Live data from Hacker News

Want to piss off your IT department? Are the links not malicious looking enough?

phishyurl.com

81–90 of 335 posts

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#81

Earlier quoted context omitted.

Not going to lie, I was expecting this[1]. Maybe it's just not done on HN. 1: https://pc-helper.xyz/scanner-snatcher/session-snatcher/cred...

Oh I figured it was gonna be this one: https://cam-xxx.live/rootkit-injector/evil-controller/payloa...

Is this gonna work on my 2008 Symbian’s browser?

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#85
post #52

Earlier quoted context omitted.

In New Zealand, there is a long list of companies who need to reach out to a large number of current and former employees, and try to convince them to go to a website and enter sensitive information to receive some money (1). Where I'm working, we found it hard, even for current employees, to convince them that it's not either phishing, or a phishing test. This is getting off-topic, but I found it interesting so I'll…

Or IRD (NZ tax dept.) a few years back sending out a survey on a .co.nz domain. Gave their security team a hard time for that one!

IRD's phone calling campaign about enabling two-factor auth was also not great.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#87

Earlier quoted context omitted.

I had the opposite funny experience. When I worked for Global MegaCorp, they would occasionally send out phishing emails and if you clicked on a link it would be recorded and you would have to do trainings if you got fooled a couple times. Eventually everyone learned to stop clicking on links on emails. That's good. However, they sent out a yearly survey to get feedback from all the employees and no one clicked the l…

The way they used to handle that at a FAANG I worked for was they had this app installed on each machine issued by IT, that would ask you a question daily about some aspect of your workplace. Handles all the phishing concerns, except that participation was either low or the feedback was negative, which would lead to the leaders issuing subtle threats to the team about how they'd find out the involved folks and fire t…

> The way they used to handle that at a FAANG I worked for was they had this app installed on each machine issued by IT, that would ask you a question daily about some aspect of your workplace.

I presume you're referring to "Amazon Connections"?

Had to be the most-hated bit of corporate enforcedware around. Every Linux laptop user had a different hack for hobbling or removing it.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#88
Ha! Great minds think alike.

We have something that makes genuine links look malicious at work too.

I think it’s called Microsoft Safelink or something. Its purpose is to go through your Outlook inbox and obscure the origin of every link because, obviously, being able to understand what you’re clicking on is bad.

Remember kids, no one ever gets fired for buying Microsoft. ;)

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#89

Earlier quoted context omitted.

> That seems to be the best possible strategy for any feedback you have to give as a captive audience? It is, but at that point why even have that bureaucratic process that achieves exactly nothing? Of course, I understand that being able to pat yourself on the back and concluding with statements like "Leadership is truly connected with its employees, keeping in touch every day through questions about improving the w…

> why even have that bureaucratic process that achieves exactly nothing? It is a very good question that you should never bring up as captive audience.

If you have a back channel in the audience you should get a large enough group to ask this question in the free form feedback box in the exactly same wording. Should send chills down the lord of HR spine.

Don’t do it with a group which isn’t large enough though, you’ll get you all fired for unionizing^W no reason.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#90
post #88

Ha! Great minds think alike. We have something that makes genuine links look malicious at work too. I think it’s called Microsoft Safelink or something. Its purpose is to go through your Outlook inbox and obscure the origin of every link because, obviously, being able to understand what you’re clicking on is bad. Remember kids, no one ever gets fired for buying Microsoft. ;)

this hits so hard hahaha

also ProofPoint filtered links

Post reply on HN