Love it! My recommendation would be to offer an option for allowing the target to be tricked through the whole process. (Even if credentials are discarded completely.) The idea here is nothing is left to the imagination. What you have is great, but it requires them to read and be observant, which is not the type of person who falls for phishing emails. Clicking the link is "No-No" #1, don't exclude "No-No" #2 from yo…
Thanks and thanks for the suggestion! One thought I'd had was longer/more in depth campaigns. It's good to know other people would be interested in that as well. One thing I was concerned about was that people might not trust some random guy on the internet to properly discard those credentials.
Show HN: Phishing as a service
51–60 of 70 posts
Re: Show HN: Phishing as a service
#52Earlier quoted context omitted.
Not to dismiss your experience (perhaps you had not heard the term yet) but the term 'phishing' has been around longer (mid 90s at least) than ebay and paypal have been big enough to be phishing targets.
I was deeply involved in the fledgling anti-spam industry in the early 2000s, by way of the anti-virus industry, and it was not a common term then. Wikipedia gives the first recorded use as '95, and that refers to it as "fishing", and as being AOL-specific.
Re: Show HN: Phishing as a service
#53Earlier quoted context omitted.
But i guess that you are in the small, small minority of false positives
Most people won't think twice about the link in the email. They'll usually stop at the login screen because it doesn't look right, has a wrong URL, etc. Having done a lot of work in this area I can tell you that I'm definitely not in the minority. Clicking the link from a secure VM sure puts me in the minority, but just clicking the link? Lots of people do that and then get suspicious. That's why you need two steps t…
Later we realized that this was a test conducted by the firm (a large investment bank) that I work for!
Re: Show HN: Phishing as a service
#54It worked wonderfully. I used it through proxies when I could and watched the phishers try to block me or even attack me back.
Re: Show HN: Phishing as a service
#551. They rely on e-mail while phishing attacks come from multiple sources like Facebook and LinkedIn. Sadly, using those services to simulate phishing attacks violates their ToS.
2. Simulation phishing only provides pass or fail data meaning you cannot determine your weakest links in the organization. At best you get an "average" snapshot.
3. The data isn't very accurate or precise because there are too many confounding variables involved. Time of day, subject matter, type of phishing (attachment, social engineering, etc). Normally we ran our campaigns once a month but this wasn't enough to produce stable results.
4. Clicking doesn't mean they fell victim to the attack -- lot's of people click to investigate then report the links. Ideally, I'd like to specifically know WHY the employee clicked the link and HOW MUCH was actually at stake.
4. It pisses people off. There is enough animosity against us security folks that tricking your employees really hurts that relationship. People feel taken advantage of.
5. It doesn't actually improve security in any meaningful way. I found that it didn't actually improve people's ability to spot and report phishing attempts. They either became paranoid to the point where they were no longer productive in legitimate emails, or they had no improvements over time.
6. There's a growing body of knowledge that dismisses the effectiveness of this kind of phishing training (http://www.govinfosecurity.com/interviews/training-doesnt-mi...) .
With that being said, our company has tried about a dozen of these kinds of services and the best one so far has been one called Apozy that is rather new. It's a different approach but the data and insight you get back is actually very useful.
Re: Show HN: Phishing as a service
#56I wrote some Perl years back to take the fight to phishers. You would provide my script with the field names and POST URL of the HTML form within the phishing email, along with some generic types for each form field. There were types for firstnames, lastnames, email, addresses, usernames, passwords, social security numbers, and credit card numbers. The script would generate fake but real-looking values for each of th…
Re: Show HN: Phishing as a service
#57I work in security at a large Fortune 500 company. I know at first it sounds like phishing your employees will give you good insight, but you realize quickly that the data you get is not very useful. Here are the roadblocks I've hit with these kinds of simulation phishing services: 1. They rely on e-mail while phishing attacks come from multiple sources like Facebook and LinkedIn. Sadly, using those services to simul…
Sadly I thought of setting up a company like this to do just this job. But Apozy's gasification approach seems a good idea
Re: Show HN: Phishing as a service
#58Re: Show HN: Phishing as a service
#59Earlier quoted context omitted.
But i guess that you are in the small, small minority of false positives
Most people won't think twice about the link in the email. They'll usually stop at the login screen because it doesn't look right, has a wrong URL, etc. Having done a lot of work in this area I can tell you that I'm definitely not in the minority. Clicking the link from a secure VM sure puts me in the minority, but just clicking the link? Lots of people do that and then get suspicious. That's why you need two steps t…
Re: Show HN: Phishing as a service
#60Earlier quoted context omitted.
Most people won't think twice about the link in the email. They'll usually stop at the login screen because it doesn't look right, has a wrong URL, etc. Having done a lot of work in this area I can tell you that I'm definitely not in the minority. Clicking the link from a secure VM sure puts me in the minority, but just clicking the link? Lots of people do that and then get suspicious. That's why you need two steps t…
Isn't hovering the link and just see where it goes enough to detect a phishing attempt? You really need to open the page?
I'm a nitpicker but that's one of the reason why i dislike safari browser. You need the status bar enabled in order to see the links destination url and I don't like the 7 pixels height taken by this bar.
But as I am browsing with javascript enabled, I can't be sure that the url showed by the link is the destination I'll be sent to. That's something quite hard to explain to non technical people (like my parents). I'm not even trying to be honest. I'm not sure what to think about this behavior and generally with link shortener, it's an easy way to phish people in forum, comments, ...
And the shortened link still works for emails.