Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

251–260 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#251
post #200

Earlier quoted context omitted.

Have you ever worked for a big company? (Think several US offices, half a dozen European and Asian offices, 500m in revenue). Someone forwards me an e-mail from our Dutch office that says, essentially, "The world is burning down, we are boarding a plane in a couple of hours to go to IFA (show), and we don't have the latest copy of product X to demo for customers." I do builds by hand of this product because I can't g…

> I'm the only person in the entire world with the encryption keys to provision the product The chaos that surrounds you, the facts that astound you, at last your number has found you, your bus number is one.

Googling this quote reveals nothing. Is it a quote? Or are you HN's resident poet? :)

Re: Should Failing Phish Tests Be a Fireable Offense?

#252

In my office we can get into trouble for this. However, they always send a magic header in the email to get through the firewall. My solution: filter out emails with the header.

What if a spearphisher is watching out for the test emails on one account and we lose the magic headers that bypass the firewall? What then???

I don't disagree. But that's not my department and I'm not high enough up the chain for my opinion to matter.

Re: Should Failing Phish Tests Be a Fireable Offense?

#253
post #233

Earlier quoted context omitted.

I rather like my buildings' set up for this— We have passcarded doors and then inside we have gates like many subway stations do that are timed only long enough for one person to pass through. So I can hold the door open for someone on the way in—especially if they have their badge out— but there's nothing I can do about those giant plexi gates once inside. They have to swipe.

It might be easier to try detection (and embarrassing alarms) instead of physical prevention. For example, floor sensors could detect when multiple sets of feet are enter on the same activation. Granted, they might not know the difference between one person and a handcart versus two people where one is in a wheelchair, but I doubt many would-be infiltrators would draw attention to themselves that way.

I know for a fact that people will ignore it and set off the alarm anyway even with a large sign covering the entire top half of the door. Then the alarm goes off so often that all the bystanders ignore it too, so there really is no point.

Re: Should Failing Phish Tests Be a Fireable Offense?

#254

Earlier quoted context omitted.

Have you ever worked for a big company? (Think several US offices, half a dozen European and Asian offices, 500m in revenue). Someone forwards me an e-mail from our Dutch office that says, essentially, "The world is burning down, we are boarding a plane in a couple of hours to go to IFA (show), and we don't have the latest copy of product X to demo for customers." I do builds by hand of this product because I can't g…

Maybe that's how it is at your big organization. I'm sure glad my big organization is different.

I suspect the world runs on more chaos than anyone would like to believe.

But when your big org is hiring, let me know :)

Re: Should Failing Phish Tests Be a Fireable Offense?

#255
post #58

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…

You can wave any object at the sensor. Maybe an unauthorized tag will yield a different beep or make the light flash a different color. Maybe the person in front of you will be in a position to see the light on the reader, maybe they'll notice, and maybe they'll consider it odd. Getting that far, and then actually deciding to challenge you or report it, is a vanishingly small chance.

There is no point in badging an unlocked door, or in expecting people to do so. You have to actually close it between entries. This is a physically and socially ridiculous thing to do with traditional doors; if it's what you want, you need a turnstile.

Re: Should Failing Phish Tests Be a Fireable Offense?

#256
post #196

Earlier quoted context omitted.

The city of Toronto would like to hear from you. Our Subway turnstiles keep breaking. And since they’re entry and exit, there’s many methods to enter by triggering the exit side, from umbrellas to a small dog.

The City does not want to be sued by the estate of someone cut in half by a turnstile gate. This limits the available force and material strength. The specifications for those gates almost certainly include a requirement that they allow a sufficiently determined person through without breaking themselves, and probably sound an audible alert.

True for turnstiles that open and close. New York's full-height subway gates are just metal revolving doors that only revolve enough for one person per card.

Re: Should Failing Phish Tests Be a Fireable Offense?

#257

Earlier quoted context omitted.

It's not about being punished for being physically overpowered - it's about being a five foot 3 intern and having someone 6'1 250 lbs, in a suit and in a hurry, behind you, tailgating. The implications are enough to make it a shitty situation for such a person have to turn around and say "sorry person that looks c-suite, you can't come in with me."

If the company handles this correctly, the intern should feel empowered to tell the CEO to get a visitor badge. It’s also a safety issue. In a building evacuation, you should be able to account for every employee or visitor.

Most sites control entry, not exit, so wouldn't be able to tell whether you had already left.

Re: Should Failing Phish Tests Be a Fireable Offense?

#258
post #7

Rohyt Belani, CEO of Leesburg, Va.-based security firm Cofense (formerly PhishMe), said anti-phishing education campaigns that employ strongly negative consequences for employees who repeatedly fall for phishing tests usually create tension and distrust between employees and the company’s security team. This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days.…

90 days? Our security team forces us to change every personal password every month!

Point them to NIST's new guidance on mandatory password changes.

Re: Should Failing Phish Tests Be a Fireable Offense?

#259
post #173
post #134

Earlier quoted context omitted.

That's the point. I was in the infantry, am 6'2, and a guy. I don't have a problem with challenging folks who are tailgating. That is not the case for everyone. Do you expect disabled folks to challenge tailgaters? What about physically small people? Setting aside the office dynamics around discrimination issues, how many people actually have the confidence to challenge an unknown person who is tailgating, knowing th…

You politely say swipe your badge. If they refuse you walk over and get physical security. No need to physically challenge anyone.

Swiping on an already-unlocked door is meaningless.

Re: Should Failing Phish Tests Be a Fireable Offense?

#260

Earlier quoted context omitted.

We expect tiny people making minimum wage to ask thieves to pay for the cheese they’re shoplifting. This seems pretty minor by comparison. I wouldn’t expect any physical force to be used. If asking politely doesn’t work, call security. If they threaten you into letting them in, comply, then call security.

> We expect tiny people making minimum wage to ask thieves to pay for the cheese they’re shoplifting. We don't actually. All sane employers have them record and report the incident and not engage , because petty shoplifting isn't worth somebody getting shot and it's built into the margins anyway. If the store is big enough, they may have "loss prevention", who are people who are very much not tiny and will verbally e…

I’ve heard of policies that cashiers are not to chase, let alone fight, but never that they’re not even supposed to ask someone to pay. Is that really true?
Post reply on HN