Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

231–240 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#231

Earlier quoted context omitted.

I've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.

https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

Putting aside the fact that the conclusion of this text is not at all what GP said... You do realize that this is not a law, not even a court decision, but that it is a prosecutor's opinion / suggestion to the court??

Re: Thanks FedEx, this is why we keep getting phished

#233

Earlier quoted context omitted.

I've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.

For some things, you must use paper (or as it turns out, USB). Why the bank decided to use USB for this purpose, instead of paper, is very strange.

I'm asking for a source. You're just reformulating the statement I asking a source for.

Re: Thanks FedEx, this is why we keep getting phished

#234

I received once a mail from my bank at the time stating that they have a message for me, but for security reasons I have to read it on their systems. And they provide the following link: https://cbk.pwlnk.io/~hc The bank's name is CaixaBank. I was wrong and the message was legit. My first thought was it was a scam :)

I definitely would have called on that one and tried to avoid the whole link altogether.

Re: Thanks FedEx, this is why we keep getting phished

#235

Earlier quoted context omitted.

I've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...

Putting aside the fact that the conclusion of this text is not at all what GP said... You do realize that this is not a law, not even a court decision, but that it is a prosecutor's opinion / suggestion to the court??

Yes, if two people are going to answer with the exact same link and nothing else, I'm going to answer both with the exact same comment.

Re: Thanks FedEx, this is why we keep getting phished

#236

Canada Post actually does something good here: you can pay from the tracking page. And they don't add any fees, you just pay the duties and taxes.

> And they don't add any fees, you just pay the duties and taxes. Are you sure about this? Canada Post's webpage ( https://www.canadapost-postescanada.ca/cpc/en/support/articl... ) says: >> We apply a handling fee of CAN$9.95 per dutiable or taxable mail item.

I might misremember the last time I had to pay duties, then. Still, 10$ is much more reasonable than UPS's 70$ plus taxes!

Re: Thanks FedEx, this is why we keep getting phished

#237
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

I'd put Spectrum up against them. A few years back, an incoming neighbor typoed their address in a new account setup request to my address and Spectrum very helpfully inferred that the previous resident would want their account terminated and they turned off my service. Apparently, you can DOS any person on the planet you want from the entire Internet by simply knowing their address.

Re: Thanks FedEx, this is why we keep getting phished

#239
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

Maybe, but UPS is close to it. They for example are sending out emails that request users to log into their account to "avoid losing their profile". If this is not ripe for phishing then I don't know what will be.

Re: Thanks FedEx, this is why we keep getting phished

#240

Earlier quoted context omitted.

"The words" are probably nested templates so that at the level of input it's hard to really understand what the completed end result looks like. Also, there's many well-intentioned people in tech doing stuff that's just a tiny bit too complex for them to execute by themselves without a buddy or a reviewer. There are also whole teams and departments at big enterprises where someone might not be doing it alone, and the…

Someone, a single concrete specific individual, must actually sign off on it and/or authorize it with the SMS service provider.

Not everywhere requires bulk SMS to use an authorised template.
Post reply on HN