Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

201–210 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#201
post #44
post #32

Earlier quoted context omitted.

Often the phishing training says "do not investigate yourself" but maybe your company missed that part.

There's was the general "don't follow links in unknown emails" but nothing about what to do if you're sure it's a bad email but terminally curious. As far as I could tell nothing bad could happen (even JS was off in the browser I used to open it) when I followed the link, but is there something I should be aware of?

> what to do if you're sure it's a bad email but terminally curious

Don't open it.

"But what if it's Taco Tuesday and a full moon?"

Don't open it.

Re: Should Failing Phish Tests Be a Fireable Offense?

#202

Earlier quoted context omitted.

You are getting really hung up on a very tiny edge case. No reasonable manager would punish you for being physically overpowered. That doesn't mean you should encourage people to ignore the security policy. 99.99% of the time, saying to the tailgater "you need to swipe" is enough. If you do work somewhere where people are physically trying to break in often, then you ought to have real security personnel.

It's not about being punished for being physically overpowered - it's about being a five foot 3 intern and having someone 6'1 250 lbs, in a suit and in a hurry, behind you, tailgating. The implications are enough to make it a shitty situation for such a person have to turn around and say "sorry person that looks c-suite, you can't come in with me."

I’ve had it done to me when I was hired and they explained we don’t allow tailgating here. Even though they know explicitly who I am, they are my bosses boss, I still need to swipe my badge on every locked door.

I’ve done it to VP level and I’d do it to my CIO too. I’d be that guy who badged the CIO but I try to take basic security and company policy seriously. I’d like an intern who is professional enough to “challenge” someone. Not sure I would’ve at that time.

Re: Should Failing Phish Tests Be a Fireable Offense?

#203
post #149

Earlier quoted context omitted.

I rather like my buildings' set up for this— We have passcarded doors and then inside we have gates like many subway stations do that are timed only long enough for one person to pass through. So I can hold the door open for someone on the way in—especially if they have their badge out— but there's nothing I can do about those giant plexi gates once inside. They have to swipe.

A company I worked for just had revolving doors for all entrances

Some revolving door systems (not the ones you mean, probably) actually improve a lot on the classic turnstiles or gates.

They allow one authorized person to pass from one side through but sensors on both sides can easily detect if another person is trying to piggy back from the other side of the door. And there's no way over or around them. In higher security environments where unauthorized persons getting on the other side of the door is already an unacceptable risk they can also allow security personnel to trap someone in the door (rotate only 90 degrees).

And as far as usability and efficiency goes, they can allow traffic both ways at the same time (as long as both people are authorized).

Re: Should Failing Phish Tests Be a Fireable Offense?

#204

Earlier quoted context omitted.

You are getting really hung up on a very tiny edge case. No reasonable manager would punish you for being physically overpowered. That doesn't mean you should encourage people to ignore the security policy. 99.99% of the time, saying to the tailgater "you need to swipe" is enough. If you do work somewhere where people are physically trying to break in often, then you ought to have real security personnel.

It's not about being punished for being physically overpowered - it's about being a five foot 3 intern and having someone 6'1 250 lbs, in a suit and in a hurry, behind you, tailgating. The implications are enough to make it a shitty situation for such a person have to turn around and say "sorry person that looks c-suite, you can't come in with me."

This triggered a memory from my second "real" job.

We had a secure building with glass entry turnstyles. In my second week, a suited important-looking person was standing behind the gates at 8:20AM (we started at 8:30AM). It was busy and everyone was ignoring him (that seemed odd).

The suited guy picked me from the line of drones going through the turnstyles and asked if he could jump in behind me (he didn't even mention if he worked for the company).

I was still doing the HR training program stuff (the general wear deodorant, don't plug in flash drives from outside, don't ask for teamviewer, etc stuff) and the last thing we did the day before was end on the tailgating policy.

I told the suited guy that I couldn't let him in due to company policy. He smiled and said "all good" and went back to the corner.

He ended up being the head of logistics. Apparently, he liked to scope out the new hires and "test" their compliance. He tried this with 5 or 6 of the new hires and only managed to get let in once. The lady that let him in wasn't fired, but she did get a warning.

