Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

211–220 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#211
post #206

Earlier quoted context omitted.

Did they run the tests without training first? What’s the point? If Security/IT is so dense that they see any value in testing before training, we’ve already identified a problem: culture or a “our employees are too smart for this issue”.

> Did they run the tests without training first? What’s the point? How do you know if your training is working if you have no baseline?

They said they weren’t sure if the tests were run again. I hope they were after the training for that reason.

I’m also curious about what training methods work best (including a no-training control group).

Re: Should Failing Phish Tests Be a Fireable Offense?

#212

Can we fire the security people at our company who test us for phishing attacks, and then send us emails (with off-company links!) to polls, etc., that are required... and all the "security" in these emails is words like "THIS IS A REAL EMAIL FROM THE COMPANY!!!"? Sigh...

Report all those emails as suspected phishing attempts?

Re: Should Failing Phish Tests Be a Fireable Offense?

#213

Earlier quoted context omitted.

I rather like my buildings' set up for this— We have passcarded doors and then inside we have gates like many subway stations do that are timed only long enough for one person to pass through. So I can hold the door open for someone on the way in—especially if they have their badge out— but there's nothing I can do about those giant plexi gates once inside. They have to swipe.

The city of Toronto would like to hear from you. Our Subway turnstiles keep breaking. And since they’re entry and exit, there’s many methods to enter by triggering the exit side, from umbrellas to a small dog.

Hahaha. Tell me about it. I live and work in Toronto and use Sherbourne station every day. 80% of their gates are currently under maintenance.

The gates at my work are enter/exit as well but we have to swipe out.

Re: Should Failing Phish Tests Be a Fireable Offense?

#214
post #44

Earlier quoted context omitted.

There's was the general "don't follow links in unknown emails" but nothing about what to do if you're sure it's a bad email but terminally curious. As far as I could tell nothing bad could happen (even JS was off in the browser I used to open it) when I followed the link, but is there something I should be aware of?

Worry about CSS-based exfil. https://www.mike-gualtieri.com/posts/stealing-data-with-css-... The security teams are correct in the training they run about these: report the suspicious email and leave the investigation to them, don't try to DIY the investigation. Note you aren't penalized for false positives (reporting a legitimate email as a phishing attempt).

“Note you aren't penalized for false positives....”

I spot a critical flaw in this methodology.

Re: Should Failing Phish Tests Be a Fireable Offense?

#215
post #82

Earlier quoted context omitted.

I'm sure this [reporting spam rather than unsubscribing] happens all the time but it's sort of obnoxious if the email is legit and, especially, if it's a list you requested to get put on at some point.

If you got my email address from a third party, then I do not want to be marketed to. If you got my email address because I applied for a job, then I do not want to be marketed to. If you got my email address because I signed up for a service, then I do not want to be marketed to. If you got my email address because I purchased something, then I do not want to be marketed to. If you got my email address because someo…

Your attitude doesn't account for the possibility that since you do business with somebody, you need or want to receive some of their emails.

This is the nature of any relationship. You can't be ruthless in eliminating aspects you don't like, if you don't want to end it entirely because it's net positive.

Re: Should Failing Phish Tests Be a Fireable Offense?

#216
post #172
post #25

I'm a tech professional and security is a regular part of my jobs. At one point -- while contracting for a Fortune 500 client that shall remain unnamed -- I received an email that was quite clearly phishing. Curious as to what the payload was and whether it was worth reporting, I fired up lynx and followed the link in the email from the command line. I was promptly informed that I had failed the test and I would be r…

The fact you visited the link would let them know that company x has an current employee named y. Whilst that information might not be sensitive it could be used at a later date to extract sensitive company information.

They could also look you up on LinkedIn.

There should be a line drawn between real security-conscious workplaces, and the kind of self-important chickenshit places that seem to delight in playing games and harassing their employees with this kind of thing.

Re: Should Failing Phish Tests Be a Fireable Offense?

#217
post #7

Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative consequences for employees who repeatedly fall for phishing tests usually create tension and distrust between employees and the company’s security team. This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days.…

On the other hand, all the security team needs to do is point to the number of billion-dollar breaches that have happened due to phishing. If phishing tests are a game, then so are DR tests, so are code reviews, so is the QA department. If phishing tests are a game, then so are your yearly performance reviews, or showing up to work on time, or meeting your deadlines. Not destroying the company through your own neglig…

"Not destroying the company through your own negligence should be basic standard practice. Repeatedly failing a phishing test even when given proper security education (like PhishMe provides) is negligence that can destroy an entire company."

The issue is that people are trained and required to ignore warning signs most of the time, so it is impossible to crack down too harshly.

Employees by definition do not really care about destroying the company, because they do not own it and can walk away if they like. So the company does not have unlimited leverage over them.

Re: Should Failing Phish Tests Be a Fireable Offense?

#218
post #16

Earlier quoted context omitted.

> If you're being asked for data by someone you don't know That's not how spear phishing or even phishing works. The email looks like it came from a fellow employee/boss/trusted party.

What about the sending and reply-to address? If the account is actually compromised at a system level, that is an IT issue. Again, are people so trusting that they don't check when asked for confidential data?

The address doesn't matter in some of these scams. It could be a message spoofed from your boss's real email address saying, "Hey Sam, I sent you the wrong account we need to wire money to. It's actually 123456. Can you fix that ASAP? Thanks!"

Re: Should Failing Phish Tests Be a Fireable Offense?

#219
post #34

Earlier quoted context omitted.

That's only true if you have a shitty enterprise email system. On a proper system such spear phishing attempts are blocked before reaching end users, or at least immediately obvious to anyone paying attention.

With no false negatives, right?

Right, no false negatives. It's trivial to determine whether a message purporting to come from one of your corporate domains was actually sent through an authorized internal server. Plus the IM integration in Outlook makes it super obvious which messages came from legitimate internal senders and which did not.

Re: Should Failing Phish Tests Be a Fireable Offense?

#220
post #105
post #29

Earlier quoted context omitted.

No I can't be spearphished. Prove me wrong.

Since you are making the more extraordinary claim, you need to provide evidence that your computer usage practices are 100% infallible to sophisticated attacks against you by people who know a lot about you.

No I don't have to do that. The onus isn't on me. I don't know where you came up with such a silly idea.
Post reply on HN