Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

291–300 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#291
This reinforces the need for "mutual trust security" that I've been calling for now for years.

All of the significant authentication schemes are built to validate the customer, and none validate the vendor.

When your bank or mobile provider gives you a call : how do you know it's them? They start asking you for personal data right away, but you have no idea who you are sharing information with.

We need "mutual authentication" including better identity, trust, challenge-response and more. Customers should be able to validate who they are talking to before even sharing their own credentials.

Re: Thanks FedEx, this is why we keep getting phished

#292
post #107
post #46

Earlier quoted context omitted.

I wanted to, but I could not find it. It turn out I could not see the "report phishing" button because of an Outlook glitch. Thanks Microsoft.

Forward the email to your security org?

I did end up forwarding the email to another IT service address (one that I knew was legit). They thanked me for the feedback and said they would improve the message.

Re: Thanks FedEx, this is why we keep getting phished

#293
I clicked the link to read this article because last week I received a paper letter from FedEx I initially thought was scammy.

It asked me to pay duty/taxes for my $799 Prusa 3D print order that arrived just last week.

So now I know Troy Hunt also bought a Mk4 assemble-yourself kit from Prusa.

Enjoy, Troy! Mine took 8 hours to build and it works like a charm! Fantastic little machine.

Re: Thanks FedEx, this is why we keep getting phished

#294
post #22

Earlier quoted context omitted.

But in a modern day and age, when aren’t you expecting a package? Nearly 100% of the time, I am expecting a notification from Canada Post or Amazon (FedEx less frequently, but still). Even outside of that, you can often predict when people are expecting a package. Christmas. After various sales weeks.

> But in a modern day and age, when aren’t you expecting a package? When you’re not constantly buying things online. Most people in the world aren’t expecting packages “nearly 100% of the time”.

[deleted]

Re: Thanks FedEx, this is why we keep getting phished

#295
My favorite FedEx facepalm was when they kept trying and failing to deliver a package to themselves...

They have an option to have your package held at a FedEx store. It's great for when the package requires signature and you're not able to wait at home all day for it.

Recently I used it. Unbeknownst to me, the FedEx store changed its physical location while the package was in transit, to a different strip mall across the highway. So for several days in a row, I was notified that FedEx attempted to deliver, but that the business was closed. Every call to customer service yielded understanding and sympathetic employees who had no idea how to fix the issue.

After about 5 days, something clicked, and my package showed up at the new FedEx location.

Re: Thanks FedEx, this is why we keep getting phished

#296
post #243
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

Is it impressive though? They have about a 50% success rate delivering things to me across multiple addresses and I know other people who have had similar long term issues.

Yeah, in my experience FedEx drivers absolutely LOVE saying they “attempted delivery of my package, but nobody was home,” so I have to go get it from the depot. But I 100% was home, working from home all day, and they 100% never came.

Re: Thanks FedEx, this is why we keep getting phished

#297

Earlier quoted context omitted.

> crazy that FedEx doesn’t have the info attached to the tracking It is crazy how much the "paying duties at the border" situation feels like an afterthought for all currier companies. It is almost as if it was not really their design they just tackled it on later. I wanted to send a present to my brother in an other country using DHL Express. It was impossible to convince them that I would like to pay duties. Not a…

They get a significant markup for providing this "service" to the receiver, so it is not in their interest to help the sender. More charitably the actual duties to be paid might not be known until the package reaches the border at destination.

> They get a significant markup for providing this "service" to the receiver, so it is not in their interest to help the sender.

I understand. It is a service, and I am willing to pay for it. The alternative is that I don't send presents with them. "Happy birthday! Quick pay 20 bucks before you can get your present!" is not really a good experience.

> More charitably the actual duties to be paid might not be known until the package reaches the border at destination.

I understand that too. That is why they are sending the request for the duties only once the package is at the border. But why can they send the request towards the recipient and not towards the sender?

Re: Thanks FedEx, this is why we keep getting phished

#298

This reinforces the need for "mutual trust security" that I've been calling for now for years. All of the significant authentication schemes are built to validate the customer, and none validate the vendor. When your bank or mobile provider gives you a call : how do you know it's them? They start asking you for personal data right away, but you have no idea who you are sharing information with. We need "mutual authen…

That exists, but isn't super widespread. Some places will have you choose something (image, phrase, etc.) that they will display to you when logging in. If you don't recognize the thing shown when you go to login, don't trust it.

Re: Thanks FedEx, this is why we keep getting phished

#299

Is it common for people to have to pay previously unknown charges to get their packages delivered? I don’t frequently make international orders, but have a few times, and have never seen this. Everything has always been charged up front.

Absolutely. That's very often how customs works. As a general rule, the sender is responsible for postage, while the recipient is responsible for customs, and the package only gets released to them once they pay it.

But many times there are no customs fees, so there's no issue -- it depends entirely on the pair of sending and receiving country and the category and amount of merchandise. That may have been your experience.

Generally speaking, customs can't be charged upfront with your order. Perhaps there are exceptions with certain delivery services in certain countries which have managed to modernize some of it, but I haven't come across that yet.

Re: Thanks FedEx, this is why we keep getting phished

#300
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

It's fine.

At least they don't automatically lowercase and truncate your password behind the scenes like AMEX. Lol.

Post reply on HN