Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

471–480 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#471
post #444

Earlier quoted context omitted.

At one of my addresses FedEx will happily sell anyone overnight shipping and then just keep the parcel at the depot for a week until they have a driver who can actually make the trip. I have had like 6 very urgent packages delayed like this. Once my wife ordered something perishable and they pulled this then told her she had to drive into town and pick it up at the airport. I've also been nearly run off the road by F…

> just keep the parcel at the depot for a week until they have a driver who can actually make the trip. Depot workers can get up to the weirdest stuff. One time I was returning unused product (oil well perforating guns, a UN 1.4D explosive device) via Yellow Freight. I handed over the cases and signed all the appropriate paperwork to handover custody at the depot and went on about my day. The supplier called me ~10 d…

One of the big problems I find in the shipping industry is the reliance on insurance. The idea that most packages are insured or easily replaceable. When I was a bit younger and doing some seasonal postal work in a processing plant this was the mentality. The mentality being that sometimes things will go wrong and ruin a package, but hey, whatever. Machines would sometimes destroy a package, packages would get thrown around, heavy boxes would be stacked on very small/fragile ones, etc...

Myself and many of the people I worked with all tried their best. But at the end of the day there is only so much you can do as a temp seasonal worker to prevent such things. They'd rather have a higher amount of damaged/lost items and a higher throughput.

It'd be interesting to see a competitor that made it their goal to handle packages with more care and not have this attitude. However I can't see them getting too far. They would likely have to charge more money, and any of the big companies are not going to care to pay more. They'd rather take the risk and just ship it again if it gets broken on the way. It'll end up being cheaper for them that way. The ones who lose out are the smaller businesses and individuals shipping personal items. It pissed me off when I'd see a damaged package of an item that was clearly a personal homemade thing. Something that isn't easy to just quick send another copy of.

Re: Thanks FedEx, this is why we keep getting phished

#472

Earlier quoted context omitted.

I called them and questioned them about this - they didn't even come down my street, and yet claimed that they "attempted delivery". The customer service person was honest enough to say there was no code for the driver to say "too busy, can't meet my unrealistic targets".

> too busy, can't meet my unrealistic targets At least that could explain why the driver showed up to the address without dropping off the package. If finding the package takes a non-trivial amount of time, it would add up over the course of the day. It's otherwise just wild to me that the driver did 99% of the delivery and just noped out of the last 1%.

this happens to me all the time, but I live in a place where a delivery van/truck is basically always going to be double parking.

Re: Thanks FedEx, this is why we keep getting phished

#473

Earlier quoted context omitted.

If 10% of customers have passwords that now can't log in and submit orders, that would be an emergency. We're taking OP's word for it that FedEx doesn't allow certain characters as passwords (actually, from the description, it seems more like FedEx only allows specific characters which is even worse). If either of those are true, it is most certainly a defect. Whether FedEx treats that defect as an emergency is up to…

> it seems more like FedEx only allows specific characters which is even worse) If I read it right it sounds even worse. Fedex allows the characters and then random stuff just breaks. It is much preferred to get a simple "only english alphabet and numbers please" warning message when you are trying to set the password than not getting any warning and then things breaking.

I've had this before at a University I used to attend. I had a password with either a % or a & and I found I couldn't log into one specific system. I changed my password to a different one, but still had one of those special characters. I was curious and tried a more "basic" password and I was able to get in. The system just wouldn't accept certain characters in your password. The main University password manager did disallow certain special characters, but clearly not enough of them.

It never makes you feel very confident in an institutions security when they can't even figure out how to get a username/password to work properly on their systems.

Re: Thanks FedEx, this is why we keep getting phished

#474

Earlier quoted context omitted.

It leads to less security as it is more likely that the new password will just be an old one with an incremented number at the end.

The worst part is it actually leads users to boasting about how they `beat the system', essentially telling their coworkers what their pattern is, making the password easier to guess.

I have long felt that organizations that require password rotation for employees should, when the users are changing their passwords, record and post the old password to an internal site (without any identification of the user) for educational (and mockery) purposes.

Re: Thanks FedEx, this is why we keep getting phished

#475

Earlier quoted context omitted.

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

I've noticed that Microsoft themselves aren't helping this right now. M365 seems to default to using random-tenant-guid.onmicrosoft.com for a lot of these transactional emails like password changes even though the official account.microsoft.com is fully multi-tenant aware and most Microsoft guidance tells you to always go directly to account.microsoft.com. These transactional email mistakes seem like another case of…

The whole Microsoft Office suite online just feels like hacky code on top of more hacky code. And combine with how your account can also be signed into your PC, and then also signed into applications. I have a work email, and two personal emails that all make use of Microsoft products. What a mess it is managing the accounts and the different systems. The business emails and accounts just seem sloppy and seem to work different than personal accounts.

Overall when compared to Google's suite of products, M365 just seems so sloppy.

Re: Thanks FedEx, this is why we keep getting phished

#476
post #30

Earlier quoted context omitted.

I will simply refuse to believe this is real. As a psychological defense mechanism. What the hell.

There's a reason why infosec is hard and why there's a hiring shortage.

Hiring shortage? I guess I should brush up on my security skills, because I can’t get an interview anywhere to save my life.

Re: Thanks FedEx, this is why we keep getting phished

#477
post #439

Earlier quoted context omitted.

I bought an OP-1 from teenage engineering years ago and fedex delivered it inside of the mailbox. USPS removed the fedex package from the mailbox and impounded it at our local USPS post office without ever notifying me. After 1-2 months of waiting/assuming the package had been stolen, I call the USPS office and asked if they somehow had the package in their custody/possession and, lo-and-behold, they did (in the "und…

The mailbox? On your property? that you paid for an installed (or bought off the previous owner), is government/usps property and they'll steal a parcel that someone else has delivered to it? That's insane lmao

USPS owns and maintains some cluster mailboxes at apartment complexes and HOAs.

Re: Thanks FedEx, this is why we keep getting phished

#478
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

> Guess the average strength of an employee password!

It is interesting how sometimes creating "more secure" measures results on less security. Our IT department decided that using 2fa for vpn is not enough, we should also extra 2fa for connecting to the webmail even through intranet or vpn. Guess who stopped using the vpn.

Meanwhile, one can set up and use our email through any email client app on desktop or mobile without any 2fa at any step. Go figure.

Re: Thanks FedEx, this is why we keep getting phished

#480
post #475

Earlier quoted context omitted.

I've noticed that Microsoft themselves aren't helping this right now. M365 seems to default to using random-tenant-guid.onmicrosoft.com for a lot of these transactional emails like password changes even though the official account.microsoft.com is fully multi-tenant aware and most Microsoft guidance tells you to always go directly to account.microsoft.com. These transactional email mistakes seem like another case of…

The whole Microsoft Office suite online just feels like hacky code on top of more hacky code. And combine with how your account can also be signed into your PC, and then also signed into applications. I have a work email, and two personal emails that all make use of Microsoft products. What a mess it is managing the accounts and the different systems. The business emails and accounts just seem sloppy and seem to work…

Add to this the different varieties of their apps. The whole MS thing is a mess imo also because it cannot decide if it is for enterprise or for personal use. Some colleagues had to reinstall outlook, and after that things did not work properly. What actually happened was that they had googled and downloaded "outlook" from microsoft's website, instead of installing the m365 suite version. Which is basically a different application or version or whatever, but sharing the same name and app icon.
Post reply on HN