Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

201–210 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#201

Earlier quoted context omitted.

NIST, whose guidelines, somehow, even other federal departments and agencies usually don’t follow. NIST has very good password complexity and management guidelines. Just USE THEM! It’s not that hard! How do you have billion dollar companies that can’t RTFM.

NIST whose guidelines are admissible in court and a competent judge will take over expert testimony. (an expert witness who says something that contradicts these guidelines is guilty of perjury, though good luck persecuting that)

Are there any examples of the former that you know of? Or is this just optimism?

Re: Thanks FedEx, this is why we keep getting phished

#202
I just got a letter from the insurance agent that I thought was going to say "THIS IS NOT A BILL" but it was a cancellation notice for my homeowner's policy. The letter was designed to be as difficult to read as possible, about 97% of the space was form letter elements that weren't relevant, in the middle of page 2 there was an area covered with large black underlines that had the reason for the cancellation typed lightly in it.

It is probably time to look for a new insurance provider but I was thinking of calling back the insurance agent and telling her I was planning to run for state senate on a platform of reforming the insurance laws and legislating that you can get 20 years in prison for sending a letter that says "THIS IS NOT A BILL" and that insurance paperwork has to be written in English excerpting any words that are shared with Latin or French. (Which I'm sure the French would approve of)

Re: Thanks FedEx, this is why we keep getting phished

#203
post #200

Earlier quoted context omitted.

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

> have to type 10-20 per day Same problem here. My solution: Get a mouse with internal memory for macros, such as Natec Genesis GX78 (old, no longer available, but this is an example). Program your new password on one of the unused mouse buttons or in a different profile. Use the mouse to type the password.

Might be a good product to app-ify. Maybe a USB dongle that acts like a keyboard and controlled by your phone. Give it some sort of 1Password / Bitwarden integration.

Could make it double as a YubiKey.

Surely this exists already?

Re: Thanks FedEx, this is why we keep getting phished

#204

I know this comes down to institutional incompetency, but at some point there was a singular human person putting the template content the SMS message in question was generated from into some computer system somewhere and I genuinely wonder what was going on in their head that made them string the words together in this way. You'd have to give it a true, earnest shot to make it worse.

"The words" are probably nested templates so that at the level of input it's hard to really understand what the completed end result looks like. Also, there's many well-intentioned people in tech doing stuff that's just a tiny bit too complex for them to execute by themselves without a buddy or a reviewer. There are also whole teams and departments at big enterprises where someone might not be doing it alone, and the…

Someone, a single concrete specific individual, must actually sign off on it and/or authorize it with the SMS service provider.

Re: Thanks FedEx, this is why we keep getting phished

#205
post #193

Earlier quoted context omitted.

NIST whose guidelines are admissible in court and a competent judge will take over expert testimony. (an expert witness who says something that contradicts these guidelines is guilty of perjury, though good luck persecuting that)

Perjury is lying under oath, not disagreeing with government guidelines.

On one hand, I agree that just disagreeing with a guideline isn’t perjury. Especially in a case like this where lots of the industry still uses the old (bad, imo) plan.

On the other, an expert witness has specifically represented themselves to be an expert. Is there any level of incompetence that raises to the level of perjury in that case? IMO there ought to be.

Re: Thanks FedEx, this is why we keep getting phished

#206
post #89

Earlier quoted context omitted.

Healthcare companies in the US send the most scammy looking links for payment processing you’ve ever seen - things like my-healthcare-billing.net It’s insane.

Yeah I got a text from one of these a couple years ago. Something like. “You have an overdue doctor bill of $183.56, please kindly pay immediately at this link: http://my-doctorpay.net/defintelylegit123 . Thx!” Didn’t even include the name of the doctor or office, but after calling the only doctors office I had used recently it was apparently legit. I let them know whatever company handles their billing is completely…

The US healthcare billing model’s total lack of authentication and disconnection from point of service means that it’s broadly plausible you do owe some random provider money at any time up to several years after your last doctor visit.

Send someone an official looking piece of paper telling them they received $394 worth of in office medical laboratory service from Tristate Medical Partners Inc in August last year, that insurance paid $374 and that they just owe you a $20 copay, and I think a lot of people will just go to the online bill pay site and hand over the money.

Re: Thanks FedEx, this is why we keep getting phished

#207

Is it common for people to have to pay previously unknown charges to get their packages delivered? I don’t frequently make international orders, but have a few times, and have never seen this. Everything has always been charged up front.

https://en.wikipedia.org/wiki/Cash_on_delivery

There are also import duties in some places like the US that can be a surprise if you don't know where the seller is or how they're shipping: https://en.wikipedia.org/wiki/Customs_duties_in_the_United_S...

I forget the name, but the USPS has a special service shippers at companies like Aliexpress often use to avoid stuff like this when shipping to the US.

Re: Thanks FedEx, this is why we keep getting phished

#208
post #6

Earlier quoted context omitted.

Any time the law sets things like "reasonable" it's a quagmire. For every utterance of "reasonable" in law you can be sure over $1B of laywer fees have been (or will be) spent.

You can spend as much as lawyer money as you want on arguing whatever nonsense you want, reasonableness is a common standard so sure, people will have spent lots of money pointlessly arguing about it but that's not a problem with reasonableness.

Sometimes the arguers win and set a new precedent... so it definitely creates a new problem with everyone who subsequently encounters the issue.

Re: Thanks FedEx, this is why we keep getting phished

#209

Earlier quoted context omitted.

[flagged]

often, chatgpt translates better.

That, and you can ask it to translate literally or colloquially, to summarize or explain about acronyms, cultural references, names, code, syntax, diagrams, graphics, or anything else.

GP: If you're going to play a curmudgeon, at least get some first hand experience with what you choose to complain about, otherwise your curmudgeoning isn't very effective, and you complain about things that aren't actually problems, and miss out on complaining about real problems.

I love to hate and complain about Unix and X-Windows and C++ and GCS, but that's because I've used them, not because I succeeded in avoiding them.

Re: Thanks FedEx, this is why we keep getting phished

#210
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

On our company (hosting & PaaS), I was contacted on our internal messenger by a person I've never seen before, asking me to "please" run some commands as root and send back the results. After the initial shock (and due infosec diligence) I found out it was just "the new guy", needing to collect info about our systems for equipment inventory purposes. Since they didn't have access to our networked management tool yet,…

I flip tables when people make offhand requests like this. Infra teams are not keyboard monkeys with admin creds.
Post reply on HN