Live data from Hacker News

Kurt Got Got

fly.io

191–200 of 256 posts

Re: Kurt Got Got

#191
post #116

When we did annual pen testing audits for my last company, the security audit company always offered to do phishing or social engineering attacks, but advised against it because they said it worked every single time. One of the most memorable things they shared is they'd throw USB sticks in the parking lot of the company they were pentesting and somebody would always put the thing into a workstation to see what as on…

Our company does regular phishing attacks against our own team, which apparently gets us a noteworthy 90% ‘not-click’ rate (don’t quote me on numbers). Never mind that that 10% is still 1500 people xD It’s gone so far that they’re now sending them from our internal domains, so when the banner to warn me it was an external email wasn’t there, I also got got.

I used to work for an anti-phishing focused brand protection firm, we provide training and testing to third parties and heavily, aggressively dog-fooded our own products.

So, of course, we got to a point as a company where no one opened any email or clicked any link ever. This caused HR pain every year during open-enrollment season, for other annual trainings, etc.

At one point they started putting “THIS IS NOT A PHISH” in big red letters at the top of the email body to get folks to open emails and handle paperwork.

So then our trainers stole the “NOT A PHISH” header and got almost the entire company with that one email.

Re: Kurt Got Got

#193

The part I found surprising: 'Twitter fell outside the “things we take seriously” boundary' Sure Twitter is rubbish, but it's still a huge platform, still tied to your brand, you're still using it, so it can still hurt you. Either take it seriously or stop using it.

You mean X, right? Sounds like neither them nor you take it seriously :)

Re: Kurt Got Got

#194

Earlier quoted context omitted.

The stray USB stick is how Stuxnet allegedly got deployed. Tbh I doubt that works in this day and age.

What I heard about the Stuxnet attack was different from what you are saying: The enrichment facility had an air-gapped network, and just like our air-gapped networks, they had security requirements that mandated continuous anti-virus definition updates. The AV updates were brought in on a USB thumb drive that had been infected, because it WASN'T air-gapped when the updates were loaded. Obviously their AV tools didn'…

Do you have any sources that the infected USB contained AV updates?

I can't find any sources saying that..

Re: Kurt Got Got

#195
post #116

When we did annual pen testing audits for my last company, the security audit company always offered to do phishing or social engineering attacks, but advised against it because they said it worked every single time. One of the most memorable things they shared is they'd throw USB sticks in the parking lot of the company they were pentesting and somebody would always put the thing into a workstation to see what as on…

Our company does regular phishing attacks against our own team, which apparently gets us a noteworthy 90% ‘not-click’ rate (don’t quote me on numbers). Never mind that that 10% is still 1500 people xD It’s gone so far that they’re now sending them from our internal domains, so when the banner to warn me it was an external email wasn’t there, I also got got.

>> so when the banner to warn me it was an external email

These are so obviously useless. When the majority of your email has a warning banner it stops to be any sort of warning. It's like being at "code orange" for 20 years after 9/11; no-one maintained "heightened security awareness" for decades, it just became something else to filter.

Re: Kurt Got Got

#196
post #67
post #59

Earlier quoted context omitted.

You’re right - I flagged on Thomas’s name in the signature and because I’ve seen him around here, well, forever, but Kurt is also extremely savvy.

No he's not! He got taken by this dumb phishing thing!

The post is good but this comment is funnier than the whole thing.

Re: Kurt Got Got

#197
post #27

Earlier quoted context omitted.

Yep. A technical half-baked solution to a problem that has been solved since it's inception. Really just feels like FAANG exists to invent new ways to charge rent...

What’s the solution for preventing this kind of phishing attack?

TLS client certificates. Unfortunately, the browser UI for them ranges from godawful to removed-because-nobody-used-them.

Re: Kurt Got Got

#198

The part I found surprising: 'Twitter fell outside the “things we take seriously” boundary' Sure Twitter is rubbish, but it's still a huge platform, still tied to your brand, you're still using it, so it can still hurt you. Either take it seriously or stop using it.

Before the Twitter Change of Control, we were actively using it. After, it fell into a kind of limbo. There was a solid 6 months or so when we thought maybe we were just going to do everything via our Hachyderm account. Shit's complicated. And if we'd stopped using it altogether, we'd still be in the same boat!

Re: Kurt Got Got

#199
post #7

I want to say again that the key thing in this post is that anything "serious" at Fly.io couldn't have gotten phished: your SSO login won't work if you don't have mandatory phish-resistant 2FA set up for it. What went wrong here is that Twitter wasn't behind that perimeter, because, well, we have trouble taking Twitter seriously. We shouldn't have, and we do take it seriously now.

I will say that a "Critical Security Vulnerability in flyctl, update now: https://bad-link/to/update.zip" tweet will have very serious consequences for a portion of your userbase, despite not directly compromising your own infra.

You could do that yourself today by getting a blue-checked @realFlyDotIo. But there's a paragraph in the article about this, and we know what we would have done had there been any signs of direct attacks on our users.

Re: Kurt Got Got

#200

I got hit with the same kind of phishing attack a couple months ago It's pretty incredible the level of UI engineering that went into it. Some screenshots I took: https://x.com/grinich/status/1963744947053703309

Hmm, since Chromium is working on adding browser-local AI features, I wonder if this one day could be a security check (for links opened from the outside of the browser). E.g. the browser detected that you clicked on a new-tab link, and the page looks like a commonly known site, then the AI detects that the URL isn't "x.com" and gives a heads-up warning. At least for the top 1000 most common sites, this could prevent a lot of phishing attacks.
Post reply on HN