Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

161–170 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#161
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Yeah, was working for a (then) 15k employee company and got an email "You have expenses due". Blank content, PDF attachment. I hadn't initiated any payments (but it later turned out the bank had just charged the annual tax on my corporate card account)

Ignored it.

Later got my manager asking as the expense team had been chasing down managers of people with overdue reports.

Re: Thanks FedEx, this is why we keep getting phished

#162
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

The lack of use of a non-corp domain, the typos and the use of shortened links does sound like a form of incompetence, probably at the management layer.

However, the password rotation requirement was until relatively recently something that many IT auditors would actually recommend, even though it leads directly to bad user password choices. In fact I wouldn't be at surprised to learn that was still the case in a lot of places.

Re: Thanks FedEx, this is why we keep getting phished

#163
post #81

Your security is increasing at risk from organisations and corporations whose own grasp of security is appalling. Because instead of dealing with it they externalise risks and consequences onto the public and customers. Even worse, is where attempts to query that security is actively punished . This is typical now. Listen here (at 42:20) with an example regarding the UK NHS whose incompetence plays directly into the…

Even worse, is where attempts to query that security is actively punished. like this case: https://news.ycombinator.com/item?id=37250024

My UK bank semi-regularly cold-calls me and ask me to authenticate by providing personal information. When I decline they readily tell me instead to call some number available on the bank website. So they not only are incompetent, they actually know it.

Re: Thanks FedEx, this is why we keep getting phished

#164

Earlier quoted context omitted.

Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.

Forced password updates are a bad thing. If your company does forced password updates, they are not following the NIST recommendation: https://pages.nist.gov/800-63-FAQ/#q-b05 If your company is not following the NIST recommendation, they are incompetent, and will be held liable in case of a breach.

The company I work for had a ransomware issue, so they got more zealous about security.

They require us to change our passwords every 45 days now. When I pointed out the NIST recommendations of not rotating passwords, they say they are following the guidance of the response team that helped them recover from the ransomware. And that the NIST doesn't actually deal with the real world.

Re: Thanks FedEx, this is why we keep getting phished

#165
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

My company's security training tells me to carefully verify any URLs in received emails, but then they have some security software that rewrites all the URLs in incoming emails - presumably as a way of screening them themselves.

This might be a reasonable trade-off for centralising monitoring, but it significantly hampers the ability to judge the legitimacy of emails myself. At least update your training!

Re: Thanks FedEx, this is why we keep getting phished

#166
post #124
post #36

Earlier quoted context omitted.

Clearly the safer option is sending the terms via CD https://t3n.de/news/sparkasse-digital-strategie-cds-per-post... Since no-one has a CD drive in their computer anymore, the security risk is negligible

And even if you do have a CD drive in your computer, the risk is still lower than a USB stick. A CD contains only data, it cannot do things like emulating a keyboard. The worst it can do is shatter when your high-speed DVD-ripping drive spins it up a bit too fast.

CD drives may not be able to emulate a keyboard, but they can certainly install software. You might not click on any system popups that appear after inserting a malicious CD, but the sort of people who plug in random USB sticks likely wouldn't bat an eye.

"The Sony BMG CD copy protection scandal concerns the copy protection measures included by Sony BMG on compact discs in 2005. When inserted into a computer, the CDs installed one of two pieces of software that provided a form of digital rights management (DRM) by modifying the operating system to interfere with CD copying. Neither program could easily be uninstalled, and they created vulnerabilities that were exploited by unrelated malware. One of the programs would install and "phone home" with reports on the user's private listening habits, even if the user refused its end-user license agreement (EULA), while the other was not mentioned in the EULA at all. Both programs contained code from several pieces of copylefted free software in an apparent infringement of copyright, and configured the operating system to hide the software's existence, leading to both programs being classified as rootkits."

https://en.m.wikipedia.org/wiki/Sony_BMG_copy_protection_roo...

Re: Thanks FedEx, this is why we keep getting phished

#167
post #27

Earlier quoted context omitted.

You mean everyone should install a piece of software from a company that appears to be ignorant about security?

And buy a very expensive tracking device with frequent security issues? I am lucky to live in a country in which a large religious population eschews the smartphone, so saying "I don't have one" is acceptable and common here. But I have colleagues who tell me that they are expected to have a smartphone from everything to banks to government services to simple small restaurants.

Was also thinking, cool, where is this place, and how do I sign up?

But then I remembered, I already belong to a religion that makes the ownership of a smartphine quite unconscionable to me.

Indeed I wrote about how even a religious objection is unnecessary when there's a knock-down argument on the grounds of what is merely patently unethical.

> are expected to

I find these "expectations" come from those who didn't read Dickens.

[0] https://news.tuxmachines.org/n/2023/03/06/Microsoft_is_Not_a...

Re: Thanks FedEx, this is why we keep getting phished

#168

Earlier quoted context omitted.

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.

In combination with forced changes, it leads to…

Password1

Password2

Password3

Etc

Re: Thanks FedEx, this is why we keep getting phished

#169

So far every time I’ve gotten dodgy AF texts or emails I’ve been able to verify at the real site… crazy that FedEx doesn’t have the info attached to the tracking.

> crazy that FedEx doesn’t have the info attached to the tracking It is crazy how much the "paying duties at the border" situation feels like an afterthought for all currier companies. It is almost as if it was not really their design they just tackled it on later. I wanted to send a present to my brother in an other country using DHL Express. It was impossible to convince them that I would like to pay duties. Not a…

They get a significant markup for providing this "service" to the receiver, so it is not in their interest to help the sender. More charitably the actual duties to be paid might not be known until the package reaches the border at destination.

Re: Thanks FedEx, this is why we keep getting phished

#170

Earlier quoted context omitted.

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

The lack of use of a non-corp domain, the typos and the use of shortened links does sound like a form of incompetence, probably at the management layer. However, the password rotation requirement was until relatively recently something that many IT auditors would actually recommend , even though it leads directly to bad user password choices. In fact I wouldn't be at surprised to learn that was still the case in a lo…

Fortunately NIST has specific advice that recommends against that which is admissible in court (in the US). I'm not sure how to work through the bureaucracy to do this, but your company should sue them in court for incompetence to get their money back.
Post reply on HN