https://www.cyber.gov.au/business-government/asds-cyber-secu...
Want to piss off your IT department? Are the links not malicious looking enough?
291–300 of 335 posts
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#292I think that guy would get a kick out of using this for his pranks.
> https://pc-helper.xyz/usr/libexec/gnome-session/binary/etc/p...
Although I suspect some IT drone would be less enthusiastic when reviewing the chat logs when it’s picked up on heuristics
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#293Re: Want to piss off your IT department? Are the links not malicious looking enough?
#294Re: Want to piss off your IT department? Are the links not malicious looking enough?
#295Earlier quoted context omitted.
See https://xkcd.com/936/
Why would you want to memorise a password? That's what password managers or even paper is for. (Writing your passwords down on paper is actually less crazy than it sounds like: It's impossible to hack paper from the internet. And, if someone has physical access to your stuff, they could install a keylogger anyway.)
You'll definitely want to memorize the password to the backup service that has the last copy of your password vault after a disaster. :P
> Writing your passwords down on paper is actually less crazy than it sounds
I agree that physical security can be incredibly useful against a lot of modern threats... but we can do better. I wish there was a dedicated password-keeper device format of:
* A small keyboard and screen
* The data encrypted at rest by one master password
* Only permits upload/download of the the encrypted file over USB. With some companion software, you just plug it into your computer, computer copies the encrypted file to somewhere on disk that gets regularly backed up, the disconnects and beeps to tell you it's done.
* Sturdy enough that any "Evil Maid" attack needs to be done by a professional rather than a conniving roommate or jilted partner.
* Tracks history of entries, last-changed, etc.
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#296Earlier quoted context omitted.
See https://xkcd.com/936/
Why would you want to memorise a password? That's what password managers or even paper is for. (Writing your passwords down on paper is actually less crazy than it sounds like: It's impossible to hack paper from the internet. And, if someone has physical access to your stuff, they could install a keylogger anyway.)
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#297Ah no need, corporate IT already make all URLs malicious looking through some microsoft "secure link" service, and constantly shows everyone shady looking prompts that constantly change and have cmd.exe windows flash in at random. A phone call from Microsoft about my Norton anti-virus subscription putting me into debt that can only be settled with Nintendo gift cards bought in cash across 16 specific gas stations see…
It’s a trade-off. Most people are never going to check the links no matter how much you ask them to, and even if they did they wouldn’t know what to check for. But the tool Microsoft give you to check a link before opening it is that awful URL rewriter, which prevents the small minority who would check from being able to. Similarly those flashing cmd windows are usually automatic update processes that Windows has no…
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#298Re: Want to piss off your IT department? Are the links not malicious looking enough?
#299Earlier quoted context omitted.
All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com
Outlook has a rule filter for header content. Just saying I haven't failed a phishing test in ~10 years.
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#300Or just report their mandatory compliance emails as phishing attempts. I’ve worked for multiple large companies where the annual IT security signoffs look exactly like malicious emails: weird formatting; originates from weird external url that includes suspicious words; urgent call to action; and threats of discipline for non-compliance. All this money being spent on training, only to immediately lull users into acce…
The phishing-emails-as-a-test emails were so frequent that I started flagging all emails from our company that had a link in them as phishing emails and let the IT staff tell me which ones were real. They didn't enjoy that so they stopped sending the phishing emails as often. They still send them though, from time to time. I ended up creating my own browser extension for gmail that blocks clicking on any link unless…