Live data from Hacker News

Want to piss off your IT department? Are the links not malicious looking enough?

phishyurl.com

181–190 of 335 posts

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#181

Earlier quoted context omitted.

All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com

In Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.

Are you sure? Never seen any such thing.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#182
post #170

Earlier quoted context omitted.

1Password’s default for secret questions is a sequence of English words, rather than random gibberish.

See https://xkcd.com/936/

Why would you want to memorise a password? That's what password managers or even paper is for.

(Writing your passwords down on paper is actually less crazy than it sounds like:

It's impossible to hack paper from the internet. And, if someone has physical access to your stuff, they could install a keylogger anyway.)

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#184

Ah no need, corporate IT already make all URLs malicious looking through some microsoft "secure link" service, and constantly shows everyone shady looking prompts that constantly change and have cmd.exe windows flash in at random. A phone call from Microsoft about my Norton anti-virus subscription putting me into debt that can only be settled with Nintendo gift cards bought in cash across 16 specific gas stations see…

All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com

Outlook has a rule filter for header content.

Just saying I haven't failed a phishing test in ~10 years.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#185
post #110

Earlier quoted context omitted.

> And because there has been an inflation in how complimentary these letters are, people started suing when their letter wasn't flowery enough, because that somehow could be read as an implicit criticism. You got a source for this folktale?

I have no official source but know that this happens a lot. Also the arguments with the employer about the letters afterwards. Some are so fed up and let you write the first or final draft. There is also the hidden code. So instead of writing something negative which is forbidden you just use different words or leave out some intensifications. Like “zur größten Zufriedenheit” vs “zur allergrößten Zufriedenheit”. One…

My question would be: why even bother with any kind of code? What incentive is there for the employer to write anything truthful, to write anything but the blandest most positive things that really don't say anything hidden?

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#186
post #110

Earlier quoted context omitted.

> And because there has been an inflation in how complimentary these letters are, people started suing when their letter wasn't flowery enough, because that somehow could be read as an implicit criticism. You got a source for this folktale?

this is common practice in general no? People ask for references, or try to contact former bosses, when hiring critical profiles. Obviously nobody will say anything bad, so HR is trained, and giving trainings to the hiring managers, how to "grade" the level of positivity. There's a difference in saying "Yes I confirm person X worked here, he did a good job on all the tasks that we have asked him to do" vs "Yes, he wa…

> this is common practice in general no?

The German situation is especially unhinged. See https://de.wikipedia.org/wiki/Arbeitszeugnis (ask Google Translate for help, if necessary).

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#187
post #110
post #67

Earlier quoted context omitted.

> So, in the end, people just started giving the best possible feedback regardless of the team or manager performance. That seems to be the best possible strategy for any feedback you have to give as a captive audience? Reminds me of the feedback German companies are forced to give about their employees. It's like a formal letter of reference, but you can and will be sued if you you anything negative. Consequences ar…

> And because there has been an inflation in how complimentary these letters are, people started suing when their letter wasn't flowery enough, because that somehow could be read as an implicit criticism. You got a source for this folktale?

You can check out https://de.wikipedia.org/wiki/Arbeitszeugnis with the help of Google Translate.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#188

Earlier quoted context omitted.

I have firstname@lastname.email... people keep telling me that can't be right and don't i mean it ends with email.com?

I have a .ninja email and get the same a lot to the extend where I explicitly say "it ends in .ninja with no .com or anything". Usually use company-i-buy-from@mydomain.ninja whenever I make online purchases, and I had a guy from a small shop call me up and ask why I had an email with his company name on. Took some good fifteen minutes to explain him that I was legit and owned the domain. He was still reluctant in the…

i practiced this email address scheme for a short period, then switched to ${my_initials}${few_digit_digest($other_party)}@${my_domain} $other party being a webshop, an online service, an institution, or a person.

then to ${my_initials}${random_few_digits}@${my_domain} to be able to hand out pre-generated email addresses of mine even offline, and bookkeep who has got which random number at my side internally.

this raised the least eyebrows so far.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#189
post #167
post #159

Earlier quoted context omitted.

There's no legitimate case for that since PSD2 (mandatory since 2020). Are you not confused by that? PSD2 doesn't share your credentials. I'm an European and have never needed to use nor encountered those services.

PSD2 is just MFA, it doesn't prevent shady companies still asking your login credentials, even if you must authorize that login from your official banking app. Klarna is one of many examples - they ask me for my bank credentials on their own website so they can crawl all my finance data .

Plaid and Finicity do this in the USA for some linking of banking to other financial products. Feels SO insecure. Connecting my credit union checking account through Plaid even ironically brought me to a login page which explicitly states I should never give my banking password to any other entity.

If I need to link my accounts and these services are the only choice then I change my banking passwords immediately after.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#190
I got an email the other day saying I had a new voicemail. The content of the email was regarding a new voicemail I received, and I should click the attachment to listen to it. The header and info was from some service that I had never heard of and we definitely don't use. Also, the entire message was a screenshot of an actual email, so there was no text, just one image. The attachment was a .html file.

I reported it for phishing and I kid you not, less than 30 seconds later I got a response "Email is not suspicious"

What do you MEAN email is not suspicious? This is the most suspicious email I have ever received!

Post reply on HN