Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

341–350 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#341
post #243

Earlier quoted context omitted.

Is it impressive though? They have about a 50% success rate delivering things to me across multiple addresses and I know other people who have had similar long term issues.

At one of my addresses FedEx will happily sell anyone overnight shipping and then just keep the parcel at the depot for a week until they have a driver who can actually make the trip. I have had like 6 very urgent packages delayed like this. Once my wife ordered something perishable and they pulled this then told her she had to drive into town and pick it up at the airport. I've also been nearly run off the road by F…

Strangely, I've had perishable medicine delivered to me (a biologic injection) for two years without a single hiccup by FedEx. They have been the most consistently reliable delivery service where I live (though the post office is pretty good too). My house is at the bottom of a hill that is difficult for rear wheel drive vehicles in winter.

UPS, on the other hand, can go pound sand. They often refuse to deliver due to weather, then force me to either drive two hours round trip to their distribution center, or charge me to pick it up at the local UPS store.

When when FedEx couldn't get their truck to my house due to road conditions, they were totally fine with my picking it up at their store.

Re: Thanks FedEx, this is why we keep getting phished

#342
post #296

Earlier quoted context omitted.

Yeah, in my experience FedEx drivers absolutely LOVE saying they “attempted delivery of my package, but nobody was home,” so I have to go get it from the depot. But I 100% was home, working from home all day, and they 100% never came.

I had video of them pulling into the driveway and leaving without getting out of the vehicle and saying "no one was home." I'm also in the video.

That sounds like internal verification uses GPS. So in most cases it's going to be the customer's word against the astonishingly lazy driver's evidence.

Re: Thanks FedEx, this is why we keep getting phished

#343
post #173

Earlier quoted context omitted.

If your company is not following the NIST recommendation, they are incompetent, and will be held liable in case of a breach This is a stretch. Liable? Please show the case law, or the legislation. (My statement has no relevance to the validity of NIST's recommendations)

Not directly. However NIST is admissible in court and so if someone sues there is now evidence that they should have known better.

Anything is admissible in court, the judge merely has to allow it.

There are 1000s of such organizations, and many conflict with each other.

My point is, it's inaccurate to say you are liable for not following NIST. I could easily say you could be liable, for not following me.

Does that make it so? No.

Re: Thanks FedEx, this is why we keep getting phished

#344

Earlier quoted context omitted.

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

The lack of use of a non-corp domain, the typos and the use of shortened links does sound like a form of incompetence, probably at the management layer. However, the password rotation requirement was until relatively recently something that many IT auditors would actually recommend , even though it leads directly to bad user password choices. In fact I wouldn't be at surprised to learn that was still the case in a lo…

Yep. That leads directly to passwords like:

ReallyLongP@assword$01, ReallyLongP@assword$02, ReallyLongP@assword$03, and so on.

Re: Thanks FedEx, this is why we keep getting phished

#345
post #243
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

Is it impressive though? They have about a 50% success rate delivering things to me across multiple addresses and I know other people who have had similar long term issues.

They certainly can be quite impressive, I recently had something delivered from China I bought through Alibaba to South Africa, shipping cost less than 5USD and it arrived in about 13 days, 1 day less than the maximum estimate.

In my case I got an email about customs and tax payment which was needed, but the link was clearly to fedex.com.

Re: Thanks FedEx, this is why we keep getting phished

#346

Earlier quoted context omitted.

> In many companies, this would be a P0 "don't go home until it's fixed" production emergency if a bug like this crept in to the software. Would it, really? P0 would probably be "10% of our customers can't submit an order." Or "20% of our vendors are experiencing 404s."

If 10% of customers have passwords that now can't log in and submit orders, that would be an emergency. We're taking OP's word for it that FedEx doesn't allow certain characters as passwords (actually, from the description, it seems more like FedEx only allows specific characters which is even worse). If either of those are true, it is most certainly a defect. Whether FedEx treats that defect as an emergency is up to…

> it seems more like FedEx only allows specific characters which is even worse)

If I read it right it sounds even worse. Fedex allows the characters and then random stuff just breaks.

It is much preferred to get a simple "only english alphabet and numbers please" warning message when you are trying to set the password than not getting any warning and then things breaking.

Re: Thanks FedEx, this is why we keep getting phished

#347

Earlier quoted context omitted.

I can’t believe it’s 2024 and we are still seeing bugs with handling “special” characters. Unicode has been here for how long? Robust string handling is supported in every language. There is no such thing as a special character. My name should be able to contain Chinese characters. My password should be able to contain emojis. What is this Stone Age shit still running on companies’ backends?

> My password should be able to contain emojis. It's probably better if it shouldn't. It's generally better to prevent passwords from containing characters that can't be entered on a decent proportion of devices you may encounter. Emojis are particularly problematic because new ones keep being added which require OS upgrades, and you might find yourself needing to log in from another device that just doesn't support…

With built in emoji entry keywords in every modern OS how many devices are left that can't type emoji? Even if you plan to restrict to Unicode Version N - 1 or N - 2 where N is the current version to avoid "user can't type password on older hardware", the proportion of emoji you can reliably type today on just about any device is huge.

Re: Thanks FedEx, this is why we keep getting phished

#348
post #332

Earlier quoted context omitted.

I assume you know that you can open a claim? They'll either find your package really fast, or will have to pay its full value. Often the vendor has to initiate the claim. If the vendor doesn't want to open a claim, refund. If the vendor doesn't want to refund, chargeback.

Be careful about those chargebacks. I bought two new pixel phones directly from Google and only one arrived. Google support was of course awful and Fedex did absolutely nothing outside of asking me what color the phone was. lol I ended up reversing charges for the missing phone and Google immediately wrecked me - I was using Fi at the time so they killed my cell service and killed my ability to use Google Pay for any…

Did you contact the card company about this? Or your bank? Or a lawyer? Just curious. Card company should have someone who works on goog account

Re: Thanks FedEx, this is why we keep getting phished

#349
Compare this to USPS, which is so secure that I can't get back into the account I created to manage deliveries for my home address, and there is absolutely no recourse. (no customer or technical support, going into a USPS office does nothing, etc) I still receive e-mails at my old e-mail address about deliveries coming to my home, but I can not turn them off, change the e-mail address, etc.

Re: Thanks FedEx, this is why we keep getting phished

#350

Earlier quoted context omitted.

Most companies don't like rewriting their code. If it ain't broke, don't fix. (Weird password issues don't count as broke.) There's no guarantee, after all, that the rewrite won't have major edge cases and mistakes of it's own. The upper layer might change now and then, to give a veneer of modernity. But just like Windows being built on 90s technology, the stuff underneath could be even more ancient.

A software that can't accept a % as part of your password is absolutely, positively broken--in any industry or application. In many companies, this would be a P0 "don't go home until it's fixed" production emergency if a bug like this crept in to the software. We need to stop excusing long-standing bugs in horrible legacy software just because they are long-standing.

Unfortunately the InfoSec Red Team determined that % in a password could be an attempt at an SQL Injection Attack and the Security Priority is to not fix the current behavior and instead other password checks in the company should also start erroring for % and other such "power characters" used in attacks.
Post reply on HN