Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

281–290 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#281
the only other options I can think of (in the USA) are USPS and a company that I haven't seen in so long that I wondered if they were still in business, DHL. DHL's website is still up and running, but I guess they aren't doing great if I never see their delivery trucks anymore. Maybe they have a stronger presence in areas away from where I live...

Re: Thanks FedEx, this is why we keep getting phished

#282

Earlier quoted context omitted.

Here in Poland, I've already had several banks and at least one insurer send me CD-ROMs. Never heard of anyone sending USB sticks before, but I'm not surprised. The problem is, approximately no one owns a CD/DVD reader anymore, and there are no modern read-only physical media. With SD cards also going the way of the floppy, USB stick is just about the only medium you can hope most customers have means to read.

SD cards are really neat. Theoretically they could have been made with a fixed notch so they would always present as read-only.

Since SD cards and USB sticks are both just computers you plug in to a network port on your computer, they could definitely make write-once SD card controllers.

Re: Thanks FedEx, this is why we keep getting phished

#283

Earlier quoted context omitted.

> For some things, you must use paper Do you have a source backing that up? Aside from the local tax collector, which insists on snailmailing me a copy of all correspondence even though they also sent everything to me digitally, I can't even remember the last time I received any documents on paper, and I'm in the EU.

5 words: Google search eu durable medium. https://www.fca.org.uk/firms/durable-medium https://www.lexology.com/library/detail.aspx?g=788714a1-d7b6... Why did you need a source for this?

From your link

"A PDF can therefore meet the definition of a durable medium."

Re: Thanks FedEx, this is why we keep getting phished

#284

Earlier quoted context omitted.

> In many companies, this would be a P0 "don't go home until it's fixed" production emergency if a bug like this crept in to the software. Would it, really? P0 would probably be "10% of our customers can't submit an order." Or "20% of our vendors are experiencing 404s."

If 10% of customers have passwords that now can't log in and submit orders, that would be an emergency. We're taking OP's word for it that FedEx doesn't allow certain characters as passwords (actually, from the description, it seems more like FedEx only allows specific characters which is even worse). If either of those are true, it is most certainly a defect. Whether FedEx treats that defect as an emergency is up to…

> You originally said "Weird password issues don't count as broke." I think this might just be a case where we have to "agree to disagree".

I meant broke in the sense of "if it ain't broke, don't fix." If there are over 300 microservices running code, connected to mainframes running code that was originally from the 80s, but they occasionally have password issues - the risks caused by trying to fix it might be greater than it's worth.

That doesn't mean FedEx can't do a better job telling people not to use special characters - or detecting if their current password contains them and forces a password change.

Re: Thanks FedEx, this is why we keep getting phished

#285
post #243
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

Is it impressive though? They have about a 50% success rate delivering things to me across multiple addresses and I know other people who have had similar long term issues.

No. They’re 100% useless in my experience, and literally never manage to deliver to me - everything ends up returned to sender. No other courier has this problem.

As for the SMSs - in Portugal, and I’d guess Australia too, they contract all of their local operations out to some random group of muppets who can’t organise their way out of a paper bag - the SMSs they send me come from a mobile number, are handwritten (they seem to literally have someone whose job it is to write messages, on a phone, and send them), as are the emails. When it comes to delivery, i’m inevitably the last delivery of the day as I live way out in the boonies, and they just go “it’s 5pm I’m going home”, and it goes back to the depot. They drive it back and forth for a week before declaring the parcel undeliverable.

These days, if I see someone has shipped something with FedEx, despite my instructions not to, I immediately request a refund, as I know it won’t arrive.

The whole thing beggars belief.

Re: Thanks FedEx, this is why we keep getting phished

#286

Earlier quoted context omitted.

What makes bank a relevant or suitable service provider to store my "important files"? To store any files whatsoever other than those they're obliged to deliver to me?! "upload your testament, passport, and id documents here, you can trust us we are A BANK".

It's the electronic version of a safe deposit box

Perhaps this was the point of your comparison, but it's funny because "safe" deposit boxes aren't safe[0]

https://archive.is/63xoB

Re: Thanks FedEx, this is why we keep getting phished

#287
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

On our company (hosting & PaaS), I was contacted on our internal messenger by a person I've never seen before, asking me to "please" run some commands as root and send back the results. After the initial shock (and due infosec diligence) I found out it was just "the new guy", needing to collect info about our systems for equipment inventory purposes. Since they didn't have access to our networked management tool yet,…

When I worked at Sun Microsystems, they had a clever launcher shell script dealie for things like StarOffice documents that did usage tracking, portability fixes (usually setting obscure environment vars), and of course downloading and opening the actual document. Then they started sending those shell scripts as email attachments. One day they sent out an email telling people to not open executable email attachments: the full memo was a SO document wrapped in one of these scripts.

To their credit, after the inevitable replies to that email they never used that wrapper again (they moved the launchers to the centralized NFS install where they always should have been)

Re: Thanks FedEx, this is why we keep getting phished

#288
post #89

Earlier quoted context omitted.

Healthcare companies in the US send the most scammy looking links for payment processing you’ve ever seen - things like my-healthcare-billing.net It’s insane.

I’m supposed to pay my semi-annual property taxes (on the order of ~thousands of USD) on a site that ends in .org instead of .gov, and nobody apparently sees anything weird or wrong with it.

Some places in the US outsource not only payment processing, but the entire tax collection process to the private sector. I've heard stories of people living in Pennsylvania who have gone years without filing their local tax return because they thought the tax form was spam. Nope, that sketchy looking mail from some random business, with the .com address is the legally designated tax collector.

Re: Thanks FedEx, this is why we keep getting phished

#289
Wow, I thought this was a great post, and I'm just dumbfounded about how egregiously bad that first SMS was - FedEx might as well tell the recipient they want to customs duties wired to a Nigerian prince.

But I also disagree with the general push of Troy Hunt's recommendations. That is, we should just take the base assumption that humans, generally, can't distinguish between real and phishing inbound messages. That's only going to become more true with AI. Relying on those distinguishing characteristics in the first case is an absolute fatal flaw.

Instead (and, in fairness, Troy Hunt did do this) you should never depend on an outbound link or phone number in a message you received. You should log in to whatever service you think sent it based on looking up the address or phone number yourself. This "hang up, look up, call back" advice should be an absolute mantra. I think responsible organizations should just start by saying they will never put links or phone numbers in text/emails/calls, and their notification messages should say something like "Log in to your dashboard to see details."

Post reply on HN