Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

41–50 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#41

I know this comes down to institutional incompetency, but at some point there was a singular human person putting the template content the SMS message in question was generated from into some computer system somewhere and I genuinely wonder what was going on in their head that made them string the words together in this way. You'd have to give it a true, earnest shot to make it worse.

> I know this comes down to institutional incompetency

"Incompetency" is an interesting word.

The old maxim about incompetence versus malice suggests a binary choice.

I prefer the more nuanced take that there is a spectrum of positions between the two, and other dimensions that describe a cluster of intents, both conscious and unconscious.

Take the UK Post Office scandal where we see incompetence layered on top of malice, layered on top on incompetence. In some organisations obviously deliberately harmful positions are written into "policy". Often this comes under "PR" [fn:1]. More and more "AI" will be used to disguise malintent and deflect scrutiny.

In the final episode of the ITV dramatisation [0], Alan Bates (played by Toby Jones) delivers an absolutely shocking, knock down line. When talking about incompetence and evil he says: "They're the same thing" At some point there is no difference between incompetence and evil. For a deeper psychological discussion of that listen here [1].

[0] https://en.wikipedia.org/wiki/Mr_Bates_vs_The_Post_Office

[1] https://cybershow.uk/episodes.php?id=23 (from 39:20)

[fn:1] Edward Bernays seminal definition of public relations outlines a creed of deception, manipulation and disinformation which is antithetical to security [2].

[2] https://en.wikipedia.org/wiki/Public_Relations_(book)

Re: Thanks FedEx, this is why we keep getting phished

#42

Your security is increasing at risk from organisations and corporations whose own grasp of security is appalling. Because instead of dealing with it they externalise risks and consequences onto the public and customers. Even worse, is where attempts to query that security is actively punished . This is typical now. Listen here (at 42:20) with an example regarding the UK NHS whose incompetence plays directly into the…

Since the link to this podcast is in your profile, you're affiliated with it, right?

Yes

Re: Thanks FedEx, this is why we keep getting phished

#43
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Did you click on the "Report Phishing attempt" button installed by your IT center in your mail client?

Sorry for the probable sarcasm. In a company that size, if the IT center does not provide a means to report phishing attempts then there are more serious problems than a dodgy email campaign.

Re: Thanks FedEx, this is why we keep getting phished

#44

I found a Reddit post today about a German bank mailing USB sticks containing their new general terms and conditions: https://www.reddit.com/r/de/comments/1ax7ky3/milde_interessa... You can't make this up.

Some German banks created paid storage service with multiple plans available. They are required to deliver documents to their customers but managements have massive brainfuck about the requirement and the most absurd solutions and ideas are being sold to them.

Re: Thanks FedEx, this is why we keep getting phished

#45
post #36
post #30

Earlier quoted context omitted.

I will simply refuse to believe this is real. As a psychological defense mechanism. What the hell.

Clearly the safer option is sending the terms via CD https://t3n.de/news/sparkasse-digital-strategie-cds-per-post... Since no-one has a CD drive in their computer anymore, the security risk is negligible

The CD contains PDF with scanned terms and conditions?

Re: Thanks FedEx, this is why we keep getting phished

#46
post #43
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Did you click on the "Report Phishing attempt" button installed by your IT center in your mail client? Sorry for the probable sarcasm. In a company that size, if the IT center does not provide a means to report phishing attempts then there are more serious problems than a dodgy email campaign.

I wanted to, but I could not find it. It turn out I could not see the "report phishing" button because of an Outlook glitch. Thanks Microsoft.

Re: Thanks FedEx, this is why we keep getting phished

#47

Earlier quoted context omitted.

There's an EU law demanding such documents to be delivered on a "durable medium". Some banks and financial institutions may have a strange approach to those, even though email attachments seem to be enough for others.

I've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.

https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...

Re: Thanks FedEx, this is why we keep getting phished

#49
DHL, FedEx, and UPS are experts in overcharging to process a form and not caring about customers. Duty and VAT are usually low compared to this processing fee, and shipping has already been paid. Here is the catch in the EU, this simple duty form can be processed by the receiver, an agent (some related to the carrier), or an attorney-in-fact of the receiver. The big three carriers (and many others) threaten you if you refuse to use them.

At the end of the day, they don't care if we get phished or scammed; it is all of customs confusion. Next time process your customs form, you will realise how much money you will save, and the form only has less than 8 fields, the Union Customs Code is easy to read.

Re: Thanks FedEx, this is why we keep getting phished

#50
post #6
post #2

Suggest Law: If a company's electronic notification to you is so phishy that a "reasonable man" would have obvious cause to doubt its legitimacy, then all financial and legal consequences of ignoring it are on the sender . Edit: " sender " here refers to the sender of the electronic notification .

Any time the law sets things like "reasonable" it's a quagmire. For every utterance of "reasonable" in law you can be sure over $1B of laywer fees have been (or will be) spent.

I think the answer here is "don't do things that are borderline (un)reasonable"
Post reply on HN