Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

221–230 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#221
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

My company's security training tells me to carefully verify any URLs in received emails, but then they have some security software that rewrites all the URLs in incoming emails - presumably as a way of screening them themselves. This might be a reasonable trade-off for centralising monitoring, but it significantly hampers the ability to judge the legitimacy of emails myself. At least update your training!

Our last round of security training was roundly mocked by our software division, especially around the subject of one of the rules emphasized over and over being to "never click URLs in emails" and the sign-in process for the website alongside the distribution of lessons was done exclusively through magic links... in emails.

Our CEO is actually a developer himself on our core product (and a bit of a paranoid fella on the cybersecurity front to boot) and he was absolutely furious about this vendor being chosen...

Re: Thanks FedEx, this is why we keep getting phished

#222
post #77

Earlier quoted context omitted.

Man, this is just a marketing gimmick. I am always short in USB sticks. So, could have gotten another one.. How about a little bit more of humor?

If you give me your mailing address, I'll arrange it that the bank will mail you one, too. Just be sure to use the included NOTVIRUS.EXE viewer for best experience.

Just set it to autorun. I'm sure anybody you mail it to will just confirm running it without even looking what they are doing.

Re: Thanks FedEx, this is why we keep getting phished

#223

Earlier quoted context omitted.

Might be a good product to app-ify. Maybe a USB dongle that acts like a keyboard and controlled by your phone. Give it some sort of 1Password / Bitwarden integration. Could make it double as a YubiKey. Surely this exists already?

Yubikey supports this already, but without the phone part.

I should do this for ssh password entry. Running ssh-agent is still 90% of the story, but it comes up often enough that I'm on a terminal in a remote machine or inside a screen session or something that it would still be awfully useful to be able to just autotype it.

Re: Thanks FedEx, this is why we keep getting phished

#224
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

UPS is up there, too. I still get text messages about an old address on an account I can't log into for...reasons. (Special characters sound plausible! And of course the password reset flow doesn't work.)

Wonder if they share a vendor.

Re: Thanks FedEx, this is why we keep getting phished

#225

Is it common for people to have to pay previously unknown charges to get their packages delivered? I don’t frequently make international orders, but have a few times, and have never seen this. Everything has always been charged up front.

The EU and UK have systems to allow the tax to be paid when purchasing, for large companies that support it like Ali Express. These are fairly new.

Countries also have their own limits below which they don't bother with the taxes. There was so much abuse of this in the EU+UK the limit is now zero.

The only time it should be surprising is when the foreign website isn't paying the taxes, and it also isn't clear it's a foreign site. Generally on cheap crap from China.

Re: Thanks FedEx, this is why we keep getting phished

#226
post #200

Earlier quoted context omitted.

> have to type 10-20 per day Same problem here. My solution: Get a mouse with internal memory for macros, such as Natec Genesis GX78 (old, no longer available, but this is an example). Program your new password on one of the unused mouse buttons or in a different profile. Use the mouse to type the password.

Yubikeys can do this.

It can, and I tried this, but in practice we have to change our passwords at my current employer so frequently that I got more irked changing it on the Yubikey (not the least hassle-free of processes, as I couldn't install the Yubikey software on the work machine) than just typing the thing.

Re: Thanks FedEx, this is why we keep getting phished

#227

Earlier quoted context omitted.

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

The lack of use of a non-corp domain, the typos and the use of shortened links does sound like a form of incompetence, probably at the management layer. However, the password rotation requirement was until relatively recently something that many IT auditors would actually recommend , even though it leads directly to bad user password choices. In fact I wouldn't be at surprised to learn that was still the case in a lo…

It is. I work as an IT tech at a military defense contractor and they require regular recycling passwords, with a decent number of passwords remembered. They at least have complexity requirements applied so not 100% bad, but still archaic

Re: Thanks FedEx, this is why we keep getting phished

#228
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Banks do this as well. I made a purchase, and within minutes got a very scammy looking e-mail from them - low quality gifs, asking me to click on links to a random non-bank website(something like purchase-verification-users.net/235532/confirm.html, and the site wasn’t coming up on any searches). At the same time I get a call from a random number asking me to go over some purchases - I looked up the number, and it’s none of the ones listed for my bank.

So I hang up and call my bank directly. I spend 10 minutes going through the phone maze to talk to someone. Finally I get to them, and they confirm that is a number that they use to contact people. How come when you list numbers on your website you don’t list this one? Well, they said they often call from numbers they haven’t listed online. How about that e-mail, do you send those? Well, we sometimes contact people by e-mail, if it says it’s from us in the from: line you can click on it. Did you guys send that one? I don’t have that information; don’t click on it if the from: line isn’t us, but if it is, go ahead.

Re: Thanks FedEx, this is why we keep getting phished

#229
I contacted Wells Fargo to complain that their use of 3rd party surveys from non WellsFargo.com domains attenuates customers to entering banking information to 3rd parties.

They had one incompetent employee contact me to assure me that the communication was legitimate (not the complaint), then escalated to another employee who understood the complaint and promised to escalate… 6 months later I get an email assuring me that the communication was legitimate and closing the ticket.

Re: Thanks FedEx, this is why we keep getting phished

#230
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

I wonder if that's why I can't change my password with petco - every time I shop there they tell me I have rewards but I can't load them because the site errors out when I try to reset my password.

I used to be able to load the rewards to my account without logging in at all, just clicked the link in my email, but I guess they fixed that and then I realized I didn't know my password.

Post reply on HN