Earlier quoted context omitted.
Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…
I forget who puts that stuff out NIST/STIG(?) but IIRC in the recent few years they determined that rotating passwords like that was basically security theater and wasn't worth the damage to the staffs productivity
Thanks FedEx, this is why we keep getting phished
171–180 of 576 posts
Re: Thanks FedEx, this is why we keep getting phished
#172Earlier quoted context omitted.
Anyone found this? Can you remember the episode?
Found it here. https://i.blackhat.com/us-18/Wed-August-8/us-18-Shostack-Thr... He used the term "scamicry": legit communications that mimic scams. For example when a company calls you directly and asks for your security details, but offer you no way to verify who they are first.
Re: Thanks FedEx, this is why we keep getting phished
#173Earlier quoted context omitted.
Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.
Forced password updates are a bad thing. If your company does forced password updates, they are not following the NIST recommendation: https://pages.nist.gov/800-63-FAQ/#q-b05 If your company is not following the NIST recommendation, they are incompetent, and will be held liable in case of a breach.
This is a stretch. Liable? Please show the case law, or the legislation.
(My statement has no relevance to the validity of NIST's recommendations)
Re: Thanks FedEx, this is why we keep getting phished
#174Earlier quoted context omitted.
I wanted to, but I could not find it. It turn out I could not see the "report phishing" button because of an Outlook glitch. Thanks Microsoft.
Forward the email to your security org?
Re: Thanks FedEx, this is why we keep getting phished
#175Re: Thanks FedEx, this is why we keep getting phished
#176Earlier quoted context omitted.
I forget who puts that stuff out NIST/STIG(?) but IIRC in the recent few years they determined that rotating passwords like that was basically security theater and wasn't worth the damage to the staffs productivity
NIST, whose guidelines, somehow, even other federal departments and agencies usually don’t follow. NIST has very good password complexity and management guidelines. Just USE THEM! It’s not that hard! How do you have billion dollar companies that can’t RTFM.
Re: Thanks FedEx, this is why we keep getting phished
#177A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…
It happens.
Re: Thanks FedEx, this is why we keep getting phished
#178A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…
If I saw one of those in a 100k employee company I'd first just assume it's a phish-test email and that anyone who clicks on any URL in it is going to get put in the list for remedial training. There are, of course, a whole plethora of services that a CTO-type person can hire to phish test your employees. Some of them even have several hundred real domain names with live MX on them that you can add into your office36…
Re: Thanks FedEx, this is why we keep getting phished
#179Earlier quoted context omitted.
Forced password updates are a bad thing. If your company does forced password updates, they are not following the NIST recommendation: https://pages.nist.gov/800-63-FAQ/#q-b05 If your company is not following the NIST recommendation, they are incompetent, and will be held liable in case of a breach.
If your company is not following the NIST recommendation, they are incompetent, and will be held liable in case of a breach This is a stretch. Liable? Please show the case law, or the legislation. (My statement has no relevance to the validity of NIST's recommendations)
Re: Thanks FedEx, this is why we keep getting phished
#180Earlier quoted context omitted.
I've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.
For some things, you must use paper (or as it turns out, USB). Why the bank decided to use USB for this purpose, instead of paper, is very strange.
Do you have a source backing that up?
Aside from the local tax collector, which insists on snailmailing me a copy of all correspondence even though they also sent everything to me digitally, I can't even remember the last time I received any documents on paper, and I'm in the EU.