Live data from Hacker News

Want to piss off your IT department? Are the links not malicious looking enough?

phishyurl.com

291–300 of 335 posts

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#292
I had a coworker that would "prank" others by sending out of band messages from other colleagues when they leave their laptop open.

I think that guy would get a kick out of using this for his pranks.

> https://pc-helper.xyz/usr/libexec/gnome-session/binary/etc/p...

Although I suspect some IT drone would be less enthusiastic when reviewing the chat logs when it’s picked up on heuristics

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#295
post #182
post #170

Earlier quoted context omitted.

See https://xkcd.com/936/

Why would you want to memorise a password? That's what password managers or even paper is for. (Writing your passwords down on paper is actually less crazy than it sounds like: It's impossible to hack paper from the internet. And, if someone has physical access to your stuff, they could install a keylogger anyway.)

> Why would you want to memorise a password?

You'll definitely want to memorize the password to the backup service that has the last copy of your password vault after a disaster. :P

> Writing your passwords down on paper is actually less crazy than it sounds

I agree that physical security can be incredibly useful against a lot of modern threats... but we can do better. I wish there was a dedicated password-keeper device format of:

* A small keyboard and screen

* The data encrypted at rest by one master password

* Only permits upload/download of the the encrypted file over USB. With some companion software, you just plug it into your computer, computer copies the encrypted file to somewhere on disk that gets regularly backed up, the disconnects and beeps to tell you it's done.

* Sturdy enough that any "Evil Maid" attack needs to be done by a professional rather than a conniving roommate or jilted partner.

* Tracks history of entries, last-changed, etc.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#296
post #182
post #170

Earlier quoted context omitted.

See https://xkcd.com/936/

Why would you want to memorise a password? That's what password managers or even paper is for. (Writing your passwords down on paper is actually less crazy than it sounds like: It's impossible to hack paper from the internet. And, if someone has physical access to your stuff, they could install a keylogger anyway.)

[deleted]

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#297

Ah no need, corporate IT already make all URLs malicious looking through some microsoft "secure link" service, and constantly shows everyone shady looking prompts that constantly change and have cmd.exe windows flash in at random. A phone call from Microsoft about my Norton anti-virus subscription putting me into debt that can only be settled with Nintendo gift cards bought in cash across 16 specific gas stations see…

It’s a trade-off. Most people are never going to check the links no matter how much you ask them to, and even if they did they wouldn’t know what to check for. But the tool Microsoft give you to check a link before opening it is that awful URL rewriter, which prevents the small minority who would check from being able to. Similarly those flashing cmd windows are usually automatic update processes that Windows has no…

I sure do miss the days before browser makers conspired to make it near impossible to check the certs when there’s a certificate related error. “Most people are never going to check properly” is a poor excuse.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#299
post #184

Earlier quoted context omitted.

All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com

Outlook has a rule filter for header content. Just saying I haven't failed a phishing test in ~10 years.

I did this and it worked for a few months before word got to security who then forced everyone to remove the rule.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#300
post #27

Or just report their mandatory compliance emails as phishing attempts. I’ve worked for multiple large companies where the annual IT security signoffs look exactly like malicious emails: weird formatting; originates from weird external url that includes suspicious words; urgent call to action; and threats of discipline for non-compliance. All this money being spent on training, only to immediately lull users into acce…

The phishing-emails-as-a-test emails were so frequent that I started flagging all emails from our company that had a link in them as phishing emails and let the IT staff tell me which ones were real. They didn't enjoy that so they stopped sending the phishing emails as often. They still send them though, from time to time. I ended up creating my own browser extension for gmail that blocks clicking on any link unless…

Aside from the test emails, many emails from contractors that our corporate IT works with have the appearance of phishing. I'm not shy about reporting any of these. Most of the time they say "that's a real email". I like to educate them that their contractors are sending poorly-crafted emails to the whole company.
Post reply on HN