Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

211–220 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#211
post #117

Earlier quoted context omitted.

It's the electronic version of a safe deposit box

I can understand that marketing message making sense and appealing to.. some people; I am surprised to see it on HN though. This is like buying vegetable & olive oils from BP or Shell because they're oil experts looking for new income streams as we shift away from petroleum.

When shit hits the fan the bank will be like: "The storage was actually a service we nearshored to Romania and Belarus. Part of your stuff is lost, part of it had leaked. We can offer insurance lump sum of €3.64 for your loss. You consented to all the risks on the page 475 of T&C which we sent by post".

Re: Thanks FedEx, this is why we keep getting phished

#212

Earlier quoted context omitted.

Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.

In combination with forced changes, it leads to… Password1 Password2 Password3 Etc

ITYM

hunter3

hunter4

hunter5

Re: Thanks FedEx, this is why we keep getting phished

#213
post #200

Earlier quoted context omitted.

> have to type 10-20 per day Same problem here. My solution: Get a mouse with internal memory for macros, such as Natec Genesis GX78 (old, no longer available, but this is an example). Program your new password on one of the unused mouse buttons or in a different profile. Use the mouse to type the password.

Might be a good product to app-ify. Maybe a USB dongle that acts like a keyboard and controlled by your phone. Give it some sort of 1Password / Bitwarden integration. Could make it double as a YubiKey. Surely this exists already?

Yubikey supports this already, but without the phone part.

Re: Thanks FedEx, this is why we keep getting phished

#214
post #186

Earlier quoted context omitted.

In combination with forced changes, it leads to… Password1 Password2 Password3 Etc

The one I see that stays updatable is: PasswordFebruary2024! Where month and year update on the date of forced password change.

Oh, that's a good one.

Re: Thanks FedEx, this is why we keep getting phished

#215
St Louis county just did some of this for their property declaration system. It used to set right there in the website: An ugly set of forms, but perfectly functional. Apparently they ordered a rewrite to yet another contractor, and now you get a link to.. stlouismosmartfile.tylerhost.net. Following the link, from the county's own website, warns of a third party link! The link prompts the user to register... and the validation email, unsurprisingly, is sent to spam, and then flagged as risky by gmail! Enough red flags, you'd think it's an old soviet military parade, but no... when you call the county, they say that yes, this isn't them getting hacked (again), but the way things are supposed to be.

This is something everyone that owns any property and is a resident of the county must fill out: About half a million accounts will be created in two weeks. Making sure that all of this comes from the county's domain? Too difficult for them. And all for a website on the other side that doesn't look much better than the old one.

Re: Thanks FedEx, this is why we keep getting phished

#216
post #147

Earlier quoted context omitted.

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

I forget who puts that stuff out NIST/STIG(?) but IIRC in the recent few years they determined that rotating passwords like that was basically security theater and wasn't worth the damage to the staffs productivity

They decided it was useless security theater decades ago. What happened recently is that they discovered that they rule they used to actively push causes severe harm to security.

Now there's a positive rule about not doing it.

Re: Thanks FedEx, this is why we keep getting phished

#217
post #114

Earlier quoted context omitted.

[flagged]

I've seen ChatGPT translate English to German miles ahead of what Google translate does. Like an English satirical poem to perfect German. Changing the literal translation to keep the meaning and sarcasm of the poem.

I've had it translate back and forth and write songs in Simlish! It even knows and is fluent in fake nonsensical languages.

https://en.wikipedia.org/wiki/Simlish

https://news.ycombinator.com/item?id=35539207

Prompt: Write an a cappella cover of a Philip Glass song in Simlish.

ChatGPT-4:

Creating an a cappella cover of a Philip Glass song in Simlish presents an interesting challenge. Philip Glass is known for his minimalist compositions that often consist of repetitive structures, and Simlish is a nonsensical language. Since Glass's compositions are largely instrumental, I will create an a cappella adaptation inspired by his musical style while using Simlish-like sounds.

    Verse 1:

    Doo doo zib, doo doo zib, doo doo zib, doo doo zib,
    Bada bada zoob, bada bada zoob, bada bada zoob, bada bada zoob,
    Glarbni glarbni glarb, glarbni glarbni glarb, glarbni glarbni glarb, glarbni glarbni glarb,
    Sul sul sul, sul sul sul, sul sul sul, sul sul sul.

    Chorus:

    Froodle froodle, zibba zibba,
    Dag dag, drib drib, yibbs yibbs,
    Slooble slooble, wib wib, dor dor,
    Lerpna lerpna, gort gort, zor zor.

    Verse 2:

    Doo doo zib, doo doo zib, doo doo zib, doo doo zib,
    Bada bada zoob, bada bada zoob, bada bada zoob, bada bada zoob,
    Glarbni glarbni glarb, glarbni glarbni glarb, glarbni glarbni glarb, glarbni glarbni glarb,
    Sul sul sul, sul sul sul, sul sul sul, sul sul sul.

    Chorus:

    Froodle froodle, zibba zibba,
    Dag dag, drib drib, yibbs yibbs,
    Slooble slooble, wib wib, dor dor,
    Lerpna lerpna, gort gort, zor zor.
Remember, this adaptation is meant to be playful and fun, as it doesn't have any real meaning or convey any specific message. The focus here is on capturing the essence of Philip Glass's minimalist compositions using Simlish-like sounds in an a cappella context.

Re: Thanks FedEx, this is why we keep getting phished

#218
post #200

Earlier quoted context omitted.

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

> have to type 10-20 per day Same problem here. My solution: Get a mouse with internal memory for macros, such as Natec Genesis GX78 (old, no longer available, but this is an example). Program your new password on one of the unused mouse buttons or in a different profile. Use the mouse to type the password.

Yubikeys can do this.

Re: Thanks FedEx, this is why we keep getting phished

#219
FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed:

1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the same.

2. When I moved out of that building I wanted to add my new address to delivery manager … but I couldn’t. The site errored every time. The reason? Some forums revealed the correct hypothesis that if you have special characters in your password then some parts of the site are permanently broken for you. Including the change password flow. So I had to have my wife make a new account with a worse password.

Truly amateur stuff for an otherwise very impressive company.

Re: Thanks FedEx, this is why we keep getting phished

#220
post #89

Earlier quoted context omitted.

Healthcare companies in the US send the most scammy looking links for payment processing you’ve ever seen - things like my-healthcare-billing.net It’s insane.

Lets not forget all the typosquatting looking domains Microsoft uses. It almost seems like they bought them up to protect users, forgot why they did that and said "hey we have all these domains, lets use those?"

Do you have any examples? I'm largely out of the Microsoft ecosystem these days, aside from the occasional Xbox usage.
Post reply on HN