Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

371–380 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#371
post #30

I found a Reddit post today about a German bank mailing USB sticks containing their new general terms and conditions: https://www.reddit.com/r/de/comments/1ax7ky3/milde_interessa... You can't make this up.

I will simply refuse to believe this is real. As a psychological defense mechanism. What the hell.

There's a reason why infosec is hard and why there's a hiring shortage.

Re: Thanks FedEx, this is why we keep getting phished

#372
post #89

Earlier quoted context omitted.

Healthcare companies in the US send the most scammy looking links for payment processing you’ve ever seen - things like my-healthcare-billing.net It’s insane.

I’m supposed to pay my semi-annual property taxes (on the order of ~thousands of USD) on a site that ends in .org instead of .gov, and nobody apparently sees anything weird or wrong with it.

id.me

Still can't believe it

Best hope the government of Macedonia remains friendly I guess

Re: Thanks FedEx, this is why we keep getting phished

#373

Earlier quoted context omitted.

Do you have any examples? I'm largely out of the Microsoft ecosystem these days, aside from the occasional Xbox usage.

Office.com redirects you to login.microsoftonline.com which isn't horribly bad, but is starting to get there. Now you have microsoft365.com and friends, too. At least when things were login.microsoft.com you could apply the "last part is definitive" now that heuristic is pretty useless. And if you watch the actual DNS requests during a login, whew. CDNs make it even worse, here's a few VALID requests from my DNS cach…

Also Azure AD and Entra ID and other parts of Microsoft 365 all use onmicrosoft.com, too. A fun bonus to that particular domain is the random meaningless to people GUID-derived tenant IDs in the second level. Knowing what is legitimate, and what is tied so a specific corporate tenant, seems impossible. Certainly helps Microsoft themselves avoid XSS problems, I'm sure, but greatly adds to the confusion of what is a legitimate M365 URL.

Re: Thanks FedEx, this is why we keep getting phished

#374

Wow, I thought this was a great post, and I'm just dumbfounded about how egregiously bad that first SMS was - FedEx might as well tell the recipient they want to customs duties wired to a Nigerian prince. But I also disagree with the general push of Troy Hunt's recommendations. That is, we should just take the base assumption that humans, generally, can't distinguish between real and phishing inbound messages. That's…

This is more restriction than necessary, and unkind to users who may be technically unsophisticated, distracted, sick that day, or just kinda dumb. Include a link, make it a part of the core domain, short, and prominent: https://example.com/contact . If the user isn't logged in, lead with a login flow explaining "If you received a message from us, login for details", and include a contact form, phone number, and if t…

> This is more restriction than necessary, and unkind to users who may be technically unsophisticated, distracted, sick that day, or just kinda dumb.

Couldn't disagree more. By sending outbound links in notifications we're only perpetuating the idea that it's OK to click those in the first place. It's hardly any more difficult to just open your browser yourself. I also don't like the idea that we're not willing to accept the absolute mildest of inconveniences, when on the flip side we have loads of stories of people's lives being completely ruined when their life savings are stolen by scammers. It'd be like telling people not to lock their doors because that adds 5 seconds to the time it takes to enter your house.

Re: Thanks FedEx, this is why we keep getting phished

#375
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

The Walt Disney Company did exactly this when I was there, and everyone dreaded it. Did nothing but waste time.

Re: Thanks FedEx, this is why we keep getting phished

#376

Earlier quoted context omitted.

I love how those emails have extra metadata in the headers like "X-Phishing-Test: True"

I have an Outlook rule to redirect these to junk.

I wish I could do that, but then that would impact my "scoreboard" on the anti-phishing tool and they would yell at me or send me to remedial "training" too. They really like to see that useless button pressed that just patronizingly tells me "Yes, this was a training exercise".

At the moment in my current corporate email address this the number one source of spam, just all the internal phishing testing emails. It feels like the attempted cure is worse than the disease and I hate getting so much useless trash.

Re: Thanks FedEx, this is why we keep getting phished

#377

Earlier quoted context omitted.

I had video of them pulling into the driveway and leaving without getting out of the vehicle and saying "no one was home." I'm also in the video.

That sounds like internal verification uses GPS. So in most cases it's going to be the customer's word against the astonishingly lazy driver's evidence.

I called them and questioned them about this - they didn't even come down my street, and yet claimed that they "attempted delivery". The customer service person was honest enough to say there was no code for the driver to say "too busy, can't meet my unrealistic targets".

Re: Thanks FedEx, this is why we keep getting phished

#378

Earlier quoted context omitted.

UPS is up there, too. I still get text messages about an old address on an account I can't log into for...reasons. (Special characters sound plausible! And of course the password reset flow doesn't work.) Wonder if they share a vendor.

I can’t believe it’s 2024 and we are still seeing bugs with handling “special” characters. Unicode has been here for how long? Robust string handling is supported in every language. There is no such thing as a special character. My name should be able to contain Chinese characters. My password should be able to contain emojis. What is this Stone Age shit still running on companies’ backends?

Companies aren’t rewriting their entire stack or even upgrading across major versions basically ever.

Re: Thanks FedEx, this is why we keep getting phished

#379
post #307

Earlier quoted context omitted.

I don't think Troy Hunt is recommending what you're suggesting at all? The very beginning of the post starts with: > but I'm a smart human so I don't fall for this (that's a joke, read why humans are bad at URLs). It's clear that he thinks relying on heuristics to distinguish scammy URLs is not a scalable long term approach.

Two things: 1. The entire article is about a (surprisingly) legit FedEx SMS looking totally spammy. My point is that we should take "looking totally scammy" completely out of our vocabulary, and pointing out similarities or differences in scam vs real notifications only furthers the notion that they're distinguishable in the first place. Again, to emphasize, I still think this overall was a great article highlighting…

On that second point that is what Troy Hunt shows doing: he goes to the FedEx website and finds no indicator of any duties/taxes in the official package tracker. This seems a case where the Australian customs team doesn't have feature access to the main website to service this case and are instead badly routing around it.

I think this is the core point Troy Hunt is trying to show, but I don't think Troy Hunt makes it explicit enough that this org chart/processes problem is the real problem and the thing FedEx should most fix because you can't rely on incoming notifications to not look scammy, real notifications are indistinguishable from fake ones even if the real ones weren't doing so horribly to begin with. Troy Hunt often makes that point better in other posts (see the old, long series on "Extended Validation" certificates for an example) and maybe just assumed that message was clear rather than harping on it and then resummarizing it in bold text and blinking lights this post.

Re: Thanks FedEx, this is why we keep getting phished

#380
I just read an article detailing how thousands of Americans fall for scams run by Mexican cartel proposing to buy their timeshare from them. Americans buying Mexican timeshares is a big thing apparently. One guy kept getting pulled into the scams eventually paying them (and losing) $1.8MM. Others had lost tens or hundreds of thousands to the same type of scam.

Every time someone supposedly bought their timeshare there would be a bank fee or tax they would have to wire money for. The guy who lost $1.8MM wired money 90+ times.

These are lawyers and doctors, educated people getting ripped off.

Post reply on HN