Should Failing Phish Tests Be a Fireable Offense?
321–330 of 357 posts
Re: Should Failing Phish Tests Be a Fireable Offense?
#322Phish tests need to be fair to people who actually understand something about security. "Opening an email" is not actually an issue (spearphishers that sit on drive-by 0-days in current browsers or email programs are not a threat model that most orgs can possibly defend against). Opening attachements is hard to measure and again needs context: What kind of software and sandbox was the attachement opened with? Attacke…
Re: Should Failing Phish Tests Be a Fireable Offense?
#323Earlier quoted context omitted.
The German U-Bahn has a brilliant solution to this. No turnstiles or gates, you're just expected to have a ticket. The penalty for getting caught without a ticket is considered sufficiently high to make "Schwarzfahren" statistically more expensive.
"Screw 'em hard enough for breaking the rules and they'll follow the rules out of fear" is generally not considered to be a good model for organizational policy.
Re: Should Failing Phish Tests Be a Fireable Offense?
#324Earlier quoted context omitted.
Downloading and executing code is only one way a browser session can be abused. At the very least you're giving away everything your browser (even Lynx) puts in the headers of a request. That's often a heck of a lot of useful information for an attacker. Lynx supports cookies too so it would be possible to track a user between sessions. I don't know how that might benefit an attacker but I'm not an attacker[1]. I thi…
>At the very least you're giving away everything your browser (even Lynx) puts in the headers of a request. Which you're giving away any time you browse any external web site. >Lynx supports cookies too so it would be possible to track a user between sessions. You're downloading cookies for most external web sites. If the worst you do is the same as going to espn.com, then reprimand people for going to any external w…
Re: Should Failing Phish Tests Be a Fireable Offense?
#325Earlier quoted context omitted.
> Your attitude doesn't account for the possibility that since you do business with somebody, you need or want to receive some of their emails. You are incorrect and interpreting my comments very narrowly. Doing specific business with somebody should not give that somebody carte blanch to use my email address for whatever reason they wish. I absolutely can be ruthless in eliminating aspects I don't like and if busine…
And, assuming there are clear and reasonable ways to inform them that you don't wish further communications (as there should be with any professional marketing), you should take that route. Otherwise anything is fair game. But I attended an event and got a follow-up email? Calling that spam is mostly being an asshole.
I know it sucks when an IP gets burned, but when you're acting in good faith it's a rarity - or has been in my experience.
Re: Should Failing Phish Tests Be a Fireable Offense?
#326Earlier quoted context omitted.
From this and other comments in this thread it seems you have failed these phishing tests as soon as you click a link. Is the assumption here that you are completely pwned as soon as you visit an url controlled by an attacker? I can't imagine myself compromising company data/funds via a website where I ended up through a newsletter unsubscribe link so this seems quite unfair on the part of the phish-testers.
If you think visiting a webpage in Chrome, or any other browser, even inside a VM, is totally safe, especially against a nation-state level actor, I have some bad news for you.
Re: Should Failing Phish Tests Be a Fireable Offense?
#327Earlier quoted context omitted.
> Embarrassingly, I failed this once and then created an email rule which filters out the fake Phish. how did it get you, if you don't mind sharing? It seems if someone who works in IT (guessing you do) and is very careful fails it, this is an impossibly high standard to meet. curious how they got you.
I guy I worked with fell for one when he was selling his car online, he got an email from an interested buyer (car thief) the linked to a very good replication of the site he was selling it on. The car thief turns up and scouts the location but the give away was that he showed little interest in the car, at which point he went back and checked the email to discover the phishing. Even trained intelligent people have m…
Re: Should Failing Phish Tests Be a Fireable Offense?
#328I think a better question would be is Sr Leadership supporting the security and risk mgmt teams in developing proper training as well as implementing and spending the money on the proper controls to help reduce the risk to the end user of being spear phished?
Re: Should Failing Phish Tests Be a Fireable Offense?
#329Earlier quoted context omitted.
The city of Toronto would like to hear from you. Our Subway turnstiles keep breaking. And since they’re entry and exit, there’s many methods to enter by triggering the exit side, from umbrellas to a small dog.
The German U-Bahn has a brilliant solution to this. No turnstiles or gates, you're just expected to have a ticket. The penalty for getting caught without a ticket is considered sufficiently high to make "Schwarzfahren" statistically more expensive.
The social stigma, unpredictability and inconvenience of having to pay the fine is a big part of it (not having a ticket is just stressful). Another part is that you don't need to prevent freeriding, nor recoup all the lost ticket sales. You just need enough of a nudge to keep most people honest most of the time.
Re: Should Failing Phish Tests Be a Fireable Offense?
#330Earlier quoted context omitted.
You can wave any object at the sensor. Maybe an unauthorized tag will yield a different beep or make the light flash a different color. Maybe the person in front of you will be in a position to see the light on the reader, maybe they'll notice, and maybe they'll consider it odd. Getting that far, and then actually deciding to challenge you or report it, is a vanishingly small chance. There is no point in badging an u…
Agree. The whole idea of 'challenging tailgating' falls apart because someone walking in after you is not performing a strange act. You would have to actively close the door _on_ people, including your colleagues, which goes against social norms to such an extreme extent that it's just not happening.