Live data from Hacker News

Want to piss off your IT department? Are the links not malicious looking enough?

phishyurl.com

201–210 of 335 posts

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#201

Earlier quoted context omitted.

In Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.

Are you sure? Never seen any such thing.

It used to be common before PSD2 but I have personally not seen it for some years.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#202

Earlier quoted context omitted.

In Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.

I find this hard to believe and have never seen that ever.

It used to be common 5 years ago before PSD2.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#203
post #189
post #167

Earlier quoted context omitted.

PSD2 is just MFA, it doesn't prevent shady companies still asking your login credentials, even if you must authorize that login from your official banking app. Klarna is one of many examples - they ask me for my bank credentials on their own website so they can crawl all my finance data .

Plaid and Finicity do this in the USA for some linking of banking to other financial products. Feels SO insecure. Connecting my credit union checking account through Plaid even ironically brought me to a login page which explicitly states I should never give my banking password to any other entity. If I need to link my accounts and these services are the only choice then I change my banking passwords immediately afte…

I thought Plaid used OAuth2. Hmm.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#204

Earlier quoted context omitted.

I have firstname@lastname.email... people keep telling me that can't be right and don't i mean it ends with email.com?

I have a .ninja email and get the same a lot to the extend where I explicitly say "it ends in .ninja with no .com or anything". Usually use company-i-buy-from@mydomain.ninja whenever I make online purchases, and I had a guy from a small shop call me up and ask why I had an email with his company name on. Took some good fifteen minutes to explain him that I was legit and owned the domain. He was still reluctant in the…

Ha! Exactly this happens to me too. Had to return some electronics in person, the guy suddenly started fishing if I was some mystery shopper or QC person... because the invoice was made out to their.store@myname.email

That said I've caught and blacklisted quite a few bad actors this way, AND filtering is easier. So worth the occasional weird interaction.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#205
post #64

Earlier quoted context omitted.

Not going to lie, I was expecting this[1]. Maybe it's just not done on HN. 1: https://pc-helper.xyz/scanner-snatcher/session-snatcher/cred...

You innocent young being. There are some gaping holes in your Internet lore knowledge, but it's been eons since that's been seen in the wild.

This recently came up in a conversation with family, and my nephew of 17 years old knew about it, and said it still exists. Personally I haven't seen it in a long time.

I didn't have the guts to tell my family about goatse.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#206
post #201

Earlier quoted context omitted.

Are you sure? Never seen any such thing.

It used to be common before PSD2 but I have personally not seen it for some years.

It seems mainly localized to Germany

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#207

Earlier quoted context omitted.

In Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.

I find this hard to believe and have never seen that ever.

Don't understand the downvotes, i never saw that too, and i am shopping online very often.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#208
post #184

Earlier quoted context omitted.

All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com

Outlook has a rule filter for header content. Just saying I haven't failed a phishing test in ~10 years.

Mind sharing your filter rules? KnowBe4 uses X-PHISHTEST header and I think I saw Proofpoint using something similiar a few years back

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#209

Earlier quoted context omitted.

Care to mention what these legitimate and established services are?

Plaid is used by a lot of the major Canadian banks.

Flinks is also an often-used aggregator in Canada.

"Connecting" savings accounts from EQ Bank or Wealthsimple to an account at TD Bank requires providing TD credentials to Flinks.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#210

Earlier quoted context omitted.

I had the opposite funny experience. When I worked for Global MegaCorp, they would occasionally send out phishing emails and if you clicked on a link it would be recorded and you would have to do trainings if you got fooled a couple times. Eventually everyone learned to stop clicking on links on emails. That's good. However, they sent out a yearly survey to get feedback from all the employees and no one clicked the l…

noted for my phishing business: track first phishing attempt, send follow up email two days later saying the first one was legit.

Note, this only worked because the follow up email came from the head of the division.
Post reply on HN