Re: Should Failing Phish Tests Be a Fireable Offense?

#205
post #134
post #104

Earlier quoted context omitted.

That’s not true. My workplace has employee only entrances where even visitor/temporary badges don’t work. No one is standing guard and they tell everyone to not allow tailgating.

That's the point. I was in the infantry, am 6'2, and a guy. I don't have a problem with challenging folks who are tailgating. That is not the case for everyone. Do you expect disabled folks to challenge tailgaters? What about physically small people? Setting aside the office dynamics around discrimination issues, how many people actually have the confidence to challenge an unknown person who is tailgating, knowing th…

We expect tiny people making minimum wage to ask thieves to pay for the cheese they’re shoplifting. This seems pretty minor by comparison.

I wouldn’t expect any physical force to be used. If asking politely doesn’t work, call security. If they threaten you into letting them in, comply, then call security.

Re: Should Failing Phish Tests Be a Fireable Offense?

#206

I have a client in the banking industry who performed these tests. Everyone failed. I'm not sure if they ran them again but there's a point where you need to sit someone down and explain how serious the situation is. If they still don't get it, you should probably fire them or transfer them to a department that isn't vulnerable.

Did they run the tests without training first? What’s the point? If Security/IT is so dense that they see any value in testing before training, we’ve already identified a problem: culture or a “our employees are too smart for this issue”.

> Did they run the tests without training first? What’s the point?

How do you know if your training is working if you have no baseline?

Re: Should Failing Phish Tests Be a Fireable Offense?

#207

Earlier quoted context omitted.

I rather like my buildings' set up for this— We have passcarded doors and then inside we have gates like many subway stations do that are timed only long enough for one person to pass through. So I can hold the door open for someone on the way in—especially if they have their badge out— but there's nothing I can do about those giant plexi gates once inside. They have to swipe.

The city of Toronto would like to hear from you. Our Subway turnstiles keep breaking. And since they’re entry and exit, there’s many methods to enter by triggering the exit side, from umbrellas to a small dog.

BART gates are entry and exit, but require card entry on both entry and exit (there are separate emergency exits which set off alarms). So it's not possible to trick them to open, though their current configuration does make it easy to jump over.

Re: Should Failing Phish Tests Be a Fireable Offense?

#208

Earlier quoted context omitted.

From this and other comments in this thread it seems you have failed these phishing tests as soon as you click a link. Is the assumption here that you are completely pwned as soon as you visit an url controlled by an attacker? I can't imagine myself compromising company data/funds via a website where I ended up through a newsletter unsubscribe link so this seems quite unfair on the part of the phish-testers.

If you think visiting a webpage in Chrome, or any other browser, even inside a VM, is totally safe, especially against a nation-state level actor, I have some bad news for you.

If you think that just clicking a link is so dangerous that it needs to be a firing offense, then you should probably lock down the computers so that the browsers cannot view anything besides approved domains.

Re: Should Failing Phish Tests Be a Fireable Offense?

#209

Earlier quoted context omitted.

From this and other comments in this thread it seems you have failed these phishing tests as soon as you click a link. Is the assumption here that you are completely pwned as soon as you visit an url controlled by an attacker? I can't imagine myself compromising company data/funds via a website where I ended up through a newsletter unsubscribe link so this seems quite unfair on the part of the phish-testers.

If you think visiting a webpage in Chrome, or any other browser, even inside a VM, is totally safe, especially against a nation-state level actor, I have some bad news for you.

If you are in a high enough position that nation states are burning zero day exploits to launch targeted attacks against you, there should probably be a security professional filtering your email. (This is also a situation where disabling Javascript would be very reasonable.)

For the remaining 99.999% of the population, I really don't think opening a web page in an up-to-date browser is cause for concern. Certainly if that browser is also in a VM. People have more pressing concerns in their lives.

Re: Should Failing Phish Tests Be a Fireable Offense?

#210
Can we fire the security people at our company who test us for phishing attacks, and then send us emails (with off-company links!) to polls, etc., that are required... and all the "security" in these emails is words like "THIS IS A REAL EMAIL FROM THE COMPANY!!!"?

Sigh...

Post reply on HN