Live data from Hacker News

Oxford Temporarily Blocks Google Docs

blogs.oucs.ox.ac.uk

151–160 of 160 posts

Re: Oxford Temporarily Blocks Google Docs

#151

Earlier quoted context omitted.

Spotting a phishing form only seems like "basic instruction" to you because you're highly computer-literate. It's not; it involves understanding at least some of DNS and the difference between hosts, domains and TLDs, URLs, HTTPS, and not to mention certificates and their validity. In your analogy, it's like saying "people shouldn't be allowed to use cars unless they can verify the hydraulic pressure in the master br…

How to spot a phishing form: 1) Did you click a link from an email? 2) Does the page it redirect you to ask for your login info? You may have received a phishing email. Are either true? 1) You expected this email because you were notified about it from another source e.g. website, support staff. 2) If you login to the website not via the suspicious link, the linked web page does not ask for your login. If you answere…

#2 - Many people don't know what a redirect is. Many of them don't really know the difference between email and www. Some of them won't know there is a difference; it's all just clicky things.

Here are some regular people's experiences of scams.

(http://www.moneywise.co.uk/scams-rip-offs/scams/scam-watch-t...)

#1 - Yes, some scams are reasonably sophisticated.

(http://www.guardian.co.uk/money/2012/may/23/credit-card-user...)

Re: Oxford Temporarily Blocks Google Docs

#152
post #148

Earlier quoted context omitted.

Their email client can do it automatically. Basically, you just need to tell them, "Official emails will always have a big, green border around them." Also, the number of people who fall for 419 scams is fairly low, just barely above the threshold of profitability. The reason people are shocked when they hear that anyone falls for such scams is that hardly anyone does. There is a hypothesis that 419 scams are designe…

Their email client can do it automatically. Basically, you just need to tell them, "Official emails will always have a big, green border around them." You then have 2 problems: (a) What email clients will support it and (b) con artists will just put big green borders around their spam emails.

Further proof that HTML mail is a terrible idea...

(Edit: It is also conceivable that a client could put another prominent border around HTML mail, to mitigate the issue somewhat.)

Re: Oxford Temporarily Blocks Google Docs

#153
post #79
post #27

They're attacking the wrong part of the problem. If misleading messages ("phishing") are leading their users to enter credentials onto forms which are then used to send out spam, then the solution is not to block access to one of the sites that supports forms. There are an unlimited number of sites that support forms. There are LOTS of better ways to solve this problem. Here are a few: * Train your users where it is…

Oooooooooooooooo rant coming on............. Im sorry, but that is the typical tech reply that blows normal people's minds. Blame the user. Well, the user says, sod that, lets just block the problem and get on with what we wanted to do in the first place. People, normal non tech people, want to use computers as a tool, not become experts in thwarting criminals, etc. If a user cant just go to a computer and simply use…

> that is the typical tech reply that blows normal people's minds. Blame the user.

My bad... I never intended to suggest "blame the user".

> If a user cant just go to a computer and simply use it, like say a library or book, then the computer and its champions are failing. Its not the users job to provide security.

If I ran a library and I found that my visitors were just passing the same library card around to everyone in line, even strangers, instead of having each person get their own card, then I would say we needed some user education. We wouldn't need to issue special biometric IDs with a 22-step process to check out a book... but we would need to tell people "Hey, get your own card!"

Similarly, if I find that my IT system users are entering their login passwords in ANYTHING other than the login box (particularly online forms), then I have failed them -- I have failed to educate them about basic use of the systems. I should correct that, by coming to them and letting them know that I will NEVER ask for their password in ANY place other than the login form, and that they shouldn't enter it anywhere else.

> Then, you tell them to limit emails. "Oh right" says the user, "I thought one point of email was easy mass mailing, and now you want to bloke it?"

Actually, I wouldn't do it that way. I would set reasonable quotas (say, 100 outgoing emails before our rate limiting kicks in). After that, I would have it slow the rate of email sending, not block it. And if any user had sent enough that their mails were getting delayed, I'd also trigger a message to them inviting them to contact IT if they had special needs for mass emails. (We could change their quota, either temporarily or permanently, depending on what they were trying to accomplish.)

> Really think about the user.

Extremely good advice. I agree with your rant.

Re: Oxford Temporarily Blocks Google Docs

#154
post #94
post #79

Earlier quoted context omitted.

Oooooooooooooooo rant coming on............. Im sorry, but that is the typical tech reply that blows normal people's minds. Blame the user. Well, the user says, sod that, lets just block the problem and get on with what we wanted to do in the first place. People, normal non tech people, want to use computers as a tool, not become experts in thwarting criminals, etc. If a user cant just go to a computer and simply use…

I agree with your POV and the decisions we have to make as a result. That said, users should be expected to learn computers if they want to use them. If not, they shouldn't be allowed to use them. Same policy I'd have with a buzz-saw in a shop. So if you fall for email phishing attacks despite training, then you shouldn't be trusted with mass email rights. Likewise, the admins have an obligation to control those reso…

I disagree. Unless the user is intentionally TRYING to break the system, it is probably not the user's fault. It is IT's fault for failing to make it easy for the user to understand.

