Live data from Hacker News

Want to piss off your IT department? Are the links not malicious looking enough?

phishyurl.com

131–140 of 335 posts

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#134
post #9

Not bad! https://carnalflicks.online/var/lib/systemd/coredump/logging...

Not going to lie, I was expecting this[1]. Maybe it's just not done on HN. 1: https://pc-helper.xyz/scanner-snatcher/session-snatcher/cred...

I’m surprised I had to travel this far to find it.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#135
post #45

I registered the "very-secure-no-viruses.email" domain to use for burner emails. I was trying to make one that sounded maximally sketchy. It has lead to some confusing interactions with support though...

I have firstname@lastname.email... people keep telling me that can't be right and don't i mean it ends with email.com?

I have a .co domain and noticed that some people think it’s a typo and adjust it to .com

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#136
post #112
post #89

Earlier quoted context omitted.

If you have a back channel in the audience you should get a large enough group to ask this question in the free form feedback box in the exactly same wording. Should send chills down the lord of HR spine. Don’t do it with a group which isn’t large enough though, you’ll get you all fired for unionizing^W no reason.

Again, there's no incentive to do this. It's full of downsides, and the only upside is some lolz from trolling.

More like chewed out. I've been chewed out before.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#137

All of this reminds me of a hilarious situation at a previous employer. As is standard corporate practice, they used to tell people to inspect links by hovering over them to confirm that they lead to the official website of the sender. People kept falling for phishing links though, so they got a Trend Micro device to scan emails, which also rewrote every link in it to point to their URL scanning service, which means…

I had the opposite funny experience. When I worked for Global MegaCorp, they would occasionally send out phishing emails and if you clicked on a link it would be recorded and you would have to do trainings if you got fooled a couple times. Eventually everyone learned to stop clicking on links on emails. That's good. However, they sent out a yearly survey to get feedback from all the employees and no one clicked the l…

That's actually super funny and it is not first time I see quite the same story.

They train people not to click links and then someone in management is fucking stupid enough to pull "just send an email with a link" kind of crap instead of properly planning the communication in advance by telling people that there will be a survey, what will be the company that is sending it, when they should expect it - but that just "too much work".

I would fire that kind of clown ass on the spot for not doing their job.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#139

Earlier quoted context omitted.

The way they used to handle that at a FAANG I worked for was they had this app installed on each machine issued by IT, that would ask you a question daily about some aspect of your workplace. Handles all the phishing concerns, except that participation was either low or the feedback was negative, which would lead to the leaders issuing subtle threats to the team about how they'd find out the involved folks and fire t…

That sounds absolutely horrifying

The behavior is Org and department specific. What happens is that those questions are map to a 'Org Health' metric (satisfaction, innovation, etc) and they are Manager aggregated, so your Manager's manager saw those report and your Director saw your skip manager's and so on. I would say my org was very healthy in terms of handling it, no treaths or anything, just asking us what we thought was going wrong, how to improve and coming up every year with a new SOP to do the connection's review.

Again, YMMV.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#140

All of this reminds me of a hilarious situation at a previous employer. As is standard corporate practice, they used to tell people to inspect links by hovering over them to confirm that they lead to the official website of the sender. People kept falling for phishing links though, so they got a Trend Micro device to scan emails, which also rewrote every link in it to point to their URL scanning service, which means…

I had the opposite problem at my last company. When you hover over a link Apple's Mail app opens a preview of the page. So if you try to see the URL then you automatically visit the link and get sent for more training.
Post reply on HN