A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…
Healthcare companies in the US send the most scammy looking links for payment processing you’ve ever seen - things like my-healthcare-billing.net It’s insane.
Thanks FedEx, this is why we keep getting phished
301–310 of 576 posts
Re: Thanks FedEx, this is why we keep getting phished
#302Earlier quoted context omitted.
Yubikey supports this already, but without the phone part.
Does it require installing 3rd party software on the host machine? This might not work great for this kind of "shadow IT" application in all environments, whereas one that acts as a USB keyboard might be more versatile.
Re: Thanks FedEx, this is why we keep getting phished
#303This reinforces the need for "mutual trust security" that I've been calling for now for years. All of the significant authentication schemes are built to validate the customer, and none validate the vendor. When your bank or mobile provider gives you a call : how do you know it's them? They start asking you for personal data right away, but you have no idea who you are sharing information with. We need "mutual authen…
That exists, but isn't super widespread. Some places will have you choose something (image, phrase, etc.) that they will display to you when logging in. If you don't recognize the thing shown when you go to login, don't trust it.
Phone, text and email are much bigger threats.
email has some incomplete protections including DKIM and others. Phone and text only have caller-id which is easily spoofed and vendors don't even manage their contact points .
we need a platform that consumers can easily understand and use.
Re: Thanks FedEx, this is why we keep getting phished
#304Earlier quoted context omitted.
If I saw one of those in a 100k employee company I'd first just assume it's a phish-test email and that anyone who clicks on any URL in it is going to get put in the list for remedial training. There are, of course, a whole plethora of services that a CTO-type person can hire to phish test your employees. Some of them even have several hundred real domain names with live MX on them that you can add into your office36…
I love how those emails have extra metadata in the headers like "X-Phishing-Test: True"
Re: Thanks FedEx, this is why we keep getting phished
#305Earlier quoted context omitted.
If I saw one of those in a 100k employee company I'd first just assume it's a phish-test email and that anyone who clicks on any URL in it is going to get put in the list for remedial training. There are, of course, a whole plethora of services that a CTO-type person can hire to phish test your employees. Some of them even have several hundred real domain names with live MX on them that you can add into your office36…
I love how those emails have extra metadata in the headers like "X-Phishing-Test: True"
Re: Thanks FedEx, this is why we keep getting phished
#306Earlier quoted context omitted.
Yubikey supports this already, but without the phone part.
Does it require installing 3rd party software on the host machine? This might not work great for this kind of "shadow IT" application in all environments, whereas one that acts as a USB keyboard might be more versatile.
No, it identifies as a keyboard. It also defaults to generating a password that will use the same scancodes on (most?) western keyboard layouts so that computers configured to default to e.g. QWERTZ or AZERTY will still result in the same password.
Re: Thanks FedEx, this is why we keep getting phished
#307Wow, I thought this was a great post, and I'm just dumbfounded about how egregiously bad that first SMS was - FedEx might as well tell the recipient they want to customs duties wired to a Nigerian prince. But I also disagree with the general push of Troy Hunt's recommendations. That is, we should just take the base assumption that humans, generally, can't distinguish between real and phishing inbound messages. That's…
> but I'm a smart human so I don't fall for this (that's a joke, read why humans are bad at URLs).
It's clear that he thinks relying on heuristics to distinguish scammy URLs is not a scalable long term approach.
Re: Thanks FedEx, this is why we keep getting phished
#308Earlier quoted context omitted.
And even if you do have a CD drive in your computer, the risk is still lower than a USB stick. A CD contains only data, it cannot do things like emulating a keyboard. The worst it can do is shatter when your high-speed DVD-ripping drive spins it up a bit too fast.
A USB stick only contains data too.
Re: Thanks FedEx, this is why we keep getting phished
#309Earlier quoted context omitted.
They decided it was useless security theater decades ago. What happened recently is that they discovered that they rule they used to actively push causes severe harm to security. Now there's a positive rule about not doing it.
Yeah when I was a shipping clerk, we had a pile of usernames and passwords for the Census Bureau's Automated Export System on sticky notes next to the shared computer because the password rotation and complexity requirements made it impossible to remember our passwords.
When the NIST added the bad rule into their ruleset (it was mostly a collection of bad rules at the time), it was already widely mocked in popular culture (well, within the target population).
I now wonder if that ruleset (the original one, that basically mandated you copy every flaw on Windows NT) was honest.