Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

501–510 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#501
post #77

Earlier quoted context omitted.

If you give me your mailing address, I'll arrange it that the bank will mail you one, too. Just be sure to use the included NOTVIRUS.EXE viewer for best experience.

In your fantasies. It is of course in the responsibility of the bank to check if this is virus free. I am using Linux anyway.. No autorun.exe here. Is this still a thing with Windows?

>It is of course in the responsibility of the bank to check if this is virus free

Oh, trust me, it'll absolutely come from the bank where they're doing all the due diligence necessary, and not from a random malicious party!

It'll say FROM THE BANK on the envelope, so you'll know it's legit.

>I am using Linux anyway.. No autorun.exe here.

Oh, you'll have to do a bit more work then. Just follow the instructions included in the envelope, and run

    sudo ./notvirus.sh
from the terminal from the root directory of the USB drive once you mount it.

Re: Thanks FedEx, this is why we keep getting phished

#502
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

You're reminding me of the time I realized that Schwab (a massive American bank/broker) truncated all passwords to 8 characters.

Hey they don't anymore so, progress!

I remember comparing notes with fellow employees at a previous job, and depending on when you'd started working, the system had different password rules for you (users who'd been created earlier had a smaller set of allowed characters, etc.). Pretty sure it worked out to some Oracle nonsense.

Re: Thanks FedEx, this is why we keep getting phished

#503
post #245

A while ago my wife applied for a home equity loan. At some point I got a call from someone claiming to be from the bank she had applied through (I forget which one), calling to make sure I approved the loan since the home is in both our names. He asked for my name, which I gave him, and then the last four digits of my social security number, which I also gave him. He then proceeded to ask for my full social security…

Had a very similar experience with a bank few years ago. I filed an official complaint because it was not possible to verify the caller was authentic.

Can you guess what happened next? Yep... The complaints team cold called me and requested PII to confirm they were talking to the right person. I refused and the call ended.

Later got a letter saying it wasn't possible to followup on my issue and they didn't see any issues with what I had raised. I tried... :/

Re: Thanks FedEx, this is why we keep getting phished

#504
post #471
post #444

Earlier quoted context omitted.

> just keep the parcel at the depot for a week until they have a driver who can actually make the trip. Depot workers can get up to the weirdest stuff. One time I was returning unused product (oil well perforating guns, a UN 1.4D explosive device) via Yellow Freight. I handed over the cases and signed all the appropriate paperwork to handover custody at the depot and went on about my day. The supplier called me ~10 d…

One of the big problems I find in the shipping industry is the reliance on insurance. The idea that most packages are insured or easily replaceable. When I was a bit younger and doing some seasonal postal work in a processing plant this was the mentality. The mentality being that sometimes things will go wrong and ruin a package, but hey, whatever. Machines would sometimes destroy a package, packages would get thrown…

I think there is something about the monkey brain in people that if you give them an item, they think they own it. It doesn't matter that it's just a loan or they are supposed to give it to someone else.. they think they can do whatever they want with it and anyone is lucky that they didn't mess with it. This seems to happen in the food service industry as well with the whole attitude of "be nice to us so we don't mess with your food!" The monkey brain can't help but think that it owns an item that it managed to grab. That's why I think that we need a psychological trick to make humans in package management think differently about the packages. Maybe writing something like "Fedex FAMILY Owned" on each package could do the trick. Although when I worked in a shipping facility I think people were so busy that there wasn't much "thinking" either way possible. Still we will probably just go with robots though.

Re: Thanks FedEx, this is why we keep getting phished

#505
post #444

Earlier quoted context omitted.

At one of my addresses FedEx will happily sell anyone overnight shipping and then just keep the parcel at the depot for a week until they have a driver who can actually make the trip. I have had like 6 very urgent packages delayed like this. Once my wife ordered something perishable and they pulled this then told her she had to drive into town and pick it up at the airport. I've also been nearly run off the road by F…

> just keep the parcel at the depot for a week until they have a driver who can actually make the trip. Depot workers can get up to the weirdest stuff. One time I was returning unused product (oil well perforating guns, a UN 1.4D explosive device) via Yellow Freight. I handed over the cases and signed all the appropriate paperwork to handover custody at the depot and went on about my day. The supplier called me ~10 d…

Lesson for US customers: If you really want your shipment to be delivered, add a bullet or a pinch of gunpowder to the shipment.

Re: Thanks FedEx, this is why we keep getting phished

#506
post #471

Earlier quoted context omitted.

One of the big problems I find in the shipping industry is the reliance on insurance. The idea that most packages are insured or easily replaceable. When I was a bit younger and doing some seasonal postal work in a processing plant this was the mentality. The mentality being that sometimes things will go wrong and ruin a package, but hey, whatever. Machines would sometimes destroy a package, packages would get thrown…

I think there is something about the monkey brain in people that if you give them an item, they think they own it. It doesn't matter that it's just a loan or they are supposed to give it to someone else.. they think they can do whatever they want with it and anyone is lucky that they didn't mess with it. This seems to happen in the food service industry as well with the whole attitude of "be nice to us so we don't me…

I think your last couple sentences is the reality. You are expected to be quick at your job and you don't have much time to think about each package. Was that a pretty heavy package you just put on top of a fragile one? That's unfortunate, but the company just doesn't give you the time to do it properly. And the company is okay with accepting that risk at the customers expense.

Re: Thanks FedEx, this is why we keep getting phished

#507
post #387

Earlier quoted context omitted.

Might be a good product to app-ify. Maybe a USB dongle that acts like a keyboard and controlled by your phone. Give it some sort of 1Password / Bitwarden integration. Could make it double as a YubiKey. Surely this exists already?

Separately from the password aspect, consider how convenient it may be to use your smartphone as a kind of re-reified "clipboard": Use the camera and on-device OCR to copy text, then "paste" it as a virtual keyboard connected over USB. It's very niche, but in those rare situations it'll be a big time-saver compared to human transcription or the rigamarole of setting up some other kind of data channel.

Now I’m curious if BT can be secure enough for all this (responsibly)

Re: Thanks FedEx, this is why we keep getting phished

#508

Earlier quoted context omitted.

Everywhere that I know of requires a real, specific, individual to sign off on the purchase order, charge it to their card, send the bill to accounts payables, etc...

That's not what GP was saying? Whether or not the provider makes the customer pay with a credit card has no impact on if the provider requires templated SMS messages.

I'm saying it. There is a specific individual that had to approve it, somewhere, somehow, even if that's not true for the 'template'.

Re: Thanks FedEx, this is why we keep getting phished

#509

Earlier quoted context omitted.

And buy a very expensive tracking device with frequent security issues? I am lucky to live in a country in which a large religious population eschews the smartphone, so saying "I don't have one" is acceptable and common here. But I have colleagues who tell me that they are expected to have a smartphone from everything to banks to government services to simple small restaurants.

interesting. Where is that? I would like to know more

I live in Israel. Most of the ultra religious do not own a smartphone.

Re: Thanks FedEx, this is why we keep getting phished

#510

Earlier quoted context omitted.

And buy a very expensive tracking device with frequent security issues? I am lucky to live in a country in which a large religious population eschews the smartphone, so saying "I don't have one" is acceptable and common here. But I have colleagues who tell me that they are expected to have a smartphone from everything to banks to government services to simple small restaurants.

And where is this?

I live in Israel. Most of the ultra religious do not own a smartphone.
Post reply on HN