Live data from Hacker News

Want to piss off your IT department? Are the links not malicious looking enough?

phishyurl.com

71–80 of 335 posts

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#71
post #70
post #60

Earlier quoted context omitted.

> Except that the spam system they use completely mangles the URL... I hate this trend. Like an overused pool of the same "Secret Questions" every company asks, it needs to be on some "X considered harmful" list.

I usually just ask my password generator to generate another random password for the secret question's answer.

It's possible an attacker might say: "My first pet's name is random gibberish", and the person on the other end goes: "Yep, that's what it says."

I'm not sure how many companies that would happen at, but it seems... just dumb enough to be plausible.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#73
post #67

Earlier quoted context omitted.

The way they used to handle that at a FAANG I worked for was they had this app installed on each machine issued by IT, that would ask you a question daily about some aspect of your workplace. Handles all the phishing concerns, except that participation was either low or the feedback was negative, which would lead to the leaders issuing subtle threats to the team about how they'd find out the involved folks and fire t…

> So, in the end, people just started giving the best possible feedback regardless of the team or manager performance. That seems to be the best possible strategy for any feedback you have to give as a captive audience? Reminds me of the feedback German companies are forced to give about their employees. It's like a formal letter of reference, but you can and will be sued if you you anything negative. Consequences ar…

> That seems to be the best possible strategy for any feedback you have to give as a captive audience?

It is, but at that point why even have that bureaucratic process that achieves exactly nothing?

Of course, I understand that being able to pat yourself on the back and concluding with statements like "Leadership is truly connected with its employees, keeping in touch every day through questions about improving the workplace. Our surveys show 99% of our employees are very satisfied with their team, their work, and work-life balance" is "valuable", I guess, I just feel very sad about humanity.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#75
post #71
post #70

Earlier quoted context omitted.

I usually just ask my password generator to generate another random password for the secret question's answer.

It's possible an attacker might say: "My first pet's name is random gibberish", and the person on the other end goes: "Yep, that's what it says." I'm not sure how many companies that would happen at, but it seems... just dumb enough to be plausible.

1Password’s default for secret questions is a sequence of English words, rather than random gibberish.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#77
post #68
post #52

Earlier quoted context omitted.

In New Zealand, there is a long list of companies who need to reach out to a large number of current and former employees, and try to convince them to go to a website and enter sensitive information to receive some money (1). Where I'm working, we found it hard, even for current employees, to convince them that it's not either phishing, or a phishing test. This is getting off-topic, but I found it interesting so I'll…

If the amounts are so tiny, couldn't the company just voluntarily overpay everyone by three dollars a year and call it a day?

Only most of the amounts were tiny, so all the effort for the re-calculation was still needed for everyone (basically either building a payroll engine from scratch, or paying someone else to use theirs). You're right, that for most current employees, for the small amounts it actually is much simpler. You can just email and slip it into the regular payroll.

It is the former employees for up to 15 years that make the contacting step difficult. They all need to provide bank/tax details.

There are also some current employees who still have to provide details before they can be paid. The company I work for has a lot of people moving countries, and therefore tax jurisdictions. In addition, some employers decided it was worth asking if employees were prepared to voluntarily allow offsetting between the overpayments and the underpayments, as in some cases those were quite large.

I can understand not wanting to give large amounts of money where it effectively would just balance out, especially after spending staggering amounts on the recalculation itself. There are government departments that have been working on it for years (or perhaps worse, and paying consulting companies to work on it).

Edit: I should have said, I did see companies rounding all amounts up to some small amount, like $1, so your suggestion is good. It just doesn't save effort on recalculation, or much effort in getting people to dig the email out of their trash folder and provide their information to receive their $1.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#78

All of this reminds me of a hilarious situation at a previous employer. As is standard corporate practice, they used to tell people to inspect links by hovering over them to confirm that they lead to the official website of the sender. People kept falling for phishing links though, so they got a Trend Micro device to scan emails, which also rewrote every link in it to point to their URL scanning service, which means…

I had the opposite funny experience. When I worked for Global MegaCorp, they would occasionally send out phishing emails and if you clicked on a link it would be recorded and you would have to do trainings if you got fooled a couple times. Eventually everyone learned to stop clicking on links on emails. That's good. However, they sent out a yearly survey to get feedback from all the employees and no one clicked the l…

noted for my phishing business: track first phishing attempt, send follow up email two days later saying the first one was legit.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#79
post #67

Earlier quoted context omitted.

> So, in the end, people just started giving the best possible feedback regardless of the team or manager performance. That seems to be the best possible strategy for any feedback you have to give as a captive audience? Reminds me of the feedback German companies are forced to give about their employees. It's like a formal letter of reference, but you can and will be sued if you you anything negative. Consequences ar…

> That seems to be the best possible strategy for any feedback you have to give as a captive audience? It is, but at that point why even have that bureaucratic process that achieves exactly nothing? Of course, I understand that being able to pat yourself on the back and concluding with statements like "Leadership is truly connected with its employees, keeping in touch every day through questions about improving the w…

> why even have that bureaucratic process that achieves exactly nothing?

It is a very good question that you should never bring up as captive audience.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#80
post #45

I registered the "very-secure-no-viruses.email" domain to use for burner emails. I was trying to make one that sounded maximally sketchy. It has lead to some confusing interactions with support though...

I have firstname@lastname.email... people keep telling me that can't be right and don't i mean it ends with email.com?
Post reply on HN