Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

141–150 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#141
post #98
post #2

Suggest Law: If a company's electronic notification to you is so phishy that a "reasonable man" would have obvious cause to doubt its legitimacy, then all financial and legal consequences of ignoring it are on the sender . Edit: " sender " here refers to the sender of the electronic notification .

The management will overreact by implementing 100-factor authentication, requiring 30 letter password with mandatory Unicode symbols

A bunch of extra authentication factors and a password sure sounds like phishing for sensitive PII to me.

Re: Thanks FedEx, this is why we keep getting phished

#142
post #56

Earlier quoted context omitted.

I do not read this court decision like that at all: the point of contention there seems to be that the customer was just sent a link to a webpage (where the contractual terms can be changed from under him at will by the company, thus this not being durable). The court makes it pretty clear in my (non-lawyer) opinion that attaching a PDF to the email would have been fine.

I was prepared to disagree with you, but I now have the same interpretation you have. Durable medium can be email - but the example seems a little fuzzy, for instance a durable medium is definitely when the email is stored on a HDD on a customer device. But is it still durable medium if the email only exists in a webmail? Probably yes, but maybe no. So the conservative approach would be to send paper for some things.…

Most USB flash controllers support being read-only by either just being read-only or emulating optical drive. Obviously for the WORM usecase this is only an software solution inside the controller configuration as the underlying medium is still writable/erasable flash. In theory one could replace the flash with some kind of mask ROM with NAND-like interface and make it truly read only, but the cost makes that impractical for most applications.

Then there are LTO tapes that have WORM version, which is notionally not overwritable, but that is IIRC also only enforced by software (of the drive).

Re: Thanks FedEx, this is why we keep getting phished

#143
post #22

Earlier quoted context omitted.

But in a modern day and age, when aren’t you expecting a package? Nearly 100% of the time, I am expecting a notification from Canada Post or Amazon (FedEx less frequently, but still). Even outside of that, you can often predict when people are expecting a package. Christmas. After various sales weeks.

> But in a modern day and age, when aren’t you expecting a package? When you’re not constantly buying things online. Most people in the world aren’t expecting packages “nearly 100% of the time”.

If you buy stuff with long delivery estimates, you might very well be even with relatively low numbers, Electronics from China, Custom Comissions or things with waitlists

Some of those can have over a month between purchase and reception, and might be shipped at arbitrary dates after purchase

I'm not that big of an online shopper, but there's certainly people that are

Re: Thanks FedEx, this is why we keep getting phished

#144

Earlier quoted context omitted.

For some things, you must use paper (or as it turns out, USB). Why the bank decided to use USB for this purpose, instead of paper, is very strange.

Here in Poland, I've already had several banks and at least one insurer send me CD-ROMs. Never heard of anyone sending USB sticks before, but I'm not surprised. The problem is, approximately no one owns a CD/DVD reader anymore, and there are no modern read-only physical media. With SD cards also going the way of the floppy, USB stick is just about the only medium you can hope most customers have means to read.

SD cards are really neat. Theoretically they could have been made with a fixed notch so they would always present as read-only.

Re: Thanks FedEx, this is why we keep getting phished

#145
post #89
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Healthcare companies in the US send the most scammy looking links for payment processing you’ve ever seen - things like my-healthcare-billing.net It’s insane.

Yeah I got a text from one of these a couple years ago. Something like. “You have an overdue doctor bill of $183.56, please kindly pay immediately at this link: http://my-doctorpay.net/defintelylegit123. Thx!” Didn’t even include the name of the doctor or office, but after calling the only doctors office I had used recently it was apparently legit. I let them know whatever company handles their billing is completely incompetent.

Re: Thanks FedEx, this is why we keep getting phished

#146

Earlier quoted context omitted.

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.

Even if this rule technically seems benign, together with the forced change it encourages users to game the system leading to predictable patterns, eg adding a rotating letter or digit combo at the end of a same password.

Re: Thanks FedEx, this is why we keep getting phished

#147
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

I forget who puts that stuff out NIST/STIG(?) but IIRC in the recent few years they determined that rotating passwords like that was basically security theater and wasn't worth the damage to the staffs productivity

Re: Thanks FedEx, this is why we keep getting phished

#148
One time working at a bigger company I received an email that was a very, very obvious, poorly made phishing attempt - in fact, so poorly done that I wondered if I could break the login form somehow. So I submitted bogus data to see what happened -

Turns out it was part of some kind of "test" of the company to raise awareness for phishing, and I failed the test since I submitted the form.

Re: Thanks FedEx, this is why we keep getting phished

#149
post #43
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Did you click on the "Report Phishing attempt" button installed by your IT center in your mail client? Sorry for the probable sarcasm. In a company that size, if the IT center does not provide a means to report phishing attempts then there are more serious problems than a dodgy email campaign.

It’s a good idea.

I am usually a bit pessimistic about it though. If their SOP doesn’t account for “looks like phishing but is from internal sender” then chances are that nobody connects the dots and informs that sender.

The intelligence of a small and motivated IT team seems difficult to scale.

Re: Thanks FedEx, this is why we keep getting phished

#150
post #3

Maybe its just the hunan brain bad at perception, but I feel like there's some system compromised and info is leaked so scammers know when you are expecting a package because FedEx/USPS spam text increases.

But in a modern day and age, when aren’t you expecting a package? Nearly 100% of the time, I am expecting a notification from Canada Post or Amazon (FedEx less frequently, but still). Even outside of that, you can often predict when people are expecting a package. Christmas. After various sales weeks.

I would be curious if FedEx specifically has some sort of leak though, it's super anecdotal but I seem to get more FedEx phishing attempts when I'm expecting a FedEx package.

You're right though that there are other mechanisms for this, it was around the holidays when this happened most recently. Plus humans tend to remember salient things and I probably more easily forget the ones that come when I'm expecting nothing.

Anyway, if their systems were better it would be easier to avoid scams without stress. I've never had to rely on external info for Amazon and it's true I'm often expecting something from them.

Post reply on HN