Live data from Hacker News

SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

fredbenenson.com

51–60 of 152 posts

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#51

relatedly, my wife received polititexts destined to her conservative father. The latest was actually genius IMO, in that it stated "Dear STEVEN, due to inactivity, your registration will be changed to DEMOCRAT in 20 minutes unless you navigate to this link." It, I assume, redirected to some support page to donate to the US conservative party or its affiliates. The social engineering is getting more effective

I don't know if the fact that it fully slipped into the absurd or the fact that it probably still worked on people is sadder. I do love the idea of voter registration oscillating back and fourth at 20 minutes intervals forever. Would make voting in the primaries way more exciting as the voter base kept flipping.

This isn't even close to the most ridiculous emotional manipulation techniques American conservative fundraising uses to target old people who might not be in full possession of their faculties. It's some of the scummiest stuff possible.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#54
2FA doesn't stop phishing unless it's WebAuthn. But SendGrid, which is owned by Twilio, only supports 2FA based on SMS or the Authy App (which is also made by Twilio): https://www.twilio.com/docs/sendgrid/ui/account-and-settings...

It seems like Twilio has a conflict of interest that prevents them from offering WebAuthn, as that would be a tacit admission that their SMS and Authy products are not actually that secure.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#55

First thought... Why would ICE need donations? I then realized how unrecognizable scams have become to me now. Older people are going to be in a worse position.

You can donate to reduce the national debt, so it's not that far out of the realm of possibility that federal agencies would solicit donations, too.

https://www.pay.gov/public/form/start/23779454

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#56

Earlier quoted context omitted.

I think HN should embrace AI to the point of having an alternative AI-generated title next to the original title, to reduce clickbait and reduce the global rage index.

I've been thinking about building a browser extension that turns clickbait headlines into factual titles. "Why is SendGrid emailing me about supporting ICE?" becomes "Phishing Campaign Targets SendGrid Users via Compromised Accounts and Politically Charged Bait" I think it would be more time than I'd like to commit though.

I tried to vibe code it about a year ago(a firefox extension), worked surprisingly good. Basically for a small set of web sites I frequent, just rewrite titles or remove links all together if a title is a click-bait or ragebait.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#57
post #3

Before anyone launches themselves into the sky: the title is clickbait. This is about phishing attempts that use ICE to persuade you to click. Sendgrid the company is not emailing about supporting ICE. But technically Sendgrid the infrastructure is.

Maybe one day our knee jerk reactionary outrage will be quelled not by any enlightenment but because we are forced to grow weary of falling prey to phishing attacks. I'd feel pretty stupid getting worked up about something only to realize that getting worked up about it was used against me. I'm writing this because for a moment I did get worked up and then had the slow realization it was a phishing attack, slightly b…

The effectiveness of these techniques will die off over time as young people are increasingly inoculated against them in the same way our generations are generally immune to traditional advertising. The memetics filters get better over time as us geezers are replaced by new models.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#58
post #3

Before anyone launches themselves into the sky: the title is clickbait. This is about phishing attempts that use ICE to persuade you to click. Sendgrid the company is not emailing about supporting ICE. But technically Sendgrid the infrastructure is.

I seriously hope HN discourse has the bare minimum of “open the link and read it before commenting”.

Your hope is in conflict with reality.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#60
I wonder why Gmail and other email providers don't just run an LLM/ML pipeline to detect phishing emails. It seems that matching an email's content with the sender's domain (and possibly analyzing the content behind links) would be enough to show, with high certainty, a warning like "Beware: this looks like a phishing email." Is it too expensive? Too many false positives?
Post reply on HN