Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

461–470 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#461
post #439
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

I bought an OP-1 from teenage engineering years ago and fedex delivered it inside of the mailbox. USPS removed the fedex package from the mailbox and impounded it at our local USPS post office without ever notifying me. After 1-2 months of waiting/assuming the package had been stolen, I call the USPS office and asked if they somehow had the package in their custody/possession and, lo-and-behold, they did (in the "und…

The mailbox? On your property? that you paid for an installed (or bought off the previous owner), is government/usps property and they'll steal a parcel that someone else has delivered to it?

That's insane lmao

Re: Thanks FedEx, this is why we keep getting phished

#462

Earlier quoted context omitted.

You can tell it's legit if they charge you $2 extra for a credit card instead of a bank transfer lol

Most have gone that way, but a few were still letting you put your entire property tax on credit card with no fee whatsoever as recently as last year. Woohoo free miles! Sometimes the fee is so low that even when they do charge it, it's worth using the credit card.

Yeah, I've encountered sites that charge a 1% fee for using a credit card, but I get 1.5% cash back.

Re: Thanks FedEx, this is why we keep getting phished

#463
post #34

Corporates are shockingly incompetent at this sort of stuff. Seriously just use your main domain for URLs. For me at least that clears up 99% of this. I dont want to memorise a list of valid mystery domains for each shipper. Is that really too much to ask?

It is. If they use their main domain, their normal corporate email will get blocked by anti-spam filters. So everyone uses a different, unrelated domain for bulk mails.

So use a different domain for corporate email. The only reason not to is if you are prioritizing the identifiability of your corporate email over the identifiability of your actual customer-facing operations.

Re: Thanks FedEx, this is why we keep getting phished

#464

Earlier quoted context omitted.

PSA: If you are of a certain age, the last four digits might be roughly all of the useful entropy in your SSN. Be careful with them. Before 2011, the first three digits indicated the office that issued the number and the middle two (the "group number") were used in a publicly-known sequence. The Social Security Administration helpfully published periodic lists of the highest group number reached by each office. This…

Tangentially related - wouldn't that mean that if you are an immigrant, then you are at least theoretically somewhat safe from that enumeration type of an attack? Because if I got my SSN in my late teens, then my date of birth shouldn't mean much at all to anyone trying to use that method you describe, right?

Your date and place of birth would not be helpful, but an analogous attack may be possible. The key factors are when and where you applied and that the SSN was issued before June 25, 2011.

Re: Thanks FedEx, this is why we keep getting phished

#465
post #22

Earlier quoted context omitted.

But in a modern day and age, when aren’t you expecting a package? Nearly 100% of the time, I am expecting a notification from Canada Post or Amazon (FedEx less frequently, but still). Even outside of that, you can often predict when people are expecting a package. Christmas. After various sales weeks.

> But in a modern day and age, when aren’t you expecting a package? When you’re not constantly buying things online. Most people in the world aren’t expecting packages “nearly 100% of the time”.

The presence of "most people in the world" really doesn't contribute to this discussion.

Re: Thanks FedEx, this is why we keep getting phished

#466
post #436

Earlier quoted context omitted.

My UK bank semi-regularly cold-calls me and ask me to authenticate by providing personal information. When I decline they readily tell me instead to call some number available on the bank website. So they not only are incompetent, they actually know it.

why? isn't getting the number from the website the right action? you can verify that you have the bank website, get the right number, and i presume even go to the bank branch to get the number in person, and then save the number as it should not change. or are you referring to the call itself? i wonder why they need to do that.

It is the right action, and they should say exactly that when they call: we need to talk to you so call us at the number in our website.

Instead they try to do the wrong unsafe thing, but when pointed out they switch the script. So they can't even claim ignorance of basic security .

Re: Thanks FedEx, this is why we keep getting phished

#467

Earlier quoted context omitted.

Does it require installing 3rd party software on the host machine? No, it identifies as a keyboard. It also defaults to generating a password that will use the same scancodes on (most?) western keyboard layouts so that computers configured to default to e.g. QWERTZ or AZERTY will still result in the same password.

How do you tell it which password to type?

IIRC there is a maximum of two; one on short-press and one on long-press.

Re: Thanks FedEx, this is why we keep getting phished

#468

Was just dealing with similar nonsense from BMO Harris bank yesterday. I got this text (numbers changed): "FreeMsg: BMO Fraud Ctr: 18774352371 Case 19684358 Did you attempt $4.00 at NYTIMES with card x1234? Reply YES or NO" The 1234 did match the last 4 digits of my card - not the first four, a common trick - but the rest of the message is, as Troy says, Dodgy AF. They then followed up with a similar email, prompting…

I got an email from BMO the other day that I had changed my password. I immediately tried to log in (with my current password) and it worked fine. Never got any other communication from them about it, or even a fraud alert after I supposedly "changed" the password.

I moved to Schwab a while ago, so I'm not sure what I would've done to change the password. Schwab is much better, by the way. BMO is a joke. I never thought I would say this, but I miss Bank of the West.

Re: Thanks FedEx, this is why we keep getting phished

#469

Earlier quoted context omitted.

> My password should be able to contain emojis. It's probably better if it shouldn't. It's generally better to prevent passwords from containing characters that can't be entered on a decent proportion of devices you may encounter. Emojis are particularly problematic because new ones keep being added which require OS upgrades, and you might find yourself needing to log in from another device that just doesn't support…

With built in emoji entry keywords in every modern OS how many devices are left that can't type emoji? Even if you plan to restrict to Unicode Version N - 1 or N - 2 where N is the current version to avoid "user can't type password on older hardware", the proportion of emoji you can reliably type today on just about any device is huge.

I'm pretty sure that most of the on-screen keyboards for TV / streaming device platforms don't support emoji.

(I've spent about 6 years of my career running video streaming services... People watch a lot of video on TVs, it turns out, so you probably don't want to let them put these sorts of characters into their passwords when they sign up on mobile or computer devices.)

Re: Thanks FedEx, this is why we keep getting phished

#470

Earlier quoted context omitted.

People are still using Windows 7 -- it's the third most popular Windows version after 10 and 11 -- and it only supports Unicode 5.1. Emoji weren't officially supported until Unicode 6.0, though there are a subset of current emoji (less than a quarter) that work on Windows 7 in practice. Meanwhile the current standard is 15.1. There's no security or convenience necessity whatsoever for supporting emoji in passwords, b…

Windows 7 market share is barely at 3% on the internet per statcounter.com. Third place doesn't mean "popular", especially not right now. There's quite a bit of convenience, and some concomitant security, to using emoji in passwords. Emoji are high entropy code points that are easily visually distinguishable across most language boundaries. A "short" password of just emoji is going to have way higher entropy and be w…

[deleted]
Post reply on HN