Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

241–250 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#241

Earlier quoted context omitted.

Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.

It leads to less security as it is more likely that the new password will just be an old one with an incremented number at the end.

Myself and most people keep our login passwords written on paper in our desk because of this stupid practice. Can't use previous passwords and new password every 90 days. This is on top of 2FA.

Re: Thanks FedEx, this is why we keep getting phished

#242

Earlier quoted context omitted.

The lack of use of a non-corp domain, the typos and the use of shortened links does sound like a form of incompetence, probably at the management layer. However, the password rotation requirement was until relatively recently something that many IT auditors would actually recommend , even though it leads directly to bad user password choices. In fact I wouldn't be at surprised to learn that was still the case in a lo…

It is. I work as an IT tech at a military defense contractor and they require regular recycling passwords, with a decent number of passwords remembered. They at least have complexity requirements applied so not 100% bad, but still archaic

Heh. I just increased a number in my password for my passwords. Then just repeat. So “CompanyName[00]” meets almost all complexity requirements and all I have to do is increment the numbers.

Note: I only do this when I have these requirements and I can’t use a password manager.

Re: Thanks FedEx, this is why we keep getting phished

#243
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

Is it impressive though? They have about a 50% success rate delivering things to me across multiple addresses and I know other people who have had similar long term issues.

Re: Thanks FedEx, this is why we keep getting phished

#244
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

I had a similar experience at an old company that used M365. YMMV but with Bitwarden I generate passphrases like Pregnant-Guppy-Skateboard9 and it made it tons easier for me to type 20x a day than &7UoTod#$7OOD

Re: Thanks FedEx, this is why we keep getting phished

#245
A while ago my wife applied for a home equity loan. At some point I got a call from someone claiming to be from the bank she had applied through (I forget which one), calling to make sure I approved the loan since the home is in both our names. He asked for my name, which I gave him, and then the last four digits of my social security number, which I also gave him. He then proceeded to ask for my full social security number, at which point alarms started going off in my head and I started sweating about even giving the last four digits to a stranger who had called me out of the blue. I told him I wouldn't do that, and was there a number on the bank's website I could call in order to get back to him, in order to verify that he actually worked for the bank. The guy started acting really annoyed, and said he didn't think there was any number on the bank's website that could reach him, and that if I didn't give him my full social security number he would be forced to reject the loan application. I told him I didn't feel comfortable giving that information to someone who had phoned me, and if there was no way for me to call him back through an official bank phone number then the call was over. He hung up angrily.

Turns out he actually was from the bank and he did cancel the loan application.

Re: Thanks FedEx, this is why we keep getting phished

#247
post #229

I contacted Wells Fargo to complain that their use of 3rd party surveys from non WellsFargo.com domains attenuates customers to entering banking information to 3rd parties. They had one incompetent employee contact me to assure me that the communication was legitimate (not the complaint), then escalated to another employee who understood the complaint and promised to escalate… 6 months later I get an email assuring m…

Thank goodness it was legitimate.

Re: Thanks FedEx, this is why we keep getting phished

#248
post #22

Earlier quoted context omitted.

But in a modern day and age, when aren’t you expecting a package? Nearly 100% of the time, I am expecting a notification from Canada Post or Amazon (FedEx less frequently, but still). Even outside of that, you can often predict when people are expecting a package. Christmas. After various sales weeks.

> But in a modern day and age, when aren’t you expecting a package? When you’re not constantly buying things online. Most people in the world aren’t expecting packages “nearly 100% of the time”.

Yeah, I feel like I'm taking crazy pills here

Do these people need to buy shit constantly? I order maybe 5 packages a year, max

Re: Thanks FedEx, this is why we keep getting phished

#249

Earlier quoted context omitted.

Might be a good product to app-ify. Maybe a USB dongle that acts like a keyboard and controlled by your phone. Give it some sort of 1Password / Bitwarden integration. Could make it double as a YubiKey. Surely this exists already?

Yubikey supports this already, but without the phone part.

Does it require installing 3rd party software on the host machine? This might not work great for this kind of "shadow IT" application in all environments, whereas one that acts as a USB keyboard might be more versatile.

Re: Thanks FedEx, this is why we keep getting phished

#250

DHL, FedEx, and UPS are experts in overcharging to process a form and not caring about customers. Duty and VAT are usually low compared to this processing fee, and shipping has already been paid. Here is the catch in the EU, this simple duty form can be processed by the receiver, an agent (some related to the carrier), or an attorney-in-fact of the receiver. The big three carriers (and many others) threaten you if yo…

I've often felt frustrated by the processing fees. Can you elaborate on handling this yourself? Which EU country are you based in?

Does not answer your question, but related:

In Finland you can declare DHL/UPS/Fedex packages yourself with customs and pay directly to them, with no fees to carrier (it took a Finnish Competition and Consumer Authority decision in 2017 to get rid of the fees, though). But this is a bit different as it is not a hidden option but standard procedure (though you still get the option of paying the carrier to declare, instead).

Declaring inbound packages to Customs by yourself was already the standard here for postal parcels even before Customs internet services, so this was not a completely new way of working.

Post reply on HN