristics. These heuristics produce a fair number of false positives as it is. If you bring the rate up, it just increa…

[deleted]

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#17

Imagine if they later update these links to actually phish people. That'd be pretty funny.

That's what I was thinking -- eventually he'll stop paying for those domains and they'll go up for sale, and a domain taster may find that they are still active enough to use for real phishing.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#18

I know it's a joke and I had a sensible chuckle, but if you want to routinely use it at work, just keep in mind that it's probably gonna make things worse. Since you can't exhaustively enumerate every good thing or every bad thing on the internet, a lot of security detection mechanisms are based on heuristics. These heuristics produce a fair number of false positives as it is. If you bring the rate up, it just increa…

I think the lesson here is that any link in an email is bad. We should just block all of them.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#19
post #18

I know it's a joke and I had a sensible chuckle, but if you want to routinely use it at work, just keep in mind that it's probably gonna make things worse. Since you can't exhaustively enumerate every good thing or every bad thing on the internet, a lot of security detection mechanisms are based on heuristics. These heuristics produce a fair number of false positives as it is. If you bring the rate up, it just increa…

I think the lesson here is that any link in an email is bad. We should just block all of them.

Why not address the problem at its real source and just block emails entirely?
Post reply on HN