Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

281–290 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#281

Earlier quoted context omitted.

The city of Toronto would like to hear from you. Our Subway turnstiles keep breaking. And since they’re entry and exit, there’s many methods to enter by triggering the exit side, from umbrellas to a small dog.

BART gates are entry and exit, but require card entry on both entry and exit (there are separate emergency exits which set off alarms). So it's not possible to trick them to open, though their current configuration does make it easy to jump over.

I haven't been on BART in a few years, but I remember many stations having a wheelchair entrance that anyone could go through if security wasn't watching.

Re: Should Failing Phish Tests Be a Fireable Offense?

#282
post #94

Earlier quoted context omitted.

Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.

> Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? I have zero experience with this, but I imagine the policy would be "Don't enter the building if someone is too close behind you." If you don't feel comfortable asking for space (fine!), turn around, go back to your car, and call building se…

Oh that sounds like a liability nightmare if someone refuses entry to a crazy crackhead and gets stabbed for it

Re: Should Failing Phish Tests Be a Fireable Offense?

#283

Earlier quoted context omitted.

The city of Toronto would like to hear from you. Our Subway turnstiles keep breaking. And since they’re entry and exit, there’s many methods to enter by triggering the exit side, from umbrellas to a small dog.

The German U-Bahn has a brilliant solution to this. No turnstiles or gates, you're just expected to have a ticket. The penalty for getting caught without a ticket is considered sufficiently high to make "Schwarzfahren" statistically more expensive.

But I don't think that will work for corporate building security, where a single attacker could cause a large amount of damage, not just losing a ticket fare.

Re: Should Failing Phish Tests Be a Fireable Offense?

#284

Earlier quoted context omitted.

The city of Toronto would like to hear from you. Our Subway turnstiles keep breaking. And since they’re entry and exit, there’s many methods to enter by triggering the exit side, from umbrellas to a small dog.

The German U-Bahn has a brilliant solution to this. No turnstiles or gates, you're just expected to have a ticket. The penalty for getting caught without a ticket is considered sufficiently high to make "Schwarzfahren" statistically more expensive.

Same with Muni and Caltrain in the San Francisco area.

Re: Should Failing Phish Tests Be a Fireable Offense?

#285

Earlier quoted context omitted.

Swiping on an already-unlocked door is meaningless.

If there is a response at the terminal which makes it obvious that the pass is valid, and the action is also logged, I would say it has meaning.

The only response that’s reliable across doors, sites, and institutions is the door actually unlocking, which you may or may not be able to discern when already opened. Do you know the beep and light pattern by heart for valid credential vs. recognized but unauthorized credential vs. bus pass at every door you use? Each one in my office is a bit different, my apartment is something else entirely, in college they were uniform within buildings but different across buildings.

Electric mortise locks and strikes will click, though sometimes they are held in unlocked state for a few seconds so you won’t hear a second click, or the second click might be reverting to locked state. Depends on hardware and configuration, and maybe a what the person in front is doing with the handle, and when/whether the exit sensor trips. Different things on the door can make clicking sounds, they’re a bit different from each other, but pretty close. Magnetic locks, forget it. Sliding doors, forget it.

I’m an engineer interested in security, I pay close attention to these systems, I’ve run their cabling and installed their admin panels, and I doubt I could tell even if I were actively paying attention.

Re: Should Failing Phish Tests Be a Fireable Offense?

#286

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

It is absolutely unreasonable to get fired by putting your life in danger to stop trailgaters. There are essentially three types of tailgaters, people who belong there, tourists, and nefarious across. People who belong there are just getting lazy, but it is OK. Tourists you can stop (these are people who might be guests, or are just curious) but these people aren't bad people, and most lonely wing do any harm. Then there are the nefarioys types, the criminals... The ones who are there for a bad reason, and I'm supposed to stop them?

Re: Should Failing Phish Tests Be a Fireable Offense?

#287
post #58

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…

If you don't want tailgaters then hire bouncer security types to stop people. It isn't my job to put my life on the line.

Re: Should Failing Phish Tests Be a Fireable Offense?

#288

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

It is absolutely unreasonable to get fired by putting your life in danger to stop trailgaters. There are essentially three types of tailgaters, people who belong there, tourists, and nefarious across. People who belong there are just getting lazy, but it is OK. Tourists you can stop (these are people who might be guests, or are just curious) but these people aren't bad people, and most lonely wing do any harm. Then t…

>The ones who are there for a bad reason, and I'm supposed to stop them?

You can contact security, presumably a company with such a policy has 24/7 on site security.

Re: Should Failing Phish Tests Be a Fireable Offense?

#289
post #134

Earlier quoted context omitted.

That's the point. I was in the infantry, am 6'2, and a guy. I don't have a problem with challenging folks who are tailgating. That is not the case for everyone. Do you expect disabled folks to challenge tailgaters? What about physically small people? Setting aside the office dynamics around discrimination issues, how many people actually have the confidence to challenge an unknown person who is tailgating, knowing th…

You are getting really hung up on a very tiny edge case. No reasonable manager would punish you for being physically overpowered. That doesn't mean you should encourage people to ignore the security policy. 99.99% of the time, saying to the tailgater "you need to swipe" is enough. If you do work somewhere where people are physically trying to break in often, then you ought to have real security personnel.

Then why bother? If most of the time, asking is enough, then why bother at all? Because occasionally a bad actor wants in, I don't want to have to confront a bad actor.

Re: Should Failing Phish Tests Be a Fireable Offense?

#290

I worked for a defense contractor that had a 3 strikes policy for security violations. Failing the phishing emails was a strike. Other breaches of security policy (like getting caught letting someone tailgate you in) could be strikes too. You got fired at 3. Nobody thought this was unreasonable. Part of your job when you work in defense or finance is giving a sufficient number of fucks about things that people in oth…

Say what you want about air travel security but the TSA has figured some stuff out. For all of the behind the scenes employees, working in what’s known as the SIDA (security identification display are), there are protocols that must be followed. Most are what seems like security common sense but to really drive the point home there are stiff financial penalties for not following them. Typically the employer will pick up the bill but ring up a couple of them and you better start looking for a new job because you’re definitely going to get fired.

I think some kind of strike system is completely reasonable and if you’re working on sensitive information or systems then phishing most definitely needs to count as a strike.

Post reply on HN