Earlier quoted context omitted.
In Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.
Are you sure? Never seen any such thing.
Want to piss off your IT department? Are the links not malicious looking enough?
201–210 of 335 posts
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#202Earlier quoted context omitted.
In Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.
I find this hard to believe and have never seen that ever.
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#203Earlier quoted context omitted.
PSD2 is just MFA, it doesn't prevent shady companies still asking your login credentials, even if you must authorize that login from your official banking app. Klarna is one of many examples - they ask me for my bank credentials on their own website so they can crawl all my finance data .
Plaid and Finicity do this in the USA for some linking of banking to other financial products. Feels SO insecure. Connecting my credit union checking account through Plaid even ironically brought me to a login page which explicitly states I should never give my banking password to any other entity. If I need to link my accounts and these services are the only choice then I change my banking passwords immediately afte…
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#204Earlier quoted context omitted.
I have firstname@lastname.email... people keep telling me that can't be right and don't i mean it ends with email.com?
I have a .ninja email and get the same a lot to the extend where I explicitly say "it ends in .ninja with no .com or anything". Usually use company-i-buy-from@mydomain.ninja whenever I make online purchases, and I had a guy from a small shop call me up and ask why I had an email with his company name on. Took some good fifteen minutes to explain him that I was legit and owned the domain. He was still reluctant in the…
That said I've caught and blacklisted quite a few bad actors this way, AND filtering is easier. So worth the occasional weird interaction.
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#205Earlier quoted context omitted.
Not going to lie, I was expecting this[1]. Maybe it's just not done on HN. 1: https://pc-helper.xyz/scanner-snatcher/session-snatcher/cred...
You innocent young being. There are some gaping holes in your Internet lore knowledge, but it's been eons since that's been seen in the wild.
I didn't have the guts to tell my family about goatse.
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#206Re: Want to piss off your IT department? Are the links not malicious looking enough?
#207Earlier quoted context omitted.
In Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.
I find this hard to believe and have never seen that ever.
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#208Earlier quoted context omitted.
All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com
Outlook has a rule filter for header content. Just saying I haven't failed a phishing test in ~10 years.
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#209Earlier quoted context omitted.
Care to mention what these legitimate and established services are?
Plaid is used by a lot of the major Canadian banks.
"Connecting" savings accounts from EQ Bank or Wealthsimple to an account at TD Bank requires providing TD credentials to Flinks.
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#210Earlier quoted context omitted.
I had the opposite funny experience. When I worked for Global MegaCorp, they would occasionally send out phishing emails and if you clicked on a link it would be recorded and you would have to do trainings if you got fooled a couple times. Eventually everyone learned to stop clicking on links on emails. That's good. However, they sent out a yearly survey to get feedback from all the employees and no one clicked the l…
noted for my phishing business: track first phishing attempt, send follow up email two days later saying the first one was legit.