Live data from Hacker News

Want to piss off your IT department? Are the links not malicious looking enough?

phishyurl.com

321–330 of 335 posts

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#321
post #315
post #295

Earlier quoted context omitted.

> Why would you want to memorise a password? You'll definitely want to memorize the password to the backup service that has the last copy of your password vault after a disaster. :P > Writing your passwords down on paper is actually less crazy than it sounds I agree that physical security can be incredibly useful against a lot of modern threats... but we can do better. I wish there was a dedicated password-keeper dev…

> You'll definitely want to memorize the password to the backup service that has the last copy of your password vault after a disaster. :P Why? Write it down. Perhaps leave multiple paper copies around with some trusted people, like your lawyer and a safe deposit box at your bank. Your proposed device seems a bit complicated. You can get pretty far with a piece of paper and this protocol: Construct your password from…

> Why? Write it down. Perhaps leave multiple paper copies around with some trusted people, like your lawyer and a safe deposit box at your bank.

Those people would then effectively have access to your nearly-current desktop/laptop data from anywhere, especially since they would have to know who you are which greatly simplifies guessing your username/email.

> You can get pretty far with a piece of paper

Password Papers (A) never get backed-up, meaning they'll be locked out of basically everything if the house burns down and (B) I've already tried getting relatives using them to adopt exactly such a fixed+variable combo scheme.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#322
post #320
post #315

Earlier quoted context omitted.

> You'll definitely want to memorize the password to the backup service that has the last copy of your password vault after a disaster. :P Why? Write it down. Perhaps leave multiple paper copies around with some trusted people, like your lawyer and a safe deposit box at your bank. Your proposed device seems a bit complicated. You can get pretty far with a piece of paper and this protocol: Construct your password from…

> Why? Write it down. Perhaps leave multiple paper copies around with some trusted people, like your lawyer and a safe deposit box at your bank. Those people would then effectively have access to your nearly-current desktop/laptop data from anywhere, especially since they would have to know who you are which greatly simplifies guessing your username/email. > You can get pretty far with a piece of paper Password Paper…

> Those people would then effectively have access to your nearly-current desktop/laptop data from anywhere, especially since they would have to know who you are which greatly simplifies guessing your username/email.

Why from anywhere?

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#323

Earlier quoted context omitted.

I used to use this company-i-buy-from strategy, but i got accused of fakery a lot, until I tried a new strategy -- interest@domain.dev. So if i were buying from REI, i would use camping@domain.dev or if i were ordering office supplies i would use officemgmt@domain.dev. It's slightly less obvious what you're doing, and raises fewer questions.

People will still ask if you work in the 'interest' sector, but it is still better than having to explain why their company name is in your e-mail address.

Haha yeah I used to give realtors "realty@domain.dev" and I used to get a lot of dirty looks ... I think they thought I was competition

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#324
post #56

Earlier quoted context omitted.

Or do what actually happened in the 20 years since that myth was actively doing the rounds: display HTML with sandboxed text/html viewers, as pine was doing back then, and as other systems eventually cottoned on to doing. By the time that the 2010s came along, the idea of sandboxing had taken root. Even in the middle 2000s, mail readers such as NEO and Eudora came with feature-reduced internal HTML viewers as an opti…

Thats a lot of effort compared to just plaintext that not only need none of this but also looks more professional, saves time and bandwidth. The only people who care about HTML mails are scammer and marketing.

As a reader (and sometimes sender) of emails, I don't know why wanting my emails to be formatted when I'm reading them, so that some text is bigger than others makes me a scammer, but ok. Personally, I think it's quite nice when the 2fa email has the code in giant font so it's easier to pick out.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#325

Earlier quoted context omitted.

I do not believe this is a trade-off, I believe this behavior from corporate IT is a primary cause of the problem. I do agree that dealing with users is awful, but that doesn't justify solutions that only make things worse. The flashing cmd.exe windows are not drivers from Windows Update - this could have been the case as drivers shipped with Windows Update is a total security nightmare running arbitrary code with ad…

> Cisco Umbrella My current employer was somewhat recently purchased by a large, publicly-traded company and I had this installed on my work machine. Suddenly DoH was forced off by administrator policy and I had to use some specific internal IP for DNS. Which isn't strictly less secure but let's just say I would, even for my large, publicly-traded business, trust Mullvad more than Cisco.

The stupidity of the whole thing is that by creating these MiTM servers, they're creating a single point of security failure. Anyone who then compromises one of those servers, can with a little care, trick the entire organisation into downloading compromised executables from what they think is a trusted site.

