Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

171–180 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#171
post #147

Earlier quoted context omitted.

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

I forget who puts that stuff out NIST/STIG(?) but IIRC in the recent few years they determined that rotating passwords like that was basically security theater and wasn't worth the damage to the staffs productivity

NIST, but they required password rotation up until very recently, against their own advice.

Re: Thanks FedEx, this is why we keep getting phished

#172

Earlier quoted context omitted.

Anyone found this? Can you remember the episode?

Found it here. https://i.blackhat.com/us-18/Wed-August-8/us-18-Shostack-Thr... He used the term "scamicry": legit communications that mimic scams. For example when a company calls you directly and asks for your security details, but offer you no way to verify who they are first.

You star! Thank you anon.

Re: Thanks FedEx, this is why we keep getting phished

#173

Earlier quoted context omitted.

Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.

Forced password updates are a bad thing. If your company does forced password updates, they are not following the NIST recommendation: https://pages.nist.gov/800-63-FAQ/#q-b05 If your company is not following the NIST recommendation, they are incompetent, and will be held liable in case of a breach.

If your company is not following the NIST recommendation, they are incompetent, and will be held liable in case of a breach

This is a stretch. Liable? Please show the case law, or the legislation.

(My statement has no relevance to the validity of NIST's recommendations)

Re: Thanks FedEx, this is why we keep getting phished

#174
post #107
post #46

Earlier quoted context omitted.

I wanted to, but I could not find it. It turn out I could not see the "report phishing" button because of an Outlook glitch. Thanks Microsoft.

Forward the email to your security org?

This. We have a dedicated phish/scam/it-sec channel in Slack for this (in addition to an embedded “report this email” plug-in in Outlook).

Re: Thanks FedEx, this is why we keep getting phished

#175
This is a real problem with so much stuff outsourced to external cloud providers. Used to be, if it was from the company intranet, no problem. Now every survey, every training thing, every new flavour of the month is from external mystery domains and then it wants your corporate credentials to log in. At my company they keep us sharp by running "fake phishing" campaigns to kind of gamify recognizing phishing emails. But this shouldn't be necessary for legitimate corporate stuff.

Re: Thanks FedEx, this is why we keep getting phished

#176
post #147

Earlier quoted context omitted.

I forget who puts that stuff out NIST/STIG(?) but IIRC in the recent few years they determined that rotating passwords like that was basically security theater and wasn't worth the damage to the staffs productivity

NIST, whose guidelines, somehow, even other federal departments and agencies usually don’t follow. NIST has very good password complexity and management guidelines. Just USE THEM! It’s not that hard! How do you have billion dollar companies that can’t RTFM.

NIST whose guidelines are admissible in court and a competent judge will take over expert testimony. (an expert witness who says something that contradicts these guidelines is guilty of perjury, though good luck persecuting that)

Re: Thanks FedEx, this is why we keep getting phished

#177
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

On our company (hosting & PaaS), I was contacted on our internal messenger by a person I've never seen before, asking me to "please" run some commands as root and send back the results. After the initial shock (and due infosec diligence) I found out it was just "the new guy", needing to collect info about our systems for equipment inventory purposes. Since they didn't have access to our networked management tool yet, and didn't know the finer points about how running `curl ... | sh` randomly is not a good idea, they thought it would be ok to get that information piecemeal directly from people.

It happens.

Re: Thanks FedEx, this is why we keep getting phished

#178
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

If I saw one of those in a 100k employee company I'd first just assume it's a phish-test email and that anyone who clicks on any URL in it is going to get put in the list for remedial training. There are, of course, a whole plethora of services that a CTO-type person can hire to phish test your employees. Some of them even have several hundred real domain names with live MX on them that you can add into your office36…

I love how those emails have extra metadata in the headers like "X-Phishing-Test: True"

Re: Thanks FedEx, this is why we keep getting phished

#179
post #173

Earlier quoted context omitted.

Forced password updates are a bad thing. If your company does forced password updates, they are not following the NIST recommendation: https://pages.nist.gov/800-63-FAQ/#q-b05 If your company is not following the NIST recommendation, they are incompetent, and will be held liable in case of a breach.

If your company is not following the NIST recommendation, they are incompetent, and will be held liable in case of a breach This is a stretch. Liable? Please show the case law, or the legislation. (My statement has no relevance to the validity of NIST's recommendations)

Not directly. However NIST is admissible in court and so if someone sues there is now evidence that they should have known better.

Re: Thanks FedEx, this is why we keep getting phished

#180

Earlier quoted context omitted.

I've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.

For some things, you must use paper (or as it turns out, USB). Why the bank decided to use USB for this purpose, instead of paper, is very strange.

> For some things, you must use paper

Do you have a source backing that up?

Aside from the local tax collector, which insists on snailmailing me a copy of all correspondence even though they also sent everything to me digitally, I can't even remember the last time I received any documents on paper, and I'm in the EU.

Post reply on HN