I'm disappointed by how little protection we're getting against phishing campaigns. Google's SafeSearch takes forever to process stuff, where presumably very quick response times are much more effective, Fastmail, despite being great in general, is _terrible_ at detecting phishing, Booking.com met my report of a phishing campaign over their site (hotel got hacked) with a "it happens, we might talk to the hotel about…
> banks and other institutions continue to send legitimate messages that look like phishing. The Canada Revenue Agency (tax collectors) once called me up about something. They literally said "To verify your identity, please give me your social insurance number". It's hard to blame people when actual government agencies are training people to be phished.
Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
31–40 of 75 posts
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#32USPS.gov redirecting to USPS.com certainly doesn't help matters. Things like this should use one of the few TLDs that actually has policies and procedures in place; then it's a simple "if it's not .gov, it's not real."
They need to parse slashes, dots, colons and ats (remember URLs can contain credentials, even though I believe browser issue warnings these days), identifiy the TLD and the domain and then know what is legit and what isn't. And know that things like onmicrosoft.com is legit while atmicrosoft.com is probably not. Or whatever link shortener some legit organizations are using.
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#33Earlier quoted context omitted.
I wonder if the .com TLD is part of the GOP campaign to kill the USPS
USPS purchased the usps.com domain a long time ago specifically so they could control it and prevent phishing. The decision to replace usps.gov with the .com domain came later, with the tenure of Trump appointee Louis DeJoy. Right wingers believe that USPS should operate as a business, not a public service, so "rebranding" their website to be .com is definitely a part of that narrative.
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#34Earlier quoted context omitted.
> banks and other institutions continue to send legitimate messages that look like phishing. The Canada Revenue Agency (tax collectors) once called me up about something. They literally said "To verify your identity, please give me your social insurance number". It's hard to blame people when actual government agencies are training people to be phished.
Just curious, how did you confirm it was The Canada Revenue Agency and not scammers?
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#35Earlier quoted context omitted.
USPS purchased the usps.com domain a long time ago specifically so they could control it and prevent phishing. The decision to replace usps.gov with the .com domain came later, with the tenure of Trump appointee Louis DeJoy. Right wingers believe that USPS should operate as a business, not a public service, so "rebranding" their website to be .com is definitely a part of that narrative.
So the ask should be to have .gov be canonical, and usps.com directing to .gov it sounds like?
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#36USPS.gov redirecting to USPS.com certainly doesn't help matters. Things like this should use one of the few TLDs that actually has policies and procedures in place; then it's a simple "if it's not .gov, it's not real."
You're right that it doesn't help, but looking at regular non-technical people like my retired parents for example, I really wonder if it's a realistic expectation that people know what the important part of a URL are. They need to parse slashes, dots, colons and ats (remember URLs can contain credentials, even though I believe browser issue warnings these days), identifiy the TLD and the domain and then know what is…
But we should be taking the obvious steps like enforcing government domains on .gov . Attacks and scams are getting more sophisticated, so I hope when I'm elderly I can atleast check the .gov portion and know it's an actual government website.
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#37Its not just in US, it happens in every country. SMS is the main way these links are distributed. So much so that in Sri Lanka, gov planned to add a centralized SMS firewall. https://economynext.com/sri-lanka-to-study-infobip-centraliz... Google messages have a good spam filter than can filter in real time them, but I have seen some get though for a small period of time.
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#38Earlier quoted context omitted.
I wonder if the .com TLD is part of the GOP campaign to kill the USPS
USPS purchased the usps.com domain a long time ago specifically so they could control it and prevent phishing. The decision to replace usps.gov with the .com domain came later, with the tenure of Trump appointee Louis DeJoy. Right wingers believe that USPS should operate as a business, not a public service, so "rebranding" their website to be .com is definitely a part of that narrative.
[1] https://web.archive.org/web/20000229182038/http://www.usps.g...
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#39Earlier quoted context omitted.
You're right that it doesn't help, but looking at regular non-technical people like my retired parents for example, I really wonder if it's a realistic expectation that people know what the important part of a URL are. They need to parse slashes, dots, colons and ats (remember URLs can contain credentials, even though I believe browser issue warnings these days), identifiy the TLD and the domain and then know what is…
The Internet has been around long enough at this point. Maybe your parents might never be able to read a URL and there will always be people who get scammed. But we should be taking the obvious steps like enforcing government domains on .gov . Attacks and scams are getting more sophisticated, so I hope when I'm elderly I can atleast check the .gov portion and know it's an actual government website.
Re: Phishing Campaigns Targeting USPS See as Much Web Traffic as the USPS Itself
#40Earlier quoted context omitted.
I wonder if the .com TLD is part of the GOP campaign to kill the USPS
USPS purchased the usps.com domain a long time ago specifically so they could control it and prevent phishing. The decision to replace usps.gov with the .com domain came later, with the tenure of Trump appointee Louis DeJoy. Right wingers believe that USPS should operate as a business, not a public service, so "rebranding" their website to be .com is definitely a part of that narrative.
[0]here is just one: https://www.reddit.com/r/explainlikeimfive/comments/3piv7w/e...