Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

381–390 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#381
post #245

A while ago my wife applied for a home equity loan. At some point I got a call from someone claiming to be from the bank she had applied through (I forget which one), calling to make sure I approved the loan since the home is in both our names. He asked for my name, which I gave him, and then the last four digits of my social security number, which I also gave him. He then proceeded to ask for my full social security…

A bank called me to ask me security questions. I said that I would call back using the number on the bank's website. They said (and the bank confirmed when I did call the number) that there is no way to be transferred to the security question people when I call the bank - the only way is for them to call me. I explained that that was poor security practice. They said that I should just look at the caller ID to see that it was the bank calling. It was useless trying to tell them about caller ID spoofing.

Re: Thanks FedEx, this is why we keep getting phished

#382
post #243

Earlier quoted context omitted.

Is it impressive though? They have about a 50% success rate delivering things to me across multiple addresses and I know other people who have had similar long term issues.

At one of my addresses FedEx will happily sell anyone overnight shipping and then just keep the parcel at the depot for a week until they have a driver who can actually make the trip. I have had like 6 very urgent packages delayed like this. Once my wife ordered something perishable and they pulled this then told her she had to drive into town and pick it up at the airport. I've also been nearly run off the road by F…

today I learned a new thing:

https://www.bikelaw.com/2017/07/punishment-pass-defined/

Re: Thanks FedEx, this is why we keep getting phished

#383
post #245

A while ago my wife applied for a home equity loan. At some point I got a call from someone claiming to be from the bank she had applied through (I forget which one), calling to make sure I approved the loan since the home is in both our names. He asked for my name, which I gave him, and then the last four digits of my social security number, which I also gave him. He then proceeded to ask for my full social security…

This method of data exfiltration is in Kevin Mitnick's book! He needed a daily pin that banks used to validate intra-bank communications. He called a bank, said that he needed to fax over loan forms from another branch for signing later that day (or something like that). He then asked the bank that he called for the daily PIN. They refused because he called them. He pointed out that he was sending sensitive data to them so they needed to provide the pin... and they did.

Re: Thanks FedEx, this is why we keep getting phished

#384

Earlier quoted context omitted.

Yeah when I was a shipping clerk, we had a pile of usernames and passwords for the Census Bureau's Automated Export System on sticky notes next to the shared computer because the password rotation and complexity requirements made it impossible to remember our passwords.

Oh, there are many fun games from the 90's where you must infiltrate some place and every computer has some version of "due to the password rotation requirements, this week's password for the South-East door is 1-2-3-4, effective from Monday" pasted into it. When the NIST added the bad rule into their ruleset (it was mostly a collection of bad rules at the time), it was already widely mocked in popular culture (well,…

> there are many fun games from the 90's where you must infiltrate some place and every computer has some [sticky note]

"Come to think of it, it's about time to replay Deus Ex again..."

Re: Thanks FedEx, this is why we keep getting phished

#385
post #243
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

Is it impressive though? They have about a 50% success rate delivering things to me across multiple addresses and I know other people who have had similar long term issues.

I'm in the same camp. The single time they actually delivered it to me without saying I wasn't home they had actually delivered it one street over.

I spent 72 hours waiting (3x24 periods they told me to wait and call back tomorrow while they "investigated") for a $1300 package. Initially they said it must have been stolen and its my loss, to which I said "no I was home and near the front door all day, you didn't deliver it". Pretty absurd they can't just look where he was when it was "delivered" and deal with it. Or maybe they can and they just don't bother.

Eventually the person actually called me using my number on the box and said it was delivered there.

Still no recourse from FedEx, whom I have not informed I got the package in the end.

Re: Thanks FedEx, this is why we keep getting phished

#386

Earlier quoted context omitted.

