Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

361–370 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#361

Earlier quoted context omitted.

I ordered a computer from Southern California, they shipped it to Texas, Florida, Maine, and then back to Northern California. My last two orders were just stolen from someone at FedEx. They got the shipment, but it never left the facility after that. Customer service is an offshore apology machine that can't help with anything. I used to prefer fedex, but the standard of service is so subpar I go out of my way to av…

I assume you know that you can open a claim? They'll either find your package really fast, or will have to pay its full value. Often the vendor has to initiate the claim. If the vendor doesn't want to open a claim, refund. If the vendor doesn't want to refund, chargeback.

Only if the package is insured. That's around 1% of the declared value of the package, so many/most vendors don't opt for it.

Re: Thanks FedEx, this is why we keep getting phished

#362
I've somewhat convinced myself that someone in the postal service is leaking information about pending parcels to scammers (or the scammers have access to some servers). Whenever I'm expecting a package the number of phishing attempts in my email skyrockets. Period of no packages - a lot less attempts. Waiting for a new package? Phishing emails ramp up again.

Re: Thanks FedEx, this is why we keep getting phished

#363
post #245

A while ago my wife applied for a home equity loan. At some point I got a call from someone claiming to be from the bank she had applied through (I forget which one), calling to make sure I approved the loan since the home is in both our names. He asked for my name, which I gave him, and then the last four digits of my social security number, which I also gave him. He then proceeded to ask for my full social security…

> He asked for my name, which I gave him, and then the last four digits of my social security number, which I also gave him. He then proceeded to ask for my full social security number, at which point alarms started going off in my head and I started sweating about even giving the last four digits to a stranger who had called me out of the blue.

I'm super paranoid about even the last four. The first five digits of an SSN were algorithmic for most of US history, and still mostly are but a tiny bit more random entropy, and can be narrowed down with mostly only the city in which you were born and what year. You can often use basic k-means clustering to find it even without that information. More often than not entire families share the first five (or close to it) and you only need to phish one family member to k-means cluster the five digits for the rest.

The last four are more often than not the most significant digits in terms of identification and entropy. Masking the rest is almost silly for most Americans. Our masking schemes have actually made phishing easier because people feel safer sharing just the last four, when for most those are the only four that matter.

SSN was never intended to be a secret so its design is horrifyingly bad for something that has come to be a huge secret in banking and healthcare and so many other industries. Recent SSN changes have made it a little better for anyone born after roughly 2010, increasing somewhat the entropy in the first five, but the rest of us have problems that we can't solve easily and banks should be ashamed they helped lead us to these problems.

Re: Thanks FedEx, this is why we keep getting phished

#364
And Amazon emailing me about my package due to arrive today. Clicking the link is right there and very convenient to find out which one. They won't tell me which package because then gmail will be able to know what I'm buying (which I'm fine with).

These emails are the _exact same form_ that a phishing email would take.

Re: Thanks FedEx, this is why we keep getting phished

#365

Earlier quoted context omitted.

> My password should be able to contain emojis. It's probably better if it shouldn't. It's generally better to prevent passwords from containing characters that can't be entered on a decent proportion of devices you may encounter. Emojis are particularly problematic because new ones keep being added which require OS upgrades, and you might find yourself needing to log in from another device that just doesn't support…

With built in emoji entry keywords in every modern OS how many devices are left that can't type emoji? Even if you plan to restrict to Unicode Version N - 1 or N - 2 where N is the current version to avoid "user can't type password on older hardware", the proportion of emoji you can reliably type today on just about any device is huge.

People are still using Windows 7 -- it's the third most popular Windows version after 10 and 11 -- and it only supports Unicode 5.1.

Emoji weren't officially supported until Unicode 6.0, though there are a subset of current emoji (less than a quarter) that work on Windows 7 in practice.

Meanwhile the current standard is 15.1.

There's no security or convenience necessity whatsoever for supporting emoji in passwords, but inconsistent OS support is an excellent reason against it.

