Live data from Hacker News

Launch HN: Riot (YC W20) – Phishing training for your team

news.ycombinator.com

51–60 of 93 posts

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#51

My company uses Knowbe4, and I'm constantly frustrated how it considers it a fail if I only click a link vs entering in credentials. Sometimes it's tough to tell if something is phishing when your checking email on your phone. Does Riot work the same way? Or do you test to see if users notice issues once they've actually opened something in the browser?

That's not a knowbe4 thing, that's your company's choice.

opened/clicked/creds and so forth are various levels. Your company has decided that a mere click is a fail. also, in gmail, if you 'report phishing' (without clicking), gmail will "click" it for you as part of their back-end analysis. this will show up in the click report. this type of click is distinguishable from a user click, but it's not obvious and knowbe4 has zero docs on it.

Keep in mind, a mere click can in fact be a fail. There are still drive-by attacks that work simply by clicking.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#52

How do you differentiate yourself with places like https://www.knowbe4.com/ which offer free services against phishing.

I tried Knowbe4, I think it's a horrible product. I heard once you try the "free service" they call you daily to sign you up for the paid plan.

like sibling, i found knowbe4 to be pretty good. easy to setup, easy to use, great support, pretty comprehensive.

not perfect, mind you, but still pretty good.

they do bug the hell out of you but who cares? it's just one of dozens of calls i have to ignore on the daily. i told them to back off and they did.

i'll tell you what product is actually horrible, and perhaps ironically so. SANS security training (phishing part relevant here, but the entire suite is horrid). just stay away, don't waste a minnit evaluating it.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#53

Why is this any better than product offerings from PhishMe, Wombat, or KnowBe4?

Most of them target big companies. It makes a very different product. I have a fun story with Wombat: I tried to use the product in my previous company (100 employees), had 4 different calls, with 4 different sales persons, during 2 months. At the end they just forgot about me.

don't know about wombat and the other, but how can you say knowbe4 targets big companies? Their SCORM integration is horrible.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#54
post #11

> Would love to hear your war stories on phishing scams, and how you train your teams! I was working on anti-phishing in 2003, before it had the name phishing. We were trying to teach our users not to fall for the scams. It didn't work. People will fall for the same scam over and over. The conclusion we came to was that the only solution to phishing was education, and education was also nearly impossible to get 100%…

> The conclusion we came to was that the only solution to phishing was education, and education was also nearly impossible to get 100% coverage.

A friend works for a company that fires employees after failing three phishing tests.

It doesn’t solve the problem for those people, but it does work for that company. What has priority depends on your management style :)

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#56
True story (except for the last two lines):

Boss: install this antivirus and run it: [link].

Me: I dunno, that seems like a phishing attempt... is that really you, boss? What's the code word?

Boss: DO IT OR YOU ARE FIRED!

Me: oh yeah, definitely you; installing it right now.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#57

Hi Ben - cool product! Speaking as the lead for Riot.im, I would recommend picking another name asap, if nothing else because Riot Games has an awful lot of lawyers (as we know first hand, unfortunately).

Damn!

that was our thought too :/ On the plus side, you can come join our secret treehouse alongside the nice people at https://riot.js.org/ and https://www.riot-os.org/ who have RG hanging over their heads...

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#58

Earlier quoted context omitted.

It's bad in that there's already a very popular game company named Riot (Games) which everyone refers to as 'Riot'.

Some people know League of Legends, most don't know Riot Games. And I double checked: Riot Games don't own a trademark for anything related to cybersecurity.

Unfortunately that doesn't seem to stop them going after companies with Riot in their name (even though Riot is also a dictionary word) :(

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#60
post #11

> Would love to hear your war stories on phishing scams, and how you train your teams! I was working on anti-phishing in 2003, before it had the name phishing. We were trying to teach our users not to fall for the scams. It didn't work. People will fall for the same scam over and over. The conclusion we came to was that the only solution to phishing was education, and education was also nearly impossible to get 100%…

If you wouldn't mind I'd really like to get your opinion on this proposed hardware solution I posted a while back:

https://news.ycombinator.com/item?id=22343786

Post reply on HN