Earlier quoted context omitted.
Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.
It leads to less security as it is more likely that the new password will just be an old one with an incremented number at the end.
Thanks FedEx, this is why we keep getting phished
241–250 of 576 posts
Re: Thanks FedEx, this is why we keep getting phished
#242Earlier quoted context omitted.
The lack of use of a non-corp domain, the typos and the use of shortened links does sound like a form of incompetence, probably at the management layer. However, the password rotation requirement was until relatively recently something that many IT auditors would actually recommend , even though it leads directly to bad user password choices. In fact I wouldn't be at surprised to learn that was still the case in a lo…
It is. I work as an IT tech at a military defense contractor and they require regular recycling passwords, with a decent number of passwords remembered. They at least have complexity requirements applied so not 100% bad, but still archaic
Note: I only do this when I have these requirements and I can’t use a password manager.
Re: Thanks FedEx, this is why we keep getting phished
#243FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…
Re: Thanks FedEx, this is why we keep getting phished
#244A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…
Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…
Re: Thanks FedEx, this is why we keep getting phished
#245Turns out he actually was from the bank and he did cancel the loan application.
Re: Thanks FedEx, this is why we keep getting phished
#246Re: Thanks FedEx, this is why we keep getting phished
#247I contacted Wells Fargo to complain that their use of 3rd party surveys from non WellsFargo.com domains attenuates customers to entering banking information to 3rd parties. They had one incompetent employee contact me to assure me that the communication was legitimate (not the complaint), then escalated to another employee who understood the complaint and promised to escalate… 6 months later I get an email assuring m…
Re: Thanks FedEx, this is why we keep getting phished
#248Earlier quoted context omitted.
But in a modern day and age, when aren’t you expecting a package? Nearly 100% of the time, I am expecting a notification from Canada Post or Amazon (FedEx less frequently, but still). Even outside of that, you can often predict when people are expecting a package. Christmas. After various sales weeks.
> But in a modern day and age, when aren’t you expecting a package? When you’re not constantly buying things online. Most people in the world aren’t expecting packages “nearly 100% of the time”.
Do these people need to buy shit constantly? I order maybe 5 packages a year, max
Re: Thanks FedEx, this is why we keep getting phished
#249Earlier quoted context omitted.
Might be a good product to app-ify. Maybe a USB dongle that acts like a keyboard and controlled by your phone. Give it some sort of 1Password / Bitwarden integration. Could make it double as a YubiKey. Surely this exists already?
Yubikey supports this already, but without the phone part.
Re: Thanks FedEx, this is why we keep getting phished
#250DHL, FedEx, and UPS are experts in overcharging to process a form and not caring about customers. Duty and VAT are usually low compared to this processing fee, and shipping has already been paid. Here is the catch in the EU, this simple duty form can be processed by the receiver, an agent (some related to the carrier), or an attorney-in-fact of the receiver. The big three carriers (and many others) threaten you if yo…
I've often felt frustrated by the processing fees. Can you elaborate on handling this yourself? Which EU country are you based in?
In Finland you can declare DHL/UPS/Fedex packages yourself with customs and pay directly to them, with no fees to carrier (it took a Finnish Competition and Consumer Authority decision in 2017 to get rid of the fees, though). But this is a bit different as it is not a hidden option but standard procedure (though you still get the option of paying the carrier to declare, instead).
Declaring inbound packages to Customs by yourself was already the standard here for postal parcels even before Customs internet services, so this was not a completely new way of working.