Live data from Hacker News

Want to piss off your IT department? Are the links not malicious looking enough?

phishyurl.com

211–220 of 335 posts

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#211
post #189

Earlier quoted context omitted.

Plaid and Finicity do this in the USA for some linking of banking to other financial products. Feels SO insecure. Connecting my credit union checking account through Plaid even ironically brought me to a login page which explicitly states I should never give my banking password to any other entity. If I need to link my accounts and these services are the only choice then I change my banking passwords immediately afte…

I thought Plaid used OAuth2. Hmm.

Plaid asks for your raw bank credentials so that it can scrape up data. That's why I've always refused to use it.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#212

Earlier quoted context omitted.

In Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.

Care to mention what these legitimate and established services are?

Sofort used to do this. I don't know if they still do.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#213
post #45

I registered the "very-secure-no-viruses.email" domain to use for burner emails. I was trying to make one that sounded maximally sketchy. It has lead to some confusing interactions with support though...

I have firstname@lastname.email... people keep telling me that can't be right and don't i mean it ends with email.com?

Oh, you must mean firstnamelastname@gmail.com.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#214
post #196

No need, my IT already do this by running the MimeCast email filter [1]. Links to non-whitelist sites are expressed in the format: https://url.uk.m.mimecastprotect.com/s/ ?domain= Maybe I can tell the link is from Google, but not what is likely to be in the URL. It's a complete surprise as to whether I will be looking at a web page or downloading something. [1] https://www.mimecast.com/

My favorite part of mimecast is that their servers apparently can't handle normal volume and regularly time out before redirecting to the destination URL.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#215
post #189

Earlier quoted context omitted.

Plaid and Finicity do this in the USA for some linking of banking to other financial products. Feels SO insecure. Connecting my credit union checking account through Plaid even ironically brought me to a login page which explicitly states I should never give my banking password to any other entity. If I need to link my accounts and these services are the only choice then I change my banking passwords immediately afte…

I thought Plaid used OAuth2. Hmm.

Plaid whole business model is that it uses OAuth2 on banks that support it and export the data through APIs; and for the banks that don't, they ask for name/password and scrape it through "fake" web browser that mimick user behavior on the backend.

(I worked for a Plaid competitor. The long-term goal for all similar companies is of course to use OAuth and APIs, because it breaks less often; but since the banks don't offer that, scraping it is!)

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#216
post #70
post #60

Earlier quoted context omitted.

> Except that the spam system they use completely mangles the URL... I hate this trend. Like an overused pool of the same "Secret Questions" every company asks, it needs to be on some "X considered harmful" list.

I usually just ask my password generator to generate another random password for the secret question's answer.

I usually just ask my password generator to generate another random password for the secret question's answer.

Not great when you're on the phone with United Airlines and the person who's trying to help you get un-stranded asks what your favorite ice cream flavor is.

United has the absolute stupidest secret questions.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#217

Around 2001 I worked for one of the big dot com news outlets. In our reception we had a PC with a browser set up where people could "use the internet" while they waited. One day the receptionist asked me to fix the PC as it wasn't connected to the internet and no one from IT was available. So I messed around a bit (think in the end I just reset the DCHP lease) and to test I opened the browser to surf the net. Of cour…

I remember typing whitehouse.com (hoping that was safe) in the early days of Internet... nope, it was not the same as whitehouse.gov!

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#218
post #196

No need, my IT already do this by running the MimeCast email filter [1]. Links to non-whitelist sites are expressed in the format: https://url.uk.m.mimecastprotect.com/s/ ?domain= Maybe I can tell the link is from Google, but not what is likely to be in the URL. It's a complete surprise as to whether I will be looking at a web page or downloading something. [1] https://www.mimecast.com/

My favorite part of mimecast is that their servers apparently can't handle normal volume and regularly time out before redirecting to the destination URL.

That's a feature, not a bug. If the user can't load the redirection, they can't get phished! Problem solved.

If anyone complains, refer them to the security department to be audited. It's really rather suspicious when someone values doing their job above security.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#219

Earlier quoted context omitted.

I thought Plaid used OAuth2. Hmm.

Plaid whole business model is that it uses OAuth2 on banks that support it and export the data through APIs; and for the banks that don't, they ask for name/password and scrape it through "fake" web browser that mimick user behavior on the backend. (I worked for a Plaid competitor. The long-term goal for all similar companies is of course to use OAuth and APIs, because it breaks less often; but since the banks don't…

MX?

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#220
post #167
post #159

Earlier quoted context omitted.

There's no legitimate case for that since PSD2 (mandatory since 2020). Are you not confused by that? PSD2 doesn't share your credentials. I'm an European and have never needed to use nor encountered those services.

PSD2 is just MFA, it doesn't prevent shady companies still asking your login credentials, even if you must authorize that login from your official banking app. Klarna is one of many examples - they ask me for my bank credentials on their own website so they can crawl all my finance data .

I have a Klarna account I opened when their flex account rate was amongst the best you could get and I don't remember them ever asking for my bank credential.

I think Bankin' used to before PSD2 and to get a bit more information from some banks but then again Bankin' is a financial agreggator whose explicit purpose is crawling your banking data so it's not too surprising to see them asking for your credentials.

Post reply on HN