Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

481–490 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#481
post #384

Earlier quoted context omitted.

Oh, there are many fun games from the 90's where you must infiltrate some place and every computer has some version of "due to the password rotation requirements, this week's password for the South-East door is 1-2-3-4, effective from Monday" pasted into it. When the NIST added the bad rule into their ruleset (it was mostly a collection of bad rules at the time), it was already widely mocked in popular culture (well,…

> there are many fun games from the 90's where you must infiltrate some place and every computer has some [sticky note] "Come to think of it, it's about time to replay Deus Ex again..."

Don't forget to invest heavily in Swimming!

Re: Thanks FedEx, this is why we keep getting phished

#482
post #245

A while ago my wife applied for a home equity loan. At some point I got a call from someone claiming to be from the bank she had applied through (I forget which one), calling to make sure I approved the loan since the home is in both our names. He asked for my name, which I gave him, and then the last four digits of my social security number, which I also gave him. He then proceeded to ask for my full social security…

A bank called me to ask me security questions. I said that I would call back using the number on the bank's website. They said (and the bank confirmed when I did call the number) that there is no way to be transferred to the security question people when I call the bank - the only way is for them to call me. I explained that that was poor security practice. They said that I should just look at the caller ID to see th…

And then if your identifiers somehow get in the hands of bad actors and the bank gets fooled by them to open a bank account in your name, you are the one on the hook. It's utter insanity!

Re: Thanks FedEx, this is why we keep getting phished

#483
Last year we received an email with title

> ACTION REQUIRED - New certificate authority for slack-edge.com

Capitalised letters telling you MUST do sth (check; plus "as soon as possible" in the body). Bad/incosistent email layout (check). Unknown urls (slack-edge.com, slackhq.com) that resemble the services's standard url slack.com (check). A bunch of links obfuscated behind "slackhq" redirects, check. Even a link that reads "slack.com" and points to that slackhq redirect thing. The majority thought it was scam, of course. I only suspected it may not have been scam because a scammer would have done a better job explaining what one had to actually do (and in the end there was nothing we needed to do anyway).

Re: Thanks FedEx, this is why we keep getting phished

#484
post #200

Earlier quoted context omitted.

> have to type 10-20 per day Same problem here. My solution: Get a mouse with internal memory for macros, such as Natec Genesis GX78 (old, no longer available, but this is an example). Program your new password on one of the unused mouse buttons or in a different profile. Use the mouse to type the password.

Might be a good product to app-ify. Maybe a USB dongle that acts like a keyboard and controlled by your phone. Give it some sort of 1Password / Bitwarden integration. Could make it double as a YubiKey. Surely this exists already?

The InputStick¹ can provide the hardware side, the software side is open-source² as well. It only has a keepass2android plugin at the moment though.

1: http://inputstick.com

2: https://github.com/inputstick

Re: Thanks FedEx, this is why we keep getting phished

#485

Wow, I thought this was a great post, and I'm just dumbfounded about how egregiously bad that first SMS was - FedEx might as well tell the recipient they want to customs duties wired to a Nigerian prince. But I also disagree with the general push of Troy Hunt's recommendations. That is, we should just take the base assumption that humans, generally, can't distinguish between real and phishing inbound messages. That's…

Not to worry. According to some judges and elected officials, you can just ask ChatGPT whether or not the suspicious text was made by AI.

Re: Thanks FedEx, this is why we keep getting phished

#486

Earlier quoted context omitted.

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

I've noticed that Microsoft themselves aren't helping this right now. M365 seems to default to using random-tenant-guid.onmicrosoft.com for a lot of these transactional emails like password changes even though the official account.microsoft.com is fully multi-tenant aware and most Microsoft guidance tells you to always go directly to account.microsoft.com. These transactional email mistakes seem like another case of…

Agreed!

This should be out of the hands of the local IT clowns entirely.

Re: Thanks FedEx, this is why we keep getting phished

#487
post #64

This fits nicely with my experience of FedEx. They sent me a bill 7 months after I had received the package. A few days later I get a reminder that doesn't include the necessary information for payment, which seems rather lazy and stupid since an unpaid bill might well have been lost. It refers me to www.fedex.com where I'm told to create an account. I do that only to find it doesn't know anything about my bill. By c…

This is common practice for some businesses.

If you ever drive on a toll road in Texas (there are a lot of them and more every year) there are no toll booths that allow you to pay then and there but you'll get a bill in the mail 6-12 months later informing you that this is your fifth and final warning and you owe $4 for the toll and $80 in late fees. I guarantee you the people behind this have friends or family in the Texas legislature supporting them.

Re: Thanks FedEx, this is why we keep getting phished

#488
post #360
post #337

Earlier quoted context omitted.

Terms of service from my bank say you're not allowed to give your PIN or secrets like one-time passwords (called "TAN" here) to third parties, not even the bank employees themselves. But when I contacted them about a phishing practice, it was A-OK because it was a "legitimate" website that phished your credentials to view the last 180 days of transaction histories, compute a credit score, and then withdraw the money.…

I've implemented the bank account checking flow for a German client in a purely B2B setting, and this is essentially based on the PSD2 directive, which requires all/some/most (not entirely sure) banks to provide exactly this functionality (google keywords "PSD2" and "XS2A"). The bank's T&C should reflect this ... somewhere. The main protection to you not getting scammed out of money this way is in the kind of TAN use…

> It should/must only allow read access to your account

Besides that it also needs to perform the payment, why do they need to pull 180 days of transaction history just so that I can give the merchant their money? (I'd be happy to just be given an IBAN number and transaction description to use and do it myself.)

At least that's what the consent screen said it was going to do: assess my creditworthiness before withdrawing the money. There was no way to pay without sharing who my employer is and how much I earn, which shops I visit in which cities, where I've been on holiday, what online purchases I do and on which platform and how frequently and for how much, etc. Obviously I declined this but since it's one of the logos you see every time, I guess a lot of people "consent" to this (knowingly or otherwise)

Re: Thanks FedEx, this is why we keep getting phished

#489

Earlier quoted context omitted.

That sounds like internal verification uses GPS. So in most cases it's going to be the customer's word against the astonishingly lazy driver's evidence.

Can you file a small-claims? You have nothing to lose, it’s not like they could threaten to stop delivering your packages.

Why couldn't they threaten to stop delivering? I was under the impression that only the Postal Service (USPS) had a regulatory mandate to serve all US addresses.

Re: Thanks FedEx, this is why we keep getting phished

#490
post #243
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

Is it impressive though? They have about a 50% success rate delivering things to me across multiple addresses and I know other people who have had similar long term issues.

They definitely are not impressive. I always avoid them if I am given a choice, because for the last 20 years they have always been sub-par. UPS isn't perfect, but they consistently do better than FedEx. Sadly these days it's pretty uncommon for vendors to give you the choice of who they use to ship the package, so I can't always avoid them.
Post reply on HN