Also when you're snooping on a conversation between myself or one of my servers and one of your employees you are impersonating me and intercepting my communications too! I did not sign your AUP to agree to this. Also if I happen to be in a two-party consent state at the time, and you're intercepting a VoIP call/Teams/Zoom with me, that's a crime.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#326

Earlier quoted context omitted.

All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com

My It department does mandatory phishing training every year, and then for the "test" e-mails, they spoof a domain and whitelist the DMARC on their side so it goes through. So we get e-mails from @microsoft.com and it's only if you dig in the metadata that you see it failed authentication. The only tell in the e-mail is checking the URL, which doesn't tell you much because tons of regular e-mails use tracker redirect…

My company does similar phishing thing.

Except their system adds extra headers related to the phishing… Wonder if they even know…

Thus, I created an Outlook rule to automatically move them to a dedicated folder… (;->

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#327

Earlier quoted context omitted.

I have firstname@lastname.email... people keep telling me that can't be right and don't i mean it ends with email.com?

I have a .ninja email and get the same a lot to the extend where I explicitly say "it ends in .ninja with no .com or anything". Usually use company-i-buy-from@mydomain.ninja whenever I make online purchases, and I had a guy from a small shop call me up and ask why I had an email with his company name on. Took some good fifteen minutes to explain him that I was legit and owned the domain. He was still reluctant in the…

I have used the company-i-buy-from in my email address I give the for over 20 years. It mostly works well, a couple of serious businesses had their data stolen and are now blocked and I use a secondary address for them if I still have a need. Never noticed a spammer would misuse the scheme, even though it would be extremely easy.

The funniest experience was when searching a VoIP provider. One had it in their terms that their name must not be part of the email address. Well, no chance to get my business then.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#328

Earlier quoted context omitted.

Yes, just what we need, retired people with a whole career of making income behind themselves taking another decent entry level job someone one just out of college can get. (No teaching credential needed for substitute teachers usually)

If a semi-retired engineer with 2-4 decades of work experience makes a better public high school STEM teacher, then I hope a lot more engineers do it as a semi-retirement gig. The aspiring career schoolteachers will just have to find a job in a field that is short-staffed, like registered nurses or one of the trades. I'm sure that comes across as "let them eat cake" to some Bernie moron, but going back to school for…

I am 100% opposed to immigration too.

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#329
post #109
post #77

Earlier quoted context omitted.

Only most of the amounts were tiny, so all the effort for the re-calculation was still needed for everyone (basically either building a payroll engine from scratch, or paying someone else to use theirs). You're right, that for most current employees, for the small amounts it actually is much simpler. You can just email and slip it into the regular payroll. It is the former employees for up to 15 years that make the c…

Thanks for the detailed answer. > It is the former employees for up to 15 years that make the contacting step difficult. They all need to provide bank/tax details. Give people 30 dollars extra on their way out, and only contact them when you used up that budget? (Should take care of the majority of cases?) > Edit: I should have said, I did see companies rounding all amounts up to some small amount, like $1, so your s…

I think when companies found out that they had an issue with their Payroll software calculations, they mostly tried to solve it as quickly as possible, to put a line in the sand - from that point onwards at least, no additional errors were being made. But they still had many years in the past, of issues which needed to be fixed.

I think what you're proposing probably would have worked for reducing the communication issues in the future for any employees who left after that. I didn't hear of anyone who did that, but that definitely doesn't mean it didn't happen. Likely no one thought of it because I would guess most people didn't expect it to take as long as it did to fix. That the people who left while the recalculation was going on would just be a few more compared to everyone who had left in the previous 7 or 10 or 15 years (I think different companies came to different opinions for the time period they needed to retrospectively fix).

Re: Want to piss off your IT department? Are the links not malicious looking enough?

#330
post #329
post #109

Earlier quoted context omitted.

Thanks for the detailed answer. > It is the former employees for up to 15 years that make the contacting step difficult. They all need to provide bank/tax details. Give people 30 dollars extra on their way out, and only contact them when you used up that budget? (Should take care of the majority of cases?) > Edit: I should have said, I did see companies rounding all amounts up to some small amount, like $1, so your s…

I think when companies found out that they had an issue with their Payroll software calculations, they mostly tried to solve it as quickly as possible, to put a line in the sand - from that point onwards at least, no additional errors were being made. But they still had many years in the past, of issues which needed to be fixed. I think what you're proposing probably would have worked for reducing the communication i…

It's a shame that the bureaucrats / politicians / voters who are responsible for these hard-to-comply-with rules will never bear the costs.
Post reply on HN