For instance, how about if the login page says in big bold letters: "This is the ONLY page you should ever enter your password on." With this tiny change, moderately competent users are much better protected from phishing attempts that use something like Google Docs forms... although that still hasn't protected them from something like a hand-crafted phishing site. Other techniques can help with this: for example, you could offer a bounty: pay real dollars for the first person to report any phishing site resembling your login page.

Some steps are up to the user, but instead of BLAMING the user, make it EASY for the user.

Re: Oxford Temporarily Blocks Google Docs

#155
post #150

Earlier quoted context omitted.

Most bureaucratic IT departments (i.e. big corps, govs, schools) tend to be more about the reduction of work for the IT department and less about the best solutions for the users.

Since IT departments are generally regarded as cost centres & therefore they are usually either understaffed or expected to keep costs to the absolute minimum by upper management this is hardly surprising. In this particular case, the department is in a double bind: the success of phishing emails threatens the ability of the university to send email to many other major hosts on the net. If you sat the users down and…

> If you sat the users down and asked them which they need more, a reliable email to people outside the university or access to Google Docs, then the decision isn't so clear cut all of a sudden is it?

But it's a false dichotomy: there are solutions that preserve both.

Re: Oxford Temporarily Blocks Google Docs

#156
post #140

Earlier quoted context omitted.

My mom told me not to take candy from strangers. Why can't you tell users not to give out their password? And yes, that means not putting in the password when they click a link. Only when they access the website themselves.

I guess you can - I see what you mean. But when looking for an answer I found that you're not training children here. You're preaching to grown-ups who are not that^H^H^H^H trainable.

15 years ago, when computers were less ubiquitous than today, I worked with near-retirement-age users (many 55 or 60 yrs old) who had NEVER used a computer (I had to start by teaching how to move a mouse). And they were perfectly trainable as long as you didn't start with an attitude that they were dumb for not already knowing this stuff.

Re: Oxford Temporarily Blocks Google Docs

#157
post #156

Earlier quoted context omitted.

I guess you can - I see what you mean. But when looking for an answer I found that you're not training children here. You're preaching to grown-ups who are not that^H^H^H^H trainable.

15 years ago, when computers were less ubiquitous than today, I worked with near-retirement-age users (many 55 or 60 yrs old) who had NEVER used a computer (I had to start by teaching how to move a mouse). And they were perfectly trainable as long as you didn't start with an attitude that they were dumb for not already knowing this stuff.

My father's pleasure is to spend half an hour a day on Windows Solitaire. He moves the cards faster than I can see what the cards are... It took him probably a week to accommodate with the mouse and now he is faster than anyone I know. My guess is that if he knew a little bit of English he would have entered "that Internet of yours" with no difficulties. He is technical literate mind you - he build in the early 90s a Spectrum clone.

On the other hand I see plenty of 25+ people that don't care too much to change their status quo. I might as well be one of them and pretend I'm not.

Re: Oxford Temporarily Blocks Google Docs

#158
The problem is that unless you are a Google Apps for education customer who can get Google on the phone, the form doesn't come down for weeks.

That means they'll have hundreds of credentials and can do all sorts of nasty things to your computing environment and to people's accounts.

That's not acceptable.

Hopefully Google will treat this more seriously now that it's hit the press.

Re: Oxford Temporarily Blocks Google Docs

#159
post #148

Earlier quoted context omitted.

Their email client can do it automatically. Basically, you just need to tell them, "Official emails will always have a big, green border around them." You then have 2 problems: (a) What email clients will support it and (b) con artists will just put big green borders around their spam emails.

Further proof that HTML mail is a terrible idea... (Edit: It is also conceivable that a client could put another prominent border around HTML mail, to mitigate the issue somewhat.)

Heh, and you think people will be able to tell the difference between HTML email with a border, and the border around certified email.

Re: Oxford Temporarily Blocks Google Docs

#160
post #82
post #50

Earlier quoted context omitted.

Yet they apparently have not implemented 2-factor authentication or rate limiting for students' email accounts... As others have pointed out, there are a few very simple ways to deal with this sort of thing. Rate limiting alone would like take care of the problem. This is probably a simple config update on the smtp server.

Catering for such a large and varied set of users requires difficult evaluation of risks and benefits to the majority. The underlying problem in this situation was that Google were so slow to respond to reports of malicious content. The brief block on Google Docs has served as an excellent way to get attention and highlight a number of things that need consideration.

Google was picked on b/c it was an easy target. I'm sure there are plenty of other fishing sites out there that don't use Google, yet those weren't blocked. This a seriously boneheaded way to go about things. Unless you are just going for media attention.
Post reply on HN