Or just report their mandatory compliance emails as phishing attempts. I’ve worked for multiple large companies where the annual IT security signoffs look exactly like malicious emails: weird formatting; originates from weird external url that includes suspicious words; urgent call to action; and threats of discipline for non-compliance. All this money being spent on training, only to immediately lull users into acce…
Want to piss off your IT department? Are the links not malicious looking enough?
271–280 of 335 posts
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#272Earlier quoted context omitted.
I have no official source but know that this happens a lot. Also the arguments with the employer about the letters afterwards. Some are so fed up and let you write the first or final draft. There is also the hidden code. So instead of writing something negative which is forbidden you just use different words or leave out some intensifications. Like “zur größten Zufriedenheit” vs “zur allergrößten Zufriedenheit”. One…
My question would be: why even bother with any kind of code? What incentive is there for the employer to write anything truthful, to write anything but the blandest most positive things that really don't say anything hidden?
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#273Re: Want to piss off your IT department? Are the links not malicious looking enough?
#274Earlier quoted context omitted.
It’s a trade-off. Most people are never going to check the links no matter how much you ask them to, and even if they did they wouldn’t know what to check for. But the tool Microsoft give you to check a link before opening it is that awful URL rewriter, which prevents the small minority who would check from being able to. Similarly those flashing cmd windows are usually automatic update processes that Windows has no…
I do not believe this is a trade-off, I believe this behavior from corporate IT is a primary cause of the problem. I do agree that dealing with users is awful, but that doesn't justify solutions that only make things worse. The flashing cmd.exe windows are not drivers from Windows Update - this could have been the case as drivers shipped with Windows Update is a total security nightmare running arbitrary code with ad…
My current employer was somewhat recently purchased by a large, publicly-traded company and I had this installed on my work machine. Suddenly DoH was forced off by administrator policy and I had to use some specific internal IP for DNS. Which isn't strictly less secure but let's just say I would, even for my large, publicly-traded business, trust Mullvad more than Cisco.
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#275Re: Want to piss off your IT department? Are the links not malicious looking enough?
#276Earlier quoted context omitted.
See https://xkcd.com/936/
Why would you want to memorise a password? That's what password managers or even paper is for. (Writing your passwords down on paper is actually less crazy than it sounds like: It's impossible to hack paper from the internet. And, if someone has physical access to your stuff, they could install a keylogger anyway.)
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#277Earlier quoted context omitted.
> heard IT pays a lot with not much work I want to live in this fantasy world! (Our IT dept is so overworked that I go out of my way to work around them purely out of empathy.)
Every industry has its bad employers and good. I know teachers that make $50k and no pension, with others making $93k, halfways to their pension at 35yrs old, get almost 12 weeks off total a year, and work from 8am to 3pm (1 hour lunch, 1 hour for 'prep' aka Netflix) and home by 335, and no, they basically never do any work at home. She technically has students (10 year olds she sends links to for their chrome books)…
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#278Earlier quoted context omitted.
See https://xkcd.com/936/
Why would you want to memorise a password? That's what password managers or even paper is for. (Writing your passwords down on paper is actually less crazy than it sounds like: It's impossible to hack paper from the internet. And, if someone has physical access to your stuff, they could install a keylogger anyway.)
But at least the answer doesn't match the question.
I've also learned to store the question, as some websites make you select the question before providing the answer. And my answers don't allude to what the original question was.
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#279I registered the "very-secure-no-viruses.email" domain to use for burner emails. I was trying to make one that sounded maximally sketchy. It has lead to some confusing interactions with support though...
I have firstname@lastname.email... people keep telling me that can't be right and don't i mean it ends with email.com?
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#280Or just report their mandatory compliance emails as phishing attempts. I’ve worked for multiple large companies where the annual IT security signoffs look exactly like malicious emails: weird formatting; originates from weird external url that includes suspicious words; urgent call to action; and threats of discipline for non-compliance. All this money being spent on training, only to immediately lull users into acce…
I ended up creating my own browser extension for gmail that blocks clicking on any link unless the domain is whitelisted. Now if I click any link and it's not in the whitelist, it shows a popup that displays the domain name, and I can then choose to whitelist it and then it opens the link, or just keep blocking it. I haven't had to re-take any phishing compliance tests in a long time.