Live data from Hacker News

Should Failing Phish Tests Be a Fireable Offense?

krebsonsecurity.com

301–310 of 357 posts

Re: Should Failing Phish Tests Be a Fireable Offense?

#302
post #94

Earlier quoted context omitted.

Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.

> Are you prepared to pay your employees a significant premium for the requirement that they engage in fisticuffs with random strangers who may try to tailgate into the building? I have zero experience with this, but I imagine the policy would be "Don't enter the building if someone is too close behind you." If you don't feel comfortable asking for space (fine!), turn around, go back to your car, and call building se…

The policy at our building is that, if you don't feel comfortable, let the person follow you in, but let security know.

We have the advantage that all entrances end up going through a central area, and we have ample camera coverage, such that security can reliably find people who tailgated if they are informed.

Tailgating is actually a very frequent and problematic occurrence for us, sometimes by people who will be aggressive, and this has seemed like the safest solution for us.

Re: Should Failing Phish Tests Be a Fireable Offense?

#303
post #220

Earlier quoted context omitted.

No I don't have to do that. The onus isn't on me. I don't know where you came up with such a silly idea.

The historical record of confidence tricks goes back 400 years. Little changes. There's a con out there for everyone just like there's a lid for every pot.

Oh sure everyone can be vulnerable to certain cons. Fortunately all spear phishing attacks can be very easily avoided through technical means. I guess those who down voted me must be unfamiliar with the functionality available in current enterprise email systems.

Re: Should Failing Phish Tests Be a Fireable Offense?

#304

It makes no sense to blame users for doing perfectly normal things like clicking on web links, reading email, opening attachments, reading a memory card, connecting to a wireless network, etc. rather than blaming hardware and software developers for designing systems where perfectly normal actions result in criminals taking over your computer. It also makes no sense to blame users for thinking an email message is fro…

Except the URL is usually nothing like your banks.

Re: Should Failing Phish Tests Be a Fireable Offense?

#305
post #134
post #104

Earlier quoted context omitted.

That’s not true. My workplace has employee only entrances where even visitor/temporary badges don’t work. No one is standing guard and they tell everyone to not allow tailgating.

That's the point. I was in the infantry, am 6'2, and a guy. I don't have a problem with challenging folks who are tailgating. That is not the case for everyone. Do you expect disabled folks to challenge tailgaters? What about physically small people? Setting aside the office dynamics around discrimination issues, how many people actually have the confidence to challenge an unknown person who is tailgating, knowing th…

You're absolutely right and I find this thread completely absurd.

If building security matters you implement mechanisms to enforce it, not burden all your employees with taking up the shortcomings.

Tail-gating should be impossible if you care about security.

Re: Should Failing Phish Tests Be a Fireable Offense?

#306
post #303

Earlier quoted context omitted.

The historical record of confidence tricks goes back 400 years. Little changes. There's a con out there for everyone just like there's a lid for every pot.

Oh sure everyone can be vulnerable to certain cons. Fortunately all spear phishing attacks can be very easily avoided through technical means. I guess those who down voted me must be unfamiliar with the functionality available in current enterprise email systems.

That's great. Not all spearphishing comes in via email though. See Dark Caracal or Magic Hound for relevant history here.

Also fraudulent invoices are another form of spearphishing that you'll still have a pretty hard time against.

I don't know, I'm also on the operations side in a large enterprise and I help with our internal phishing efforts. Pretty sure I'm familiar with the same tools that you are and I vehemently disagree with your assessment.

Re: Should Failing Phish Tests Be a Fireable Offense?

#307
post #83

Earlier quoted context omitted.

The risk of hitting an exploit on the command line, especially with something like wget, is enough orders of magnitude lower that I think it falls under acceptable. The standard cannot be zero risk because that's impossible. Even shutting off the internet link doesn't get you all the way to zero.

The issue isn't how much risk there is in opening it. The problem is that regardless of how much or little risk there is in opening the link, it wasn't op's job to examine it. It was unnecessary risk to open the link.

I mean, it's not my job to refill the office coffee pot when I take the last cup of coffee, either, but since I'm decent to my coworkers I'd probably do it. Not the OP, but since I know how to open a malicious link safely in wget I would happily do that for similar reasons, and if I got reprimanded for it "not being my job"... I'd start looking for a new job where I'm respected for what I'm able to do.

Re: Should Failing Phish Tests Be a Fireable Offense?

#308

Earlier quoted context omitted.

Can't speak to whether a reprimand is warranted or not and I think many here will disagree, but unless your job is investigating phishing, you shouldn't do this because you ARE ultimately putting the corporate network at risk unnecessarily - what if it was a real link and happened to exploit a zero day on your box? Management wouldn't accept your reasoning for following the link I suspect.

I doubt most if not all exploits would work in lynx/links. But your point is spot on, don't take it upon yourself to do things that aren't in your job description. Otherwise you become that person who takes it upon themselves to "fix" things and makes the problem worse for the people responsible for fixing things.

> don't take it upon yourself to do things that aren't in your job description

That's a great way to never go anywhere in your career.

Re: Should Failing Phish Tests Be a Fireable Offense?

#309
post #58

Earlier quoted context omitted.

I actually like the idea of having consequences for allowing tailgating, assuming the company cares about it. Maybe not firing, at least right away, or if you get tricked/someone sneaks in behind you, but put some teeth in the policy and actually enforce it. If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that ev…

You can wave any object at the sensor. Maybe an unauthorized tag will yield a different beep or make the light flash a different color. Maybe the person in front of you will be in a position to see the light on the reader, maybe they'll notice, and maybe they'll consider it odd. Getting that far, and then actually deciding to challenge you or report it, is a vanishingly small chance. There is no point in badging an u…

Agree.

The whole idea of 'challenging tailgating' falls apart because someone walking in after you is not performing a strange act.

You would have to actively close the door _on_ people, including your colleagues, which goes against social norms to such an extreme extent that it's just not happening.

Re: Should Failing Phish Tests Be a Fireable Offense?

#310
post #193
post #56

Earlier quoted context omitted.

It should be appealable. I see at least two problems with such a phishing test: a) Some test phishing urls include the plaintext mail address of the employee. Easy to retaliate against someone you don't like. b) Does the phishing test service detect if the link is accessed via a sandboxed env?

> b) Does the phishing test service detect if the link is accessed via a sandboxed env? In any company likely to be doing phishing testing internally, there are two kinds of people who might try this. One is the infosec group, which isn't going to do this because they're running the test. The other is engineers who think they're clever and are equipped to fsck around with things. The former are professionals. The lat…

Good lord, you make it sound like dealing with highly radioactive plutonium. This is a site called hacker news, if you're a web developer and you can't figure out how to pull an html page without executing the scripts involved (a TRIVIAL thing to do) you shouldn't have a job. And honestly if your network is so insecure that someone running a wget on a domain poses a risk then your network has almost assuredly already been hacked.
Post reply on HN