Live data from Hacker News

Thanks FedEx, This Is Why We Keep Getting Phished (2024)

troyhunt.com

81–86 of 86 posts

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#81
I virtually never click anything texted to me (other than personal stuff from friends and family). If a bank or a shipping company texts me, I go to their website and look up the information myself.

Like the author of this post, I also have a better than average eye for spotting scams, but it’s foolish to assume you’ll be right 100% of the time.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#82
post #62

Earlier quoted context omitted.

I agree, but I'd also challenge you to find a cellphone that a normal person carries that doesn't just concatonate multiple messages and turn them into MMS. My Pinephone and Librem 5 did that, but that reinforces my point: this is not something a normal person will see

Wait, multiple messages get concatenated to MMS? In early 2010s I remember in my country it's still concatenated as regular text (so if one part is somehow missing or comes in very late, some phones will only show the surviving parts as one, others dump each parts separately), I guess they remove that functionality? Back then each part cost roughly one cent and plenty of phones in use still don't support MMS, then pe…

> Wait, multiple messages get concatenated to MMS?

SMS is a single packet over GSM with maximum payload size of 140 bytes.

https://en.wikipedia.org/wiki/SMS#Message_size

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#83

Earlier quoted context omitted.

Our idiots decided to conduct phishing tests by allowing KnowB4 to send "official" phishing emails. The kind that Outlook/Exchange don't flag as "outside your organization." So now there's no real way to tell what could be a legitimate email from illegitimate. Also, the Knowb4 phishing tests include some Knowb4 headers, so it's trivial to pass the test (though they're usually so stupidly obvious that you'd never need…

FWIW, they put a header in the message that you can spot from a thousand miles away. That is how they get past the filters. I used to work for a company y that used them, and this trick was passed around between engineers as a way to tell. They didn’t bother checking the results of whether we flagged them as spam, so ultimately we found that we could just ignore them completely. It’s compliance theater. No real secur…

At my company they started placing the emails in your inbox in a way that rules looking these headers didn’t flag them. Except that only seems to be true in Outlook and other email clients flag them just fine.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#84
post #10

Earlier quoted context omitted.

Whois has been replaced by RDAP.

As far as I am able to find Google does not provide an RDAP server for gle either.

ICANN: “All gTLD registries and registrars are required to provide RDAP services.” They are listed at lookup.icann.org and the one in question is https://pubapi.registry.google/rdap/domain/c.gle

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#85

It reminds me how at work we had to take a course hosted on our domain about how to recognize phishing and a few days later we got an e-mail from outside our domain saying we had to take a course about a different subject on their domain. We got an email from management a week or so later that complained that so few people had completed the new training -- because we all assumed it was a phishing attempt because it w…

Every official permissions block and exemption request popup our company's enterprise ops manages appears indistinguishable from malware. It's almost impressive.

Re: Thanks FedEx, This Is Why We Keep Getting Phished (2024)

#86
post #55
post #30

Earlier quoted context omitted.

We've desperately needed secure identity verification for business callers for years, so we can start the decades long process of changing people's instincts about it. There's no good reason any business should be able to contact me without whoever is calling cryptographically proving they're that business and my phone showing the name and logo from a copy or mirror of an official database. It should just be a standa…

But for which country, state, province, or city? Put in the hierarchical angle, and we're kind of back at domain names.

Which would be a vast improvement over the current system.

Quite literally if the requirement was "your domain name will match your company registration in your jurisdiction" then that would help a lot.

Post reply on HN