Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

191–200 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#191

Canada Post actually does something good here: you can pay from the tracking page. And they don't add any fees, you just pay the duties and taxes.

> And they don't add any fees, you just pay the duties and taxes.

Are you sure about this? Canada Post's webpage (https://www.canadapost-postescanada.ca/cpc/en/support/articl...) says:

>> We apply a handling fee of CAN$9.95 per dutiable or taxable mail item.

Re: Thanks FedEx, this is why we keep getting phished

#192
post #89
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Healthcare companies in the US send the most scammy looking links for payment processing you’ve ever seen - things like my-healthcare-billing.net It’s insane.

Lets not forget all the typosquatting looking domains Microsoft uses. It almost seems like they bought them up to protect users, forgot why they did that and said "hey we have all these domains, lets use those?"

Re: Thanks FedEx, this is why we keep getting phished

#193

Earlier quoted context omitted.

NIST, whose guidelines, somehow, even other federal departments and agencies usually don’t follow. NIST has very good password complexity and management guidelines. Just USE THEM! It’s not that hard! How do you have billion dollar companies that can’t RTFM.

NIST whose guidelines are admissible in court and a competent judge will take over expert testimony. (an expert witness who says something that contradicts these guidelines is guilty of perjury, though good luck persecuting that)

Perjury is lying under oath, not disagreeing with government guidelines.

Re: Thanks FedEx, this is why we keep getting phished

#194

Earlier quoted context omitted.

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.

I mean it's great for 99% of your passwords and pretty much forces people into using randomized generated passwords.. but I still have to remember at least ONE password by heart. Whether it's 32 characters or 16 or what not, I still need SOME way to get into my password manager to even get to my passwords. So what, I'm going to make my password tacokissies69 and.. what, add a 0 every 6 months so I pass the 20 password minimum?

So a hacker can infer that my password is tacokissies69000 of some sort..

Re: Thanks FedEx, this is why we keep getting phished

#195
post #22

Earlier quoted context omitted.

But in a modern day and age, when aren’t you expecting a package? Nearly 100% of the time, I am expecting a notification from Canada Post or Amazon (FedEx less frequently, but still). Even outside of that, you can often predict when people are expecting a package. Christmas. After various sales weeks.

> But in a modern day and age, when aren’t you expecting a package? When you’re not constantly buying things online. Most people in the world aren’t expecting packages “nearly 100% of the time”.

Maybe not in the world, but in my country (the Netherlands) in 2022 (last available data) there were 473 million packages send to 8.3 million households, which works out to a bit more than one package per household per week.

Re: Thanks FedEx, this is why we keep getting phished

#196
post #166
post #124

Earlier quoted context omitted.

And even if you do have a CD drive in your computer, the risk is still lower than a USB stick. A CD contains only data, it cannot do things like emulating a keyboard. The worst it can do is shatter when your high-speed DVD-ripping drive spins it up a bit too fast.

CD drives may not be able to emulate a keyboard, but they can certainly install software. You might not click on any system popups that appear after inserting a malicious CD, but the sort of people who plug in random USB sticks likely wouldn't bat an eye. "The Sony BMG CD copy protection scandal concerns the copy protection measures included by Sony BMG on compact discs in 2005. When inserted into a computer, the CDs…

I think windows has moved away from executing autorun exes from discs by default a few versions ago. But back in the day it would prompt you what to do when you insert a USB storage drive, and just run whatever's set as the autorun if it's on a disc.

The common way to get USB malware to install automatically those days was to modify the USB drive to appear as a virtual disc drive, which worked.

Re: Thanks FedEx, this is why we keep getting phished

#197

Earlier quoted context omitted.

The lack of use of a non-corp domain, the typos and the use of shortened links does sound like a form of incompetence, probably at the management layer. However, the password rotation requirement was until relatively recently something that many IT auditors would actually recommend , even though it leads directly to bad user password choices. In fact I wouldn't be at surprised to learn that was still the case in a lo…

Fortunately NIST has specific advice that recommends against that which is admissible in court (in the US). I'm not sure how to work through the bureaucracy to do this, but your company should sue them in court for incompetence to get their money back.

Two then-current NIST standards (62 and 71?) side by side gave contradictory advice. It is a step forward though for sure.

Re: Thanks FedEx, this is why we keep getting phished

#198
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

My company's security training tells me to carefully verify any URLs in received emails, but then they have some security software that rewrites all the URLs in incoming emails - presumably as a way of screening them themselves. This might be a reasonable trade-off for centralising monitoring, but it significantly hampers the ability to judge the legitimacy of emails myself. At least update your training!

My company does that too, it's really annoying. They also sometimes send out mass emails for things like surveys but link to some third party service. I've even seen them put, in the email, things like "the link goes to a trusted third party and is perfectly safe". Why should I trust that if I'm already suspicious of the emails legitimately?

Re: Thanks FedEx, this is why we keep getting phished

#199
I got an sms from "Nikki Haley" the other week asking me to join some political rally. This has SUCH potential for abuse.

A) spreading misinformation. Not hard to confuse people that their polling location is closed but the inconvenient one across town is still open

B) fake fundraising. Blast out an sms from "citizens for action" who need money to support ${popular cause/candidate}

Re: Thanks FedEx, this is why we keep getting phished

#200
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

> have to type 10-20 per day

Same problem here. My solution: Get a mouse with internal memory for macros, such as Natec Genesis GX78 (old, no longer available, but this is an example). Program your new password on one of the unused mouse buttons or in a different profile. Use the mouse to type the password.

Post reply on HN