Live data from Hacker News

Want to piss off your IT department? Are the links not malicious looking enough?

phishyurl.com

301–310 of 335 posts

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#301

Earlier quoted context omitted.

That sounds like a good semi-retirement gig just to get out of the house for a little while. If you're teaching the tech-related electives rather than mandatory core courses, the students are likely a lot more pleasant to deal with. I took German just to get away from the all the kids taking Spanish or French who were just there because they have to get their foreign language credit.

Yes, just what we need, retired people with a whole career of making income behind themselves taking another decent entry level job someone one just out of college can get. (No teaching credential needed for substitute teachers usually)

If a semi-retired engineer with 2-4 decades of work experience makes a better public high school STEM teacher, then I hope a lot more engineers do it as a semi-retirement gig.

The aspiring career schoolteachers will just have to find a job in a field that is short-staffed, like registered nurses or one of the trades. I'm sure that comes across as "let them eat cake" to some Bernie moron, but going back to school for 6 months is small potatoes, and doing a little market research before making big financial decisions like choosing your college major in the first place is basic adult responsibility.

If we apply the "lump of labor" fallacy everywhere else honestly and consistently, we would have to be opposed to immigration and trade because "those damn foreigners" went and "took er jerbs".

https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcRtkJaZ...

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#302

Earlier quoted context omitted.

The phishing-emails-as-a-test emails were so frequent that I started flagging all emails from our company that had a link in them as phishing emails and let the IT staff tell me which ones were real. They didn't enjoy that so they stopped sending the phishing emails as often. They still send them though, from time to time. I ended up creating my own browser extension for gmail that blocks clicking on any link unless…

Aside from the test emails, many emails from contractors that our corporate IT works with have the appearance of phishing. I'm not shy about reporting any of these. Most of the time they say "that's a real email". I like to educate them that their contractors are sending poorly-crafted emails to the whole company.

The last straw for me was when I received an email "from my boss" telling me of my holiday bonus with a link to click. Well I knew that was a phishing-test email right away because that cheap bastard has never given me a holiday bonus, not even once in the 10 years I've worked there. Some nerve sending out a phishing-test disguised as a bonus, fucking pour some salt into the wound why don't they.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#303

Ah no need, corporate IT already make all URLs malicious looking through some microsoft "secure link" service, and constantly shows everyone shady looking prompts that constantly change and have cmd.exe windows flash in at random. A phone call from Microsoft about my Norton anti-virus subscription putting me into debt that can only be settled with Nintendo gift cards bought in cash across 16 specific gas stations see…

In addition to making the link look shady, it adds considerable lag to opening the link. I'm using Finicky[1] on Mac to rewrite the URL by extracting the original URL from the query params[2]. 1: https://github.com/johnste/finicky 2: https://github.com/fphilipe/dotfiles/blob/31e3d18fe5f51b2fd8...

Nice, I use finicky as well, but now and again I have to change a rule or even add a new one. pisses me right off. Anyway thank you for sharing your dotfiles.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#304
post #184

Earlier quoted context omitted.

All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com

Outlook has a rule filter for header content. Just saying I haven't failed a phishing test in ~10 years.

I just don't check my emails anymore. If it is important, people will complain on teams that nobody answer with some sort of urgency and then I'll look for it specifically.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#305

All of this reminds me of a hilarious situation at a previous employer. As is standard corporate practice, they used to tell people to inspect links by hovering over them to confirm that they lead to the official website of the sender. People kept falling for phishing links though, so they got a Trend Micro device to scan emails, which also rewrote every link in it to point to their URL scanning service, which means…

I had the opposite problem at my last company. When you hover over a link Apple's Mail app opens a preview of the page. So if you try to see the URL then you automatically visit the link and get sent for more training.

Isn't that behavior desactivable?

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#306

Earlier quoted context omitted.

I have firstname@lastname.email... people keep telling me that can't be right and don't i mean it ends with email.com?

I have a .ninja email and get the same a lot to the extend where I explicitly say "it ends in .ninja with no .com or anything". Usually use company-i-buy-from@mydomain.ninja whenever I make online purchases, and I had a guy from a small shop call me up and ask why I had an email with his company name on. Took some good fifteen minutes to explain him that I was legit and owned the domain. He was still reluctant in the…

Same... I had my Luma.com account closed and disabled because of my "suspicious" email... had to ask a friend to get it back.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#307

Earlier quoted context omitted.

I have a .ninja email and get the same a lot to the extend where I explicitly say "it ends in .ninja with no .com or anything". Usually use company-i-buy-from@mydomain.ninja whenever I make online purchases, and I had a guy from a small shop call me up and ask why I had an email with his company name on. Took some good fifteen minutes to explain him that I was legit and owned the domain. He was still reluctant in the…

Ha! Exactly this happens to me too. Had to return some electronics in person, the guy suddenly started fishing if I was some mystery shopper or QC person... because the invoice was made out to their.store@myname.email That said I've caught and blacklisted quite a few bad actors this way, AND filtering is easier. So worth the occasional weird interaction.

> That said I've caught and blacklisted quite a few bad actors this way

same! A long time ago I registered an adobe account with the email "+fsck_adobe@gmail.com"

Adobe then got hacked and their account database leaked. Later I got a personalized spam email for a dating site sent to the same +fsck_adobe@gmail email. I complained, and they claimed innocence, saying they got the email from some sort of contact lead service. I then got in touch with that contact lead service's CEO, and of course he had "no idea" how that email got in there. I'm sure they knew very well how it got in there, and after I reported it, they just removed everything after a "+" on @gmail.com emails...

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#308

Earlier quoted context omitted.

I have a .ninja email and get the same a lot to the extend where I explicitly say "it ends in .ninja with no .com or anything". Usually use company-i-buy-from@mydomain.ninja whenever I make online purchases, and I had a guy from a small shop call me up and ask why I had an email with his company name on. Took some good fifteen minutes to explain him that I was legit and owned the domain. He was still reluctant in the…

I used to use this company-i-buy-from strategy, but i got accused of fakery a lot, until I tried a new strategy -- interest@domain.dev. So if i were buying from REI, i would use camping@domain.dev or if i were ordering office supplies i would use officemgmt@domain.dev. It's slightly less obvious what you're doing, and raises fewer questions.

People will still ask if you work in the 'interest' sector, but it is still better than having to explain why their company name is in your e-mail address.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#309
post #160

Earlier quoted context omitted.

Oh, come on. Freedom of Information Act sounds kinda nice!

There's exceptions to every rule

FOIAs are still faith based anyway. And we know faith based systems arn't going to survive.
Post reply on HN