Live data from Hacker News

Thanks FedEx, This Is Why We Keep Getting Phished (2024)

troyhunt.com

31–40 of 86 posts

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#31

It reminds me how at work we had to take a course hosted on our domain about how to recognize phishing and a few days later we got an e-mail from outside our domain saying we had to take a course about a different subject on their domain. We got an email from management a week or so later that complained that so few people had completed the new training -- because we all assumed it was a phishing attempt because it w…

I'm forced to have a relationship with a bank that sends out iPad giveaway emails, where your chance of winning is contingent on filling out a survey with personal information. These occasionally go out on the same day as their periodic "how to recognize scams" newsletter.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#32

It reminds me how at work we had to take a course hosted on our domain about how to recognize phishing and a few days later we got an e-mail from outside our domain saying we had to take a course about a different subject on their domain. We got an email from management a week or so later that complained that so few people had completed the new training -- because we all assumed it was a phishing attempt because it w…

A significant number of phishing attempts would be thwarted if email apps had the option to expand the links next to URLs on platforms without mouseover, like mobile.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#33
post #22
post #7

There is a similar issue with the IRS. If you call the IRS they use a text-to-speech system to generate the voice for their call tree IVR. The problem is, it's a commercially available system that fake call center scammers also use, so they sound identical. It also doesn't help that it sounds fake and scammy, so you can't use that as a signal to avoid the number you're calling, either

With calls, it's easier: if you get an incoming call with someone is asking you for money, you hang up and call back using the number for that organization that you've found yourself from official sources. Never trust incoming calls when it comes to money.

So I call back and get dropped at the top of the phone tree. Now how do I address the original problem?

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#34
post #24
post #20

Earlier quoted context omitted.

There are whois servers, and the whois command, so no, it has not. I agree that this is the goal.

Clearly there is not a whois server here

According to a new uncle to your comment, not whois or RDAP.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#35
post #4

I swear, the proliferation of random ".xyz" type gTLD is not making things any easier in stopping non tech people from clicking on phishing links. There's so damn many of them. Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose... List of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt

The menagerie of TLDs is somewhat a necessary evil in my view. Prior to them it was becoming nearly impossible to get a decent domain, with most of them already having been laid claim to by squatters, big companies, and startups with VC money to burn.

It didn't change anything though, if you have the money you can just buy more.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#36
post #22
post #7

There is a similar issue with the IRS. If you call the IRS they use a text-to-speech system to generate the voice for their call tree IVR. The problem is, it's a commercially available system that fake call center scammers also use, so they sound identical. It also doesn't help that it sounds fake and scammy, so you can't use that as a signal to avoid the number you're calling, either

With calls, it's easier: if you get an incoming call with someone is asking you for money, you hang up and call back using the number for that organization that you've found yourself from official sources. Never trust incoming calls when it comes to money.

With calls, drop any non-prearranged calls, period.

Over a few years I burned that approach into my parents. It was tough, but worth it.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#37
post #4

I swear, the proliferation of random ".xyz" type gTLD is not making things any easier in stopping non tech people from clicking on phishing links. There's so damn many of them. Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose... List of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt

I'm not convinced that would help. The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain. Its just attempting to work around incompetence, which always just shows up again somewhere else.

The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain.

Just today I saw an e-mail from "onmicrosoft.com" that was completely legit.

I wonder how many domains MS is running these days. It seems like each department and project gets its own.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#38

Earlier quoted context omitted.

The menagerie of TLDs is somewhat a necessary evil in my view. Prior to them it was becoming nearly impossible to get a decent domain, with most of them already having been laid claim to by squatters, big companies, and startups with VC money to burn.

It didn't change anything though, if you have the money you can just buy more.

Also this was never a real problem. "All the good names are taken" is true if you insist that every name which isn't taken is a bad name but otherwise obviously false.

The same exact "Somebody already had the good ideas, it's not my fault I'm just too late" whining can be seen centuries ago. People who live in a world with no electricity, absolutely convinced that every product which will ever be wanted already exists. Morons.

Way back in time I wrote an HN post where I just spotaneously came up with plausible 2LD names off the dome and every single one was available. I won't bother repeating the exercise because it was evident that everybody who could understand this was unsurprised while the people who'd previously believed all the good names were gone just dismissed these as bad names because after all, if they were good names they'd be taken already, duh.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#39

Earlier quoted context omitted.

I'm not convinced that would help. The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain. Its just attempting to work around incompetence, which always just shows up again somewhere else.

The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain. Just today I saw an e-mail from "onmicrosoft.com" that was completely legit. I wonder how many domains MS is running these days. It seems like each department and project gets its own.

At least they're not sending from contoso.com ?
Post reply on HN