Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

301–310 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#301
post #89
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Healthcare companies in the US send the most scammy looking links for payment processing you’ve ever seen - things like my-healthcare-billing.net It’s insane.

To be fair, US healthcare billing companies aren't very far removed from scammers in the first place. Except most scammers are more ethical.

Re: Thanks FedEx, this is why we keep getting phished

#302

Earlier quoted context omitted.

Yubikey supports this already, but without the phone part.

Does it require installing 3rd party software on the host machine? This might not work great for this kind of "shadow IT" application in all environments, whereas one that acts as a USB keyboard might be more versatile.

Only to configure it. It presents as a USB keyboard (among other device types).

Re: Thanks FedEx, this is why we keep getting phished

#303
post #298

This reinforces the need for "mutual trust security" that I've been calling for now for years. All of the significant authentication schemes are built to validate the customer, and none validate the vendor. When your bank or mobile provider gives you a call : how do you know it's them? They start asking you for personal data right away, but you have no idea who you are sharing information with. We need "mutual authen…

That exists, but isn't super widespread. Some places will have you choose something (image, phrase, etc.) that they will display to you when logging in. If you don't recognize the thing shown when you go to login, don't trust it.

You're right but it's for web and hardly used.

Phone, text and email are much bigger threats.

email has some incomplete protections including DKIM and others. Phone and text only have caller-id which is easily spoofed and vendors don't even manage their contact points .

we need a platform that consumers can easily understand and use.

Re: Thanks FedEx, this is why we keep getting phished

#304

Earlier quoted context omitted.

If I saw one of those in a 100k employee company I'd first just assume it's a phish-test email and that anyone who clicks on any URL in it is going to get put in the list for remedial training. There are, of course, a whole plethora of services that a CTO-type person can hire to phish test your employees. Some of them even have several hundred real domain names with live MX on them that you can add into your office36…

I love how those emails have extra metadata in the headers like "X-Phishing-Test: True"

Indeed, though the sort of person who knows how to read and understand mail headers is probably pretty unlikely to fall for a real phish.

Re: Thanks FedEx, this is why we keep getting phished

#305

Earlier quoted context omitted.

If I saw one of those in a 100k employee company I'd first just assume it's a phish-test email and that anyone who clicks on any URL in it is going to get put in the list for remedial training. There are, of course, a whole plethora of services that a CTO-type person can hire to phish test your employees. Some of them even have several hundred real domain names with live MX on them that you can add into your office36…

I love how those emails have extra metadata in the headers like "X-Phishing-Test: True"

I have an Outlook rule to redirect these to junk.

Re: Thanks FedEx, this is why we keep getting phished

#306

Earlier quoted context omitted.

Yubikey supports this already, but without the phone part.

Does it require installing 3rd party software on the host machine? This might not work great for this kind of "shadow IT" application in all environments, whereas one that acts as a USB keyboard might be more versatile.

Does it require installing 3rd party software on the host machine?

No, it identifies as a keyboard. It also defaults to generating a password that will use the same scancodes on (most?) western keyboard layouts so that computers configured to default to e.g. QWERTZ or AZERTY will still result in the same password.

Re: Thanks FedEx, this is why we keep getting phished

#307

Wow, I thought this was a great post, and I'm just dumbfounded about how egregiously bad that first SMS was - FedEx might as well tell the recipient they want to customs duties wired to a Nigerian prince. But I also disagree with the general push of Troy Hunt's recommendations. That is, we should just take the base assumption that humans, generally, can't distinguish between real and phishing inbound messages. That's…

I don't think Troy Hunt is recommending what you're suggesting at all? The very beginning of the post starts with:

> but I'm a smart human so I don't fall for this (that's a joke, read why humans are bad at URLs).

It's clear that he thinks relying on heuristics to distinguish scammy URLs is not a scalable long term approach.

Re: Thanks FedEx, this is why we keep getting phished

#308
post #124

Earlier quoted context omitted.

And even if you do have a CD drive in your computer, the risk is still lower than a USB stick. A CD contains only data, it cannot do things like emulating a keyboard. The worst it can do is shatter when your high-speed DVD-ripping drive spins it up a bit too fast.

A USB stick only contains data too.

No, that's specifically the problem - that's not necessarily true. You're talking about a small plastic box that contains a USB port and some electronics. You have absolutely no way of telling what those electronics will expose to the USB port. It's possible that they only expose some persistent storage, true, but it's equally possible that they expose an emulated keyboard, or just the good old https://en.wikipedia.org/wiki/USB_killer

Re: Thanks FedEx, this is why we keep getting phished

#309

Earlier quoted context omitted.

They decided it was useless security theater decades ago. What happened recently is that they discovered that they rule they used to actively push causes severe harm to security. Now there's a positive rule about not doing it.

Yeah when I was a shipping clerk, we had a pile of usernames and passwords for the Census Bureau's Automated Export System on sticky notes next to the shared computer because the password rotation and complexity requirements made it impossible to remember our passwords.

Oh, there are many fun games from the 90's where you must infiltrate some place and every computer has some version of "due to the password rotation requirements, this week's password for the South-East door is 1-2-3-4, effective from Monday" pasted into it.

When the NIST added the bad rule into their ruleset (it was mostly a collection of bad rules at the time), it was already widely mocked in popular culture (well, within the target population).

I now wonder if that ruleset (the original one, that basically mandated you copy every flaw on Windows NT) was honest.

Post reply on HN