Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

121–130 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#121
At my company, they announced that in the upcoming month there would be an internal phishing sensibility campaign. Then, in the same month, they started sending out incredibly dodgy looking emails to "security training" provided by an external website. Of all emails, those looked the most like phishing but they are not. I decided that I refuse to do this training completely because to me it seems crazy how that was coordinated. I would never lose my job over this but it is amusing that I get an "Urgent: security training still outstanding" about once a week which just goes straight into the trash.

Re: Thanks FedEx, this is why we keep getting phished

#122

So far every time I’ve gotten dodgy AF texts or emails I’ve been able to verify at the real site… crazy that FedEx doesn’t have the info attached to the tracking.

> crazy that FedEx doesn’t have the info attached to the tracking

It is crazy how much the "paying duties at the border" situation feels like an afterthought for all currier companies. It is almost as if it was not really their design they just tackled it on later.

I wanted to send a present to my brother in an other country using DHL Express. It was impossible to convince them that I would like to pay duties. Not a thing. Can't be done.

Re: Thanks FedEx, this is why we keep getting phished

#124
post #36
post #30

Earlier quoted context omitted.

I will simply refuse to believe this is real. As a psychological defense mechanism. What the hell.

Clearly the safer option is sending the terms via CD https://t3n.de/news/sparkasse-digital-strategie-cds-per-post... Since no-one has a CD drive in their computer anymore, the security risk is negligible

And even if you do have a CD drive in your computer, the risk is still lower than a USB stick. A CD contains only data, it cannot do things like emulating a keyboard. The worst it can do is shatter when your high-speed DVD-ripping drive spins it up a bit too fast.

Re: Thanks FedEx, this is why we keep getting phished

#125
post #75

I know this comes down to institutional incompetency, but at some point there was a singular human person putting the template content the SMS message in question was generated from into some computer system somewhere and I genuinely wonder what was going on in their head that made them string the words together in this way. You'd have to give it a true, earnest shot to make it worse.

Some say scammers are very smart, and that they deliberately use every trick in the book to tap into our psychological weaknesses and make us act irrationally. But I have the feeling that, 90% of the time, scammers are just told to write an "official-sounding" message – which is the same thing that the hypothetical human who wrote this template was trying to do: that's why the result is so similar. No doubt the use o…

Yep. It's a bit like the theory that scammers mention they're from Nigeria because they're ingeniously weeding out all the people who've heard of the scam before, and not because they need an excuse for people to send money to Nigeria (and with their culture and education level the ALLCAPS and religious references look very official and honest indeed), and if the cost of that is that 99.99% of their emails don't get delivered due to automatic filters protecting even the most gullible of recipients, well that's probably not something they've given much thought to.

Re: Thanks FedEx, this is why we keep getting phished

#126
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

I report those as phishing in order to get the feedback to the IT team who sent them from their colleagues in infosec. (I often have had IT and infosec reporting to me, which makes this even more effective of a feedback mechanism. :) )

Re: Thanks FedEx, this is why we keep getting phished

#127
post #6
post #2

Suggest Law: If a company's electronic notification to you is so phishy that a "reasonable man" would have obvious cause to doubt its legitimacy, then all financial and legal consequences of ignoring it are on the sender . Edit: " sender " here refers to the sender of the electronic notification .

Any time the law sets things like "reasonable" it's a quagmire. For every utterance of "reasonable" in law you can be sure over $1B of laywer fees have been (or will be) spent.

You can spend as much as lawyer money as you want on arguing whatever nonsense you want, reasonableness is a common standard so sure, people will have spent lots of money pointlessly arguing about it but that's not a problem with reasonableness.

Re: Thanks FedEx, this is why we keep getting phished

#128
post #56

Earlier quoted context omitted.

I do not read this court decision like that at all: the point of contention there seems to be that the customer was just sent a link to a webpage (where the contractual terms can be changed from under him at will by the company, thus this not being durable). The court makes it pretty clear in my (non-lawyer) opinion that attaching a PDF to the email would have been fine.

I was prepared to disagree with you, but I now have the same interpretation you have. Durable medium can be email - but the example seems a little fuzzy, for instance a durable medium is definitely when the email is stored on a HDD on a customer device. But is it still durable medium if the email only exists in a webmail? Probably yes, but maybe no. So the conservative approach would be to send paper for some things.…

That doesn't fix the issue though. The issue is a killer USB or a virus on the disk. Being able to only read an infected file still allows it to be read.

Also, this is only a software solution as the USB protocol would require bidirectional transmission.

Re: Thanks FedEx, this is why we keep getting phished

#129
The other thing I try to understand but just can't is how Telco providers can be so incompetent in effectively stopping scam texts.

First of, texts are not encrypted and they can see ALL communication.

On the other hand the US forces me, using Twilio for SMS automation, to sign up "campaigns" with "Sample messages" if maybe all I want to do is building a personal assistant with text commands. My messages will get hit with fees for non compliance, or end up silently blocked without any visibility.

Then there are these scammers sending the same or very similar messages to millions of people, pretending to be the same 50 companies (national banks, shipping companies, cell phone carriers) - how about these $bigcorp register their "campaigns" to combat scams and they'll leave me alone (one number sending texts to always the same one or handful of numbers).

... Oh wait I figured it out! Telco don't care, they enjoy inflated traffic numbers in their network and charge for it - why would they stop it

Re: Thanks FedEx, this is why we keep getting phished

#130
post #117

Earlier quoted context omitted.

It's the electronic version of a safe deposit box

I can understand that marketing message making sense and appealing to.. some people; I am surprised to see it on HN though. This is like buying vegetable & olive oils from BP or Shell because they're oil experts looking for new income streams as we shift away from petroleum.

Without knowing the details, one difference from your hypothetical could be ease of access to 3rd parties, especially after death.
Post reply on HN