Live data from Hacker News

Thanks FedEx, This Is Why We Keep Getting Phished (2024)

troyhunt.com

61–70 of 86 posts

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#61
post #4

I swear, the proliferation of random ".xyz" type gTLD is not making things any easier in stopping non tech people from clicking on phishing links. There's so damn many of them. Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose... List of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt

I definitely don't trust those when they show up in search results, and even when they sometimes appear here in articles voted to the front page, I tend to ignore them.

Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose

Many-legit-sounding-hyphenated-words-domain is actually another red flag for me, as that was indeed what they did before the proliferation of TLDs.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#62
post #54

Earlier quoted context omitted.

not that it really helps to know now, but .gle is a TLD operated by Google. the only domains on a .gle domain will be Google (in theory). Plus, a single letter domain (on any TLD), like c.gle would be expensive to burn on a phishing scam. But no one should need to know this. I don't know what's so wrong about just using google.com, or even .google for anything user facing... I understand the idea that they want an of…

I assume it's tied somehow to SMS character limits, where somebody decided a couple extra letters of content was worth it somehow.

I agree, but I'd also challenge you to find a cellphone that a normal person carries that doesn't just concatonate multiple messages and turn them into MMS. My Pinephone and Librem 5 did that, but that reinforces my point: this is not something a normal person will see

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#63
post #22
post #7

There is a similar issue with the IRS. If you call the IRS they use a text-to-speech system to generate the voice for their call tree IVR. The problem is, it's a commercially available system that fake call center scammers also use, so they sound identical. It also doesn't help that it sounds fake and scammy, so you can't use that as a signal to avoid the number you're calling, either

With calls, it's easier: if you get an incoming call with someone is asking you for money, you hang up and call back using the number for that organization that you've found yourself from official sources. Never trust incoming calls when it comes to money.

This actually depends on who has better SEO. Some scam numbers place higher than the help pages for actual businesses. Receiving physical bills and calling the number on the back of your credit or debit card are good suggestions.

Or, as another poster suggested, competent governments and corporations will use their actual domain name for official communication.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#64

Earlier quoted context omitted.

I'm not convinced that would help. The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain. Its just attempting to work around incompetence, which always just shows up again somewhere else.

The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain. Just today I saw an e-mail from "onmicrosoft.com" that was completely legit. I wonder how many domains MS is running these days. It seems like each department and project gets its own.

Note that XYZ.onmicrosoft.com is the domain you get when you sign up for hosted office 365 without a domain of your own

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#65
post #36
post #22

Earlier quoted context omitted.

With calls, it's easier: if you get an incoming call with someone is asking you for money, you hang up and call back using the number for that organization that you've found yourself from official sources. Never trust incoming calls when it comes to money.

With calls, drop any non-prearranged calls, period. Over a few years I burned that approach into my parents. It was tough, but worth it.

That's a good approach, and I do this too actually, but some people's job or occupation requires them to take calls from unknown numbers. And some people still use landlines without caller ID.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#66
It really doesn't help that after the acquisition of TNT couriers, some bright spark decided to call the Australian arm of FedEx "FedEx Express". That's right, "Federal Express Express".

It's moronic that these big companies can't get their shit together and provide nice links like this:

https://fedex.au/duty/abc123

which could have an explainer landing page before prompting you to visit the grotesque original link.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#67
post #4

I swear, the proliferation of random ".xyz" type gTLD is not making things any easier in stopping non tech people from clicking on phishing links. There's so damn many of them. Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose... List of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt

My theory is that it devalues the domain name thus increasing the value of search sites.

BTW, it'd be nice if browsers automatically show the CNs of the "Issued-To:" and the "Issued-By" in the security certificate.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#68
Twenty or so years ago I ordered wheels and tires from tire rack dot com and as I was in college had them delivered to my parents house. The FedEx driver proceeded to roll them down the driveway and into my parents siding scraping up my new wheels and causing about 20k in damage to the siding.

They seem to have improved so much in that time.

(╯°□°)╯︵ ┻━┻

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#69
post #66

It really doesn't help that after the acquisition of TNT couriers, some bright spark decided to call the Australian arm of FedEx "FedEx Express". That's right, "Federal Express Express". It's moronic that these big companies can't get their shit together and provide nice links like this: https://fedex.au/duty/abc123 which could have an explainer landing page before prompting you to visit the grotesque original link.

it's that way stateside too

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#70
post #66

It really doesn't help that after the acquisition of TNT couriers, some bright spark decided to call the Australian arm of FedEx "FedEx Express". That's right, "Federal Express Express". It's moronic that these big companies can't get their shit together and provide nice links like this: https://fedex.au/duty/abc123 which could have an explainer landing page before prompting you to visit the grotesque original link.

it's that way stateside too

What is even more moronic than Federal Express Express is Fedex Express (worked by well paid employees) is a completely different product than Fedex Ground (worked by the lowest paid independent contractors).
Post reply on HN