Live data from Hacker News

Want to piss off your IT department? Are the links not malicious looking enough?

phishyurl.com

111–120 of 335 posts

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#111
post #67

Earlier quoted context omitted.

> So, in the end, people just started giving the best possible feedback regardless of the team or manager performance. That seems to be the best possible strategy for any feedback you have to give as a captive audience? Reminds me of the feedback German companies are forced to give about their employees. It's like a formal letter of reference, but you can and will be sued if you you anything negative. Consequences ar…

> That seems to be the best possible strategy for any feedback you have to give as a captive audience? It is, but at that point why even have that bureaucratic process that achieves exactly nothing? Of course, I understand that being able to pat yourself on the back and concluding with statements like "Leadership is truly connected with its employees, keeping in touch every day through questions about improving the w…

> It is, but at that point why even have that bureaucratic process that achieves exactly nothing?

Well, I was talking about the best strategy from the captive audience's point of view. You are now asking about the strategy for the captor.

Going a bit beyond: getting honest feedback out of subordinates is a hard problem! Both formally and informally. That was always a big concern on my mind as a manager.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#112
post #89

Earlier quoted context omitted.

> why even have that bureaucratic process that achieves exactly nothing? It is a very good question that you should never bring up as captive audience.

If you have a back channel in the audience you should get a large enough group to ask this question in the free form feedback box in the exactly same wording. Should send chills down the lord of HR spine. Don’t do it with a group which isn’t large enough though, you’ll get you all fired for unionizing^W no reason.

Again, there's no incentive to do this. It's full of downsides, and the only upside is some lolz from trolling.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#113
post #45

I registered the "very-secure-no-viruses.email" domain to use for burner emails. I was trying to make one that sounded maximally sketchy. It has lead to some confusing interactions with support though...

I have firstname@lastname.email... people keep telling me that can't be right and don't i mean it ends with email.com?

I have had a .xyz email for like 10 years at this point. It's 50/50 of people saying "is that really a email address" and people acting completely normal.

Never going to know what reaction I'm going to get.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#114
post #112
post #89

Earlier quoted context omitted.

If you have a back channel in the audience you should get a large enough group to ask this question in the free form feedback box in the exactly same wording. Should send chills down the lord of HR spine. Don’t do it with a group which isn’t large enough though, you’ll get you all fired for unionizing^W no reason.

Again, there's no incentive to do this. It's full of downsides, and the only upside is some lolz from trolling.

It all depends on what your utility function is, but for most people I completely agree. For a good example of such activism not blowing up completely in your face would be the OpenAI revolt and sama reinstatement, but that’s obviously survivorship bias.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#115
post #18

Earlier quoted context omitted.

I think the lesson here is that any link in an email is bad. We should just block all of them.

Why not address the problem at its real source and just block emails entirely?

"any link in an email is bad, we should block all of them" could mean links AND emails.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#117
post #18

I know it's a joke and I had a sensible chuckle, but if you want to routinely use it at work, just keep in mind that it's probably gonna make things worse. Since you can't exhaustively enumerate every good thing or every bad thing on the internet, a lot of security detection mechanisms are based on heuristics. These heuristics produce a fair number of false positives as it is. If you bring the rate up, it just increa…

I think the lesson here is that any link in an email is bad. We should just block all of them.

What is an alternative?

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#118
post #110
post #67

Earlier quoted context omitted.

> So, in the end, people just started giving the best possible feedback regardless of the team or manager performance. That seems to be the best possible strategy for any feedback you have to give as a captive audience? Reminds me of the feedback German companies are forced to give about their employees. It's like a formal letter of reference, but you can and will be sued if you you anything negative. Consequences ar…

> And because there has been an inflation in how complimentary these letters are, people started suing when their letter wasn't flowery enough, because that somehow could be read as an implicit criticism. You got a source for this folktale?

The reality is that these letters are written in a kind of pseudolegalistic language, where a phrase like “the employee was punctual” means they were usually late. If they were actually punctual, you'd see something more like “the employee consistently demonstrated exceptional punctuality”.

You usually need the reference letter to be reviewed by the works council or by an employment lawyer.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#119
post #110
post #67

Earlier quoted context omitted.

> So, in the end, people just started giving the best possible feedback regardless of the team or manager performance. That seems to be the best possible strategy for any feedback you have to give as a captive audience? Reminds me of the feedback German companies are forced to give about their employees. It's like a formal letter of reference, but you can and will be sued if you you anything negative. Consequences ar…

> And because there has been an inflation in how complimentary these letters are, people started suing when their letter wasn't flowery enough, because that somehow could be read as an implicit criticism. You got a source for this folktale?

I have no official source but know that this happens a lot. Also the arguments with the employer about the letters afterwards. Some are so fed up and let you write the first or final draft. There is also the hidden code. So instead of writing something negative which is forbidden you just use different words or leave out some intensifications. Like “zur größten Zufriedenheit” vs “zur allergrößten Zufriedenheit”. One means your work was Ok the other it was great. There is also intensification by adding time adjectives like “always” or “often” etc.

This code is known by people in the HR and hiring departments. It’s a very weird praxis. I have to explain this to my non German colleagues because for them even a mark F letter sounds awesome ;)

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#120

All of this reminds me of a hilarious situation at a previous employer. As is standard corporate practice, they used to tell people to inspect links by hovering over them to confirm that they lead to the official website of the sender. People kept falling for phishing links though, so they got a Trend Micro device to scan emails, which also rewrote every link in it to point to their URL scanning service, which means…

The company I used to work for had the same thing - everything was a rewritten URL (this was a Microsoft shop so it was rewritten to something like "safe.protected.outlook.com/?random_spew". From what I remember, yo)u couldn't even see the original URL in that (or it might have just been long enough random arguments to be completely impossible to find).

Nothing raises my suspicions quite like something calling itself "safe".

Post reply on HN