Live data from Hacker News

Launch HN: Riot (YC W20) – Phishing training for your team

news.ycombinator.com

11–20 of 93 posts

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#11
> Would love to hear your war stories on phishing scams, and how you train your teams!

I was working on anti-phishing in 2003, before it had the name phishing. We were trying to teach our users not to fall for the scams.

It didn't work. People will fall for the same scam over and over.

The conclusion we came to was that the only solution to phishing was education, and education was also nearly impossible to get 100% coverage.

I wish you luck, but don't get discouraged if it doesn't work. We've been trying to educate people about phishing for 17+ years. :)

We shifted our focus to tracking the phishing sites and then tying that back to which user accounts were hacked, and disabling the hacked accounts and notifying the users before damage could be done.

PayPal actually holds the patent on what we built, along with a ton of other anti-phishing and phishing site tracking patents.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#13

How do you work with the service providers you use to host your platform and send out emails (e.g. Heroku / Mailgun) to let them know you are not a malicious phishing company, but an anti-phishing company? I say this because I ended up reporting the phishing email I received from you guys to Mailgun, and I believe accidentally got your account disabled. Sorry about that.

YES you did!

I called them just right after that, and I have to say they've been great so far. We agreed I would pay for a dedicated IP, and they now fully support Riot. And having a dedicated IP is actually better, because you can now remove the unexpected warning on Gmail.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#14
> "I was pissed"

How do you balance/deal with "security shaming", which is proven to put you further at risk as an organization?

There is some interesting research from the UK Government in this space - https://www.ncsc.gov.uk/blog-post/trouble-phishing#section_3

The relevant bit:

"If just one user reports a phish, you can get a head start on defending your company against that phishing campaign and every spotted email is one less opportunity for attackers...but phishing your own users isn't your only option.

Try being more creative; some companies have had a lot of success with training that gets the participants to craft their own phishing email, giving them a much richer view of the influence techniques used. Others are experimenting with gamification, making a friendly competition between peers, rather than an 'us vs them' situation with security."

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#15

That's an unfortunate business name

Definitely bad timing. My experience with names: they are never good enough.

What I look for in a name:

1. If I say it out loud, you know how to write it.

2. If I say it out loud today, you remember it tomorrow.

On that 2 criteria, Riot works quite well I think.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#16

That's an unfortunate business name

Definitely bad timing. My experience with names: they are never good enough. What I look for in a name: 1. If I say it out loud, you know how to write it. 2. If I say it out loud today, you remember it tomorrow. On that 2 criteria, Riot works quite well I think.

It's bad in that there's already a very popular game company named Riot (Games) which everyone refers to as 'Riot'.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#17

> "I was pissed" How do you balance/deal with "security shaming", which is proven to put you further at risk as an organization? There is some interesting research from the UK Government in this space - https://www.ncsc.gov.uk/blog-post/trouble-phishing#section_3 The relevant bit: "If just one user reports a phish, you can get a head start on defending your company against that phishing campaign and every spotted ema…

1. There's an option to hide the names of the employees. It would replace all the names with random animal name + a color. It's great if you don't want to know which employees are falling for attacks.

2. I love the idea to actually make the employees create their own attacks, but seems a bit hard to do and pretty much time consuming for a company.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#18

Earlier quoted context omitted.

Definitely bad timing. My experience with names: they are never good enough. What I look for in a name: 1. If I say it out loud, you know how to write it. 2. If I say it out loud today, you remember it tomorrow. On that 2 criteria, Riot works quite well I think.

It's bad in that there's already a very popular game company named Riot (Games) which everyone refers to as 'Riot'.

Some people know League of Legends, most don't know Riot Games. And I double checked: Riot Games don't own a trademark for anything related to cybersecurity.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#20
post #11

> Would love to hear your war stories on phishing scams, and how you train your teams! I was working on anti-phishing in 2003, before it had the name phishing. We were trying to teach our users not to fall for the scams. It didn't work. People will fall for the same scam over and over. The conclusion we came to was that the only solution to phishing was education, and education was also nearly impossible to get 100%…

I actually started coding in 2000 trying to hack my brother, so I can relate: phishing has been a never-ending story.

It's still worth trying though!

Post reply on HN