Re: Thanks FedEx, this is why we keep getting phished

#366
FedEx is trash but this kind of handling of these kinds of communications is so common it's disgusting. I say it all of the time too. "No wonder people get scammed." We get security trainings at work or get things like "_company_ will NEVER ask for your password" then they immediately violate their own rules.

It's absurd.

Re: Thanks FedEx, this is why we keep getting phished

#367
post #307

Wow, I thought this was a great post, and I'm just dumbfounded about how egregiously bad that first SMS was - FedEx might as well tell the recipient they want to customs duties wired to a Nigerian prince. But I also disagree with the general push of Troy Hunt's recommendations. That is, we should just take the base assumption that humans, generally, can't distinguish between real and phishing inbound messages. That's…

I don't think Troy Hunt is recommending what you're suggesting at all? The very beginning of the post starts with: > but I'm a smart human so I don't fall for this (that's a joke, read why humans are bad at URLs). It's clear that he thinks relying on heuristics to distinguish scammy URLs is not a scalable long term approach.

Two things:

1. The entire article is about a (surprisingly) legit FedEx SMS looking totally spammy. My point is that we should take "looking totally scammy" completely out of our vocabulary, and pointing out similarities or differences in scam vs real notifications only furthers the notion that they're distinguishable in the first place. Again, to emphasize, I still think this overall was a great article highlighting the ineptitude of FedEx sending such egregiously bad notifications in the first place

2. Hunt says exactly this in the article "But if I were to take a guess, they've merely blocked the tip of the iceberg. This is why in addition to technical controls, we reply [sic] on human controls which means helping people identify the patterns of a scam: requests for money, a sense of urgency, grammar and casing that's a bit off, add [sic] looking URLs." My point is we should stop "helping people identify patterns of a scam". We should instead just teach people to treat all incoming notifications as suspect and to never follow a link/phone number from an incoming message.

Re: Thanks FedEx, this is why we keep getting phished

#368
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

I've noticed that Microsoft themselves aren't helping this right now. M365 seems to default to using random-tenant-guid.onmicrosoft.com for a lot of these transactional emails like password changes even though the official account.microsoft.com is fully multi-tenant aware and most Microsoft guidance tells you to always go directly to account.microsoft.com. These transactional email mistakes seem like another case of Microsoft accidentally exposing problems in their org chart to external customers. I imagine it has something to do with the wild rewrites from old Azure AD to new "exciting brand" Entra ID and other such shenanigans combined with Microsoft's willingness to bend over backwards to bad IT administrators and letting them set bad defaults (such as "just us the .onmicrosoft.com GUID instead of a real domain"), because companies love to pay them good money for the "control" to do stupid things in Group Policies and corporate configuration.

Combined with the fact that the largest single source of spam I'm seeing right now is also coming from random tenant GUIDs .onmicrosoft.com (is Azure really missing that much SMTP security for random M365 tenants?) and this sort of corporate anti-training users to follow bad transactional email links, it certainly feels like we are in a perfect storm of M365 phishing.

Re: Thanks FedEx, this is why we keep getting phished

#369
post #77

Earlier quoted context omitted.

If you give me your mailing address, I'll arrange it that the bank will mail you one, too. Just be sure to use the included NOTVIRUS.EXE viewer for best experience.

In your fantasies. It is of course in the responsibility of the bank to check if this is virus free. I am using Linux anyway.. No autorun.exe here. Is this still a thing with Windows?

The problem isn't the bank verifying that the USB stick is clean; the problem is that the bank is distributing info in the exact same way that APTs would try to compromise an important target.

Hyperbole, but it's like a bank employee calling you from an unknown number and asking for your email password so they can make sure their communications about your mortgage application don't go to the spam folder.

Re: Thanks FedEx, this is why we keep getting phished

#370
I bought insurance online. Some days later I got a super dodgy email telling me I should sign up for an online portal. The link was a mess and linked to a different insurance provider.

I called my provider. Turns out the actual insurance is handled by a sub-provider that works for a different (major) insurance... WTF

Post reply on HN