Earlier quoted context omitted.
I assume it's tied somehow to SMS character limits, where somebody decided a couple extra letters of content was worth it somehow.
I agree, but I'd also challenge you to find a cellphone that a normal person carries that doesn't just concatonate multiple messages and turn them into MMS. My Pinephone and Librem 5 did that, but that reinforces my point: this is not something a normal person will see
Thanks FedEx, This Is Why We Keep Getting Phished (2024)
71–80 of 86 posts
Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)
#72Earlier quoted context omitted.
not that it really helps to know now, but .gle is a TLD operated by Google. the only domains on a .gle domain will be Google (in theory). Plus, a single letter domain (on any TLD), like c.gle would be expensive to burn on a phishing scam. But no one should need to know this. I don't know what's so wrong about just using google.com, or even .google for anything user facing... I understand the idea that they want an of…
I assume it's tied somehow to SMS character limits, where somebody decided a couple extra letters of content was worth it somehow.
However you slice it, even after we conquer character limits and font rendering and storage space for every electronic device, human beings will still be using "the analog hole" to copy code like that.
Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)
#73In a recent example my step-mother, who is constantly getting cloud storage full scam emails, received an email from Google about 75% full storage that appears to be fully valid. However all the links use a domain c.gle and whois c.gle errors with "getaddrinfo(whois.nic.gle): Name or service not known". whois gle however does work. I was not sure of the validity of c.gle myself, my step-mother would have no idea.
Whois has been replaced by RDAP.
Even if you retrieve registration information about a domain, that will not necessarily help a consumer figure out if it is legitimate, or who owns it. There will be a lot of redactions and shell companies and generic information.
The target market for WHOIS and RDAP has always been administrators and registrants and others on their level. Obviously--RDAP is a JSON format, not plain text anymore!
As a consumer, if you're trying OSINT, try not to spread that around, because it is another opportunity for deception, confusion, and cargo culting. What you want is good malware protection, according to your actual risk profile. If your browser protection is worthwhile then it will stop attacks from domains like that.
If you are particularly worried about strange domains, many 3rd-party DNS services can block those. NextDNS had a checkbox for "block newly-registered domains" as well as filtering any sus gTLD or ccTLD type ones.
Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)
#74Earlier quoted context omitted.
I assume it's tied somehow to SMS character limits, where somebody decided a couple extra letters of content was worth it somehow.
I agree, but I'd also challenge you to find a cellphone that a normal person carries that doesn't just concatonate multiple messages and turn them into MMS. My Pinephone and Librem 5 did that, but that reinforces my point: this is not something a normal person will see
Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)
#75Earlier quoted context omitted.
I agree, but I'd also challenge you to find a cellphone that a normal person carries that doesn't just concatonate multiple messages and turn them into MMS. My Pinephone and Librem 5 did that, but that reinforces my point: this is not something a normal person will see
Wait, multiple messages get concatenated to MMS? In early 2010s I remember in my country it's still concatenated as regular text (so if one part is somehow missing or comes in very late, some phones will only show the surviving parts as one, others dump each parts separately), I guess they remove that functionality? Back then each part cost roughly one cent and plenty of phones in use still don't support MMS, then pe…
it might make sense if you're on a plan where an MMS costs less than 2xSMS
Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)
#76Earlier quoted context omitted.
I assume it's tied somehow to SMS character limits, where somebody decided a couple extra letters of content was worth it somehow.
You know what? If someone shows me a shortcode on my feature phone, or on someone else's device, or it's printed on a leaf of paper, or if I'm in a library using library computers, a shortened URL like that is way easier to type in, or write it down by hand. However you slice it, even after we conquer character limits and font rendering and storage space for every electronic device, human beings will still be using "…
Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)
#77But it is real. I wondered one day how many people opening it fall into the category
- this is normal and expected, it is France
- this is a scam, let's see how it was done
- this is obviously from the post office and I would do the same if I was scammed
Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)
#78It reminds me how at work we had to take a course hosted on our domain about how to recognize phishing and a few days later we got an e-mail from outside our domain saying we had to take a course about a different subject on their domain. We got an email from management a week or so later that complained that so few people had completed the new training -- because we all assumed it was a phishing attempt because it w…
Our idiots decided to conduct phishing tests by allowing KnowB4 to send "official" phishing emails. The kind that Outlook/Exchange don't flag as "outside your organization." So now there's no real way to tell what could be a legitimate email from illegitimate. Also, the Knowb4 phishing tests include some Knowb4 headers, so it's trivial to pass the test (though they're usually so stupidly obvious that you'd never need…
https://en.wikipedia.org/wiki/Kevin_Mitnick#Consulting
Bonus KnowBe4 fact: they produced a web series from 2019-2024!
https://en.wikipedia.org/wiki/The_Inside_Man_(2019_TV_series...
Bonus bonus fact: KnowBe4 hired more than zero North Koreans!
https://en.wikipedia.org/wiki/North_Korean_remote_worker_sch...
Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)
#79I wonder how we could describe this so that aging non-technical executives understand. "It's like your real salesperson showed up in a wrinkled suit smelling of booze, telling me that your product could be seen in the back of an anonymous white van... But only if I first proved I was carrying the asking-price in the form of gift-cards."
"There are technologies and protocols from the early 2000s that need to be followed to ensure that a a message comes from your company, they are not being followed so messages requesting payment are indistinguishable from impersonators.
The protocols are called DNS and HTTPS, the cost to implement for the country in question would be in the 5 digits range, the benefits would be massively detracting scammers from targetting your company to impersonate and thus harm your brand."
I don't think metaphors help, non technical people, especially executives, can handle minimal technical details.