I know it's a joke and I had a sensible chuckle, but if you want to routinely use it at work, just keep in mind that it's probably gonna make things worse. Since you can't exhaustively enumerate every good thing or every bad thing on the internet, a lot of security detection mechanisms are based on heuristics. These heuristics produce a fair number of false positives as it is. If you bring the rate up, it just increa…
I think the lesson here is that any link in an email is bad. We should just block all of them.
Want to piss off your IT department? Are the links not malicious looking enough?
41–50 of 335 posts
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#42Earlier quoted context omitted.
I think the lesson here is that any link in an email is bad. We should just block all of them.
Why not address the problem at its real source and just block emails entirely?
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#43All of this reminds me of a hilarious situation at a previous employer. As is standard corporate practice, they used to tell people to inspect links by hovering over them to confirm that they lead to the official website of the sender. People kept falling for phishing links though, so they got a Trend Micro device to scan emails, which also rewrote every link in it to point to their URL scanning service, which means…
I had the opposite funny experience. When I worked for Global MegaCorp, they would occasionally send out phishing emails and if you clicked on a link it would be recorded and you would have to do trainings if you got fooled a couple times. Eventually everyone learned to stop clicking on links on emails. That's good. However, they sent out a yearly survey to get feedback from all the employees and no one clicked the l…
Sounds like something a phisher would do. Better not click.
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#44Re: Want to piss off your IT department? Are the links not malicious looking enough?
#45Re: Want to piss off your IT department? Are the links not malicious looking enough?
#461. Make a site like this.
2. Wait for people to try it out with an URL that goes to a significant site (bank, social media, email, etc.)
3. Allow a bit of normal use, then secretly switch the link so that further visitors land on a corresponding phishing site.
4. Having just dismissed a bunch of "obviously fake" warning signs, people may be less alert when real ones arrive.
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#47All of this reminds me of a hilarious situation at a previous employer. As is standard corporate practice, they used to tell people to inspect links by hovering over them to confirm that they lead to the official website of the sender. People kept falling for phishing links though, so they got a Trend Micro device to scan emails, which also rewrote every link in it to point to their URL scanning service, which means…
I had the opposite funny experience. When I worked for Global MegaCorp, they would occasionally send out phishing emails and if you clicked on a link it would be recorded and you would have to do trainings if you got fooled a couple times. Eventually everyone learned to stop clicking on links on emails. That's good. However, they sent out a yearly survey to get feedback from all the employees and no one clicked the l…
Handles all the phishing concerns, except that participation was either low or the feedback was negative, which would lead to the leaders issuing subtle threats to the team about how they'd find out the involved folks and fire them. If you tried to uninstall it, it'd be back in a few hours through policy management software (jamf and its ilk). On the internal discussion forums, they'd nuke threads talking about how to disable that software.
So, in the end, people just started giving the best possible feedback regardless of the team or manager performance. I never really needed those threads, all I needed was tcpdump and then blocking its domain in the hosts file :)
Re: Want to piss off your IT department? Are the links not malicious looking enough?
#48Re: Want to piss off your IT department? Are the links not malicious looking enough?
#49Earlier quoted context omitted.
Not going to lie, I was expecting this[1]. Maybe it's just not done on HN. 1: https://pc-helper.xyz/scanner-snatcher/session-snatcher/cred...
Fantastic link, very educational.