At one of my addresses FedEx will happily sell anyone overnight shipping and then just keep the parcel at the depot for a week until they have a driver who can actually make the trip. I have had like 6 very urgent packages delayed like this. Once my wife ordered something perishable and they pulled this then told her she had to drive into town and pick it up at the airport. I've also been nearly run off the road by F…

Strangely, I've had perishable medicine delivered to me (a biologic injection) for two years without a single hiccup by FedEx. They have been the most consistently reliable delivery service where I live (though the post office is pretty good too). My house is at the bottom of a hill that is difficult for rear wheel drive vehicles in winter. UPS, on the other hand, can go pound sand. They often refuse to deliver due t…

> They have been the most consistently reliable delivery service where I live (though the post office is pretty good too).

Every service relies on the USPS to some extent, which makes the Republican attempt to gut the organization so baffling. There's no replacement and nobody is looking to replace it.

From my perspective as an ex letter carrier, your personal experience with package delivery is determined almost entirely by whoever runs the local hub and handles last-mile. Unfortunately it's a McDonald's Assistant Manager kind of role; anyone truly competent will be able to find better work sooner or later.

Re: Thanks FedEx, this is why we keep getting phished

#387
post #200

Earlier quoted context omitted.

> have to type 10-20 per day Same problem here. My solution: Get a mouse with internal memory for macros, such as Natec Genesis GX78 (old, no longer available, but this is an example). Program your new password on one of the unused mouse buttons or in a different profile. Use the mouse to type the password.

Might be a good product to app-ify. Maybe a USB dongle that acts like a keyboard and controlled by your phone. Give it some sort of 1Password / Bitwarden integration. Could make it double as a YubiKey. Surely this exists already?

Separately from the password aspect, consider how convenient it may be to use your smartphone as a kind of re-reified "clipboard": Use the camera and on-device OCR to copy text, then "paste" it as a virtual keyboard connected over USB.

It's very niche, but in those rare situations it'll be a big time-saver compared to human transcription or the rigamarole of setting up some other kind of data channel.

Re: Thanks FedEx, this is why we keep getting phished

#388

Earlier quoted context omitted.

I have an Outlook rule to redirect these to junk.

I wish I could do that, but then that would impact my "scoreboard" on the anti-phishing tool and they would yell at me or send me to remedial "training" too. They really like to see that useless button pressed that just patronizingly tells me "Yes, this was a training exercise". At the moment in my current corporate email address this the number one source of spam, just all the internal phishing testing emails. It fe…

> I wish I could do that, but then that would impact my "scoreboard" on the anti-phishing tool and they would yell at me or send me to remedial "training" too. They really like to see that useless button pressed that just patronizingly tells me "Yes, this was a training exercise".

It's actually even a worse than that for our anti-phishing tool, somehow Outlook's processing triggers the tool to think that I've interacted with the email, but after several rounds of "our tool says you clicked a link" and my reply of "I 100% didn't, let me see some logs", they now seem to ignore notifications of me clicking on phishing test links. So a win for me, I guess?

Re: Thanks FedEx, this is why we keep getting phished

#389
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

My favorite was when they put my well-marked mail-order medicine right at the exit of the roof gutter pipe, instead of the front door. Sometimes it feels like the workers want to purposely cause chaos.

One part workers, 3 parts horrible management setting impossible metrics and bad incentives.

Re: Thanks FedEx, this is why we keep getting phished

#390
post #245

A while ago my wife applied for a home equity loan. At some point I got a call from someone claiming to be from the bank she had applied through (I forget which one), calling to make sure I approved the loan since the home is in both our names. He asked for my name, which I gave him, and then the last four digits of my social security number, which I also gave him. He then proceeded to ask for my full social security…

Similar story, I transferred a decent amount of money from one bank account to another (different bank). I thought nothing of it, but I got a call randomly from what appeared to be the receiving bank's 'fraud' phone number (based on Google). I picked up, and the person on the end had an extremely thick accent similar to scam callers. He started asking me if I had made a transaction recently (I said yes), then asked me to confirm this transaction if I would provide additional information about myself, including home address and social... I refused, and was told if I didn't my bank account would get locked!

Sure enough... I had to go down to the local branch to get my account unlocked, as well as prove the amount of money I was transferring was... available in the other account? Absolutely ridiculous. I don't even know what sort of fraud they were trying to prevent, as this wasn't a new bank account and I'd made transfers between them before.

Post reply on HN