Live data from Hacker News

Launch HN: Riot (YC W20) – Phishing training for your team

news.ycombinator.com

21–30 of 93 posts

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#22
post #21

How do avoid spam filters when sending your fake phishing emails?

Depending on your email provider (most of the time it's Google), you need to whitelist the IP address I use to send the emails. It takes probably no more than 4 minutes to do.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#23

How do you differentiate yourself with places like https://www.knowbe4.com/ which offer free services against phishing.

I tried Knowbe4, I think it's a horrible product.

I heard once you try the "free service" they call you daily to sign you up for the paid plan.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#24
post #11

> Would love to hear your war stories on phishing scams, and how you train your teams! I was working on anti-phishing in 2003, before it had the name phishing. We were trying to teach our users not to fall for the scams. It didn't work. People will fall for the same scam over and over. The conclusion we came to was that the only solution to phishing was education, and education was also nearly impossible to get 100%…

I actually started coding in 2000 trying to hack my brother, so I can relate: phishing has been a never-ending story. It's still worth trying though!

Definitely worth trying! Just want to help you set expectations. :)

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#25

> "I was pissed" How do you balance/deal with "security shaming", which is proven to put you further at risk as an organization? There is some interesting research from the UK Government in this space - https://www.ncsc.gov.uk/blog-post/trouble-phishing#section_3 The relevant bit: "If just one user reports a phish, you can get a head start on defending your company against that phishing campaign and every spotted ema…

1. There's an option to hide the names of the employees. It would replace all the names with random animal name + a color. It's great if you don't want to know which employees are falling for attacks. 2. I love the idea to actually make the employees create their own attacks, but seems a bit hard to do and pretty much time consuming for a company.

Its not the actual individuals - its the culture it creates, "HA! We caught you, you dumbass, here's 2hrs of training". This means people are afraid to report or take ownership over looking out for phishing as it creates no benefit for them, its just there to make the security team smug.

Having been part of and designed these campaigns before (with open source options like https://getgophish.com/), there is no way to report as phishing or reward users who detected but therefore didn't interact with it. This means in your example - did the other 81% just not open it, ignored it, or actively thought it was phishing? These are key metrics a company needs to know their potential attack surface.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#27
post #26

What are the steps necessary to get this up and running? Step 1, 2, 3... Besides signing up. ESP if you have O365 or GApps for mail.

1. Import the list of your employees.

2. Whitelist the IP address we use to send the emails.

3. Activate the "phishing simulation" module.

4. Wait and see.

Takes 5 minutes.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#28

Earlier quoted context omitted.

Definitely bad timing. My experience with names: they are never good enough. What I look for in a name: 1. If I say it out loud, you know how to write it. 2. If I say it out loud today, you remember it tomorrow. On that 2 criteria, Riot works quite well I think.

It's bad in that there's already a very popular game company named Riot (Games) which everyone refers to as 'Riot'.

Disagree, I have serious doubts you could confuse the two. I can see almost no context where 'Riot (Games)' and 'Riot (Anti-Phish Company)' could be meaningfully confused.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#29
I work at a large professional services firm (think Big 4), so the risk of any single breach in our network is taken pretty seriously. Our IT department added an Outlook plugin years ago that you can use to immediately reporting phishing attempts to them. As a bonus, they'll sometimes send these "tests" and if you select to "Report Phishing", you'll get a atta-boy type notification. I would assume at a macro level, they have stats on everyone and know who the "riskier" employees are. I have no idea if this is done inhouse at other large companies.

Sidenote/ question for you: some of the "test" attacks my company sends are very specific to the work we're doing and can sometimes sound very convincing. Do you have a catalogue of "attacks" based on industry or department (procurement might fall for something completely different than sales or marketing)? I'm sure with enough tests, you could measure the effectiveness of attacks (or maybe the difficulty of detection)... then you can start rating organizations not just based on what percentage of folks fell for it, but what specifically they fell for, or what was more likely to get them to bite. Almost like targeted training?

Cool idea overall and wish you guys the best.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#30
post #11

> Would love to hear your war stories on phishing scams, and how you train your teams! I was working on anti-phishing in 2003, before it had the name phishing. We were trying to teach our users not to fall for the scams. It didn't work. People will fall for the same scam over and over. The conclusion we came to was that the only solution to phishing was education, and education was also nearly impossible to get 100%…

According to Wikipedia, the term phishing (or fishing) originated in the mid-1990s
Post reply on HN