Live data from Hacker News

Gone (Almost) Phishin'

ma.tt

41–50 of 93 posts

Re: Gone (Almost) Phishin'

#41
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

Microsoft is really bad with this. Login might be live.com or microsoftonline.com or maybe onmicrosoft.com. I went to report a vulnerability to their security portal this week and it redirected me to b2clogin.com. OneDrive email attachments link to, I kid you not, 1drv.ms, or maybe it was 1drv.com… Not to mention, they use .ms as if it’s their personal TLD, but obviously anyone can register a .ms domain. It’s like th…

Until this moment I assumed .ms was a Microsoft TLD, but indeed it is not https://en.wikipedia.org/wiki/.ms

Re: Gone (Almost) Phishin'

#42

I’ve found that just not answering any calls from unknown numbers (and having my phone just silence those calls so I don’t even see them) prevents all of this. If the caller is legitimate (e.g., new dentist office regarding an appointment) they can leave a voicemail. And if it isn’t spam and they aren’t willing to leave a voicemail and have me call the back, it probably wasn’t important in the first place. Sure, I ma…

This, my pixel marks almost all calls not in my address book as suspected spam or phishing.

Re: Gone (Almost) Phishin'

#43
post #24

As others have mentioned, one big issue is that every company does these things differently and just because someone texts you a link doesn't mean it's phishing, even though it feels shady. In Australia I have had calls by immigration officers on supressed numbers that wanted PII over the phone without being able to tell me what the purpose of the call is.

Wow, this is tricky. Even though you can look up the official number you will likely not get through to the same person.

Re: Gone (Almost) Phishin'

#44
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

Microsoft is really bad with this. Login might be live.com or microsoftonline.com or maybe onmicrosoft.com. I went to report a vulnerability to their security portal this week and it redirected me to b2clogin.com. OneDrive email attachments link to, I kid you not, 1drv.ms, or maybe it was 1drv.com… Not to mention, they use .ms as if it’s their personal TLD, but obviously anyone can register a .ms domain. It’s like th…

[deleted]

Re: Gone (Almost) Phishin'

#45
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

1Password has really been bugging me recently, all the emails they send have giant link buttons they want you to click without verifying where you're actually going

Re: Gone (Almost) Phishin'

#46
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

> I work with senior citizens and tried to explain how to parse the domain in the URL by looking for the first forward "/" after the "https://" and then scan backwards but they find that mental algorithm confusing and those instructions don't stick.

Have you tried some analogy which will be personal to them? Like describing the URL as a family tree: “com is the oldest ancestor, like you Mr Johnson. Then apple is your son Bill, and getsupport is your grandchild Cody. If you saw ml instead of getsupport, that would be a different grandchild, but still in your family. However, when you see phish and xyz before apple and com you can think ‘I don’t know those people, they aren’t my father and grandfather’”.

The idea is imperfect but I literally just thought of it. We could certainly come up with something better that might eventually work.

Thank you for working to keep vulnerable people safe from phishing.

Re: Gone (Almost) Phishin'

#47
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

I recall receiving an email from company X, warning me to not trust emails that said they were from X but didn't come from X.com. But the warning email itself did not come from X.com! They broke their own rules in the warning email.

It's been a while, so I cannot name and shame X...

Re: Gone (Almost) Phishin'

#48
post #31

> Apple Support lives on apple.com and getsupport.apple.com, nowhere else. Meanwhile: “Microsoft support uses the following domains to send emails: microsoft.com microsoftsupport.com mail.support.microsoft.com office365support.com techsupport.microsoft.com” [1] [1] https://learn.microsoft.com/en-us/troubleshoot/azure/general...

Also, Microsoft regularly sends me legitimate emails regarding "Microsoft Rewards" that are absolutely indistinguishable from phishing, like "Total Prize Drop is here! Your chance to win 1,000,000 USD cash grand prize or one of three customizable Mercedes-Benz cars!", complete with links to login pages and everything. So like this one, just as mail: https://xcancel.com/bing/status/2034720189003231410 The first time I…

https://xkcd.com/570/

Re: Gone (Almost) Phishin'

#49
post #41

Earlier quoted context omitted.

Microsoft is really bad with this. Login might be live.com or microsoftonline.com or maybe onmicrosoft.com. I went to report a vulnerability to their security portal this week and it redirected me to b2clogin.com. OneDrive email attachments link to, I kid you not, 1drv.ms, or maybe it was 1drv.com… Not to mention, they use .ms as if it’s their personal TLD, but obviously anyone can register a .ms domain. It’s like th…

Until this moment I assumed .ms was a Microsoft TLD, but indeed it is not https://en.wikipedia.org/wiki/.ms

Handy tip: all two-letter TLDs are country code TLDs. Doesn't matter if they're trendy in website names (.nu, .cc, .io, .co, .it, .at, .cx, youtu.be and so on)

In fact, here we have the ma.tt website, where the ".tt" is Trinidad and Tobago. Is Matt Mullenweg from Trinidad? No!

Re: Gone (Almost) Phishin'

#50
post #46
post #23

>When you get an email from Apple—or, really, anyone telling you to complete a digital security measure—check the URL they’re trying to send you to. Apple Support lives on apple.com and getsupport.apple.com, nowhere else. That advice is fine for the technically savvy but doesn't work for a lot of normal people who don't have the knowledge to mentally parse urls. https://getsupport.apple.com/customer?cvid=8c11bcc71f68…

> I work with senior citizens and tried to explain how to parse the domain in the URL by looking for the first forward "/" after the "https://" and then scan backwards but they find that mental algorithm confusing and those instructions don't stick. Have you tried some analogy which will be personal to them? Like describing the URL as a family tree: “ com is the oldest ancestor, like you Mr Johnson. Then apple is you…

For a simpler example:

“You ever watch MASH? Remember the main guy, Benjamin Franklin Pierce? He’s not the same guy as Benjamin Franklin, is he? You can tell because you don’t stop after the first part of the name you recognize. You have to go all the way to the end and look at the whole name.

Well, same here!”

Post reply on HN