Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

191–200 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#191
post #4

How hard is it to make people understand what a business email should or shouldn't include? If you're being asked for data by someone you don't know, either ask a manager or someone connected to the account in question. Are people really so gullible & trusting?

The trouble is that people have a ton of intuitive buttons to push, and being intuitive they're not usually aware of them. (In straight cons, the buttons are often emotional, which is why the term con comes from building "confidence." Phishing is more faking authenticity than appealing to emotion.)

Skepticism and rational thinking require effort, and thus as people are rushed or tired, those are the first defenses to fail. You can train to recognize patterns of phishing, but learning those patterns takes time, repetition and effort.

All that a good phish requires is finding the right buttons to push on the right person, and they have many potential victims to press them on, and little to no consequence to getting it wrong.

So, the answer is people are not particularly gullible, but the weak links are a constantly changing, largely unknown dynamic and the phishers can hammer at all of them simultaneously until they get through.

Re: Should Failing Phish Tests Be a Fireable Offense?

#192

I know no civilised country which law would allow such a thing. Maybe for military or something, but anything else would simply not fly as it instigated and fake. What if they responded OK in a real situation? Also it would completely kill your workforce morale. Do you really want to run a fear based organisation?

I find such situations quite motivating to look for other jobs. In my industry, it usually means they’re going to implode.

But if you’re running a monopoly, you’ll continue to exist, just in a poorly functioning state that people have to deal with anyway.

Re: Should Failing Phish Tests Be a Fireable Offense?

#193
post #56

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

It should be appealable. I see at least two problems with such a phishing test: a) Some test phishing urls include the plaintext mail address of the employee. Easy to retaliate against someone you don't like. b) Does the phishing test service detect if the link is accessed via a sandboxed env?

> b) Does the phishing test service detect if the link is accessed via a sandboxed env?

In any company likely to be doing phishing testing internally, there are two kinds of people who might try this. One is the infosec group, which isn't going to do this because they're running the test. The other is engineers who think they're clever and are equipped to fsck around with things.

The former are professionals. The latter are dangerous and not actually an exception. The frequency with which their confidence is justified approaches zero and in the vast majority of shops simply not worth the time it takes to contemplate.

Re: Should Failing Phish Tests Be a Fireable Offense?

#194

Earlier quoted context omitted.

Did you alter the URL at all? Every phishing test campaign I've seen has a URL in the form of like http://totallylegit.your-company.com/somePath/login?id=12345... . I'd change the id= to some other value before testing to mess with their tracking.

Unless you're certain how that ID is generated and/or linked to your identity, you've probably just put someone else at your company on the naughty list.

Just change it something incredibly unlikely. Like "id=1".

Re: Should Failing Phish Tests Be a Fireable Offense?

#195
post #25

I'm a tech professional and security is a regular part of my jobs. At one point -- while contracting for a Fortune 500 client that shall remain unnamed -- I received an email that was quite clearly phishing. Curious as to what the payload was and whether it was worth reporting, I fired up lynx and followed the link in the email from the command line. I was promptly informed that I had failed the test and I would be r…

Counting opening a mail as failing is ridiculous. A a phising test should only count captured logins.

Following a link can readily enough expose someone to risks. Phishing isn't always just about entering logins.

Re: Should Failing Phish Tests Be a Fireable Offense?

#196

Earlier quoted context omitted.

I rather like my buildings' set up for this— We have passcarded doors and then inside we have gates like many subway stations do that are timed only long enough for one person to pass through. So I can hold the door open for someone on the way in—especially if they have their badge out— but there's nothing I can do about those giant plexi gates once inside. They have to swipe.

The city of Toronto would like to hear from you. Our Subway turnstiles keep breaking. And since they’re entry and exit, there’s many methods to enter by triggering the exit side, from umbrellas to a small dog.

The City does not want to be sued by the estate of someone cut in half by a turnstile gate. This limits the available force and material strength.

The specifications for those gates almost certainly include a requirement that they allow a sufficiently determined person through without breaking themselves, and probably sound an audible alert.

Re: Should Failing Phish Tests Be a Fireable Offense?

#197

In my office we can get into trouble for this. However, they always send a magic header in the email to get through the firewall. My solution: filter out emails with the header.

What if a spearphisher is watching out for the test emails on one account and we lose the magic headers that bypass the firewall? What then???

Re: Should Failing Phish Tests Be a Fireable Offense?

#198
post #56

Earlier quoted context omitted.

It should be appealable. I see at least two problems with such a phishing test: a) Some test phishing urls include the plaintext mail address of the employee. Easy to retaliate against someone you don't like. b) Does the phishing test service detect if the link is accessed via a sandboxed env?

>Does the phishing test service detect if the link is accessed via a sandboxed env? Does it really matter? I used to play these games with my org's absurdly obvious phishing trainers, but the truth is it's not my job to determine whether an apparent phishing email is genuine or not. If you know that getting phished is a fireable offense, then just don't access the links, obvious fake or not.

THIS

I forward all emails that are not directly from people in the company to the trash.

I also forward anything with the word "phishing", "test", "audit", and our our IT and security department.

The other strategy I have is simply not checking email.

This is so useful, while others are taking security test, and failing phishing link test. I am in the clear.

What test? I did not get the email. You clicked what? Humm, I did not get that email. Man you got a virus -- I run Linux and access my email via Emacs/Mu4e -- also I did not get that email.

https://imgur.com/y3sSYyd

All problems solved!

Re: Should Failing Phish Tests Be a Fireable Offense?

#199

Earlier quoted context omitted.

Did you alter the URL at all? Every phishing test campaign I've seen has a URL in the form of like http://totallylegit.your-company.com/somePath/login?id=12345... . I'd change the id= to some other value before testing to mess with their tracking.

Unless you're certain how that ID is generated and/or linked to your identity, you've probably just put someone else at your company on the naughty list.

Be a good guy greg and write a quick curl script to hit all 25k other links. If everyone is in trouble then no one is in trouble!

Re: Should Failing Phish Tests Be a Fireable Offense?

#200
post #4

How hard is it to make people understand what a business email should or shouldn't include? If you're being asked for data by someone you don't know, either ask a manager or someone connected to the account in question. Are people really so gullible & trusting?

Have you ever worked for a big company? (Think several US offices, half a dozen European and Asian offices, 500m in revenue). Someone forwards me an e-mail from our Dutch office that says, essentially, "The world is burning down, we are boarding a plane in a couple of hours to go to IFA (show), and we don't have the latest copy of product X to demo for customers." I do builds by hand of this product because I can't g…

> I'm the only person in the entire world with the encryption keys to provision the product

The chaos that surrounds you, the facts that astound you, at last your number has found you, your bus number is one.

Post reply on HN