Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

521–530 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#521
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

If you give instructions to a delivery guy, they are not secure anymore.

Re: Thanks FedEx, this is why we keep getting phished

#522
post #417

Earlier quoted context omitted.

You're reminding me of the time I realized that Schwab (a massive American bank/broker) truncated all passwords to 8 characters.

Heh, that's the same company that sends physical mail to me every time I make a trade because they believe that email sent to my personal domain is "undeliverable" and automatically opt me out of e-statements no matter how many times I opt-back in. They have to be losing money on me by paying for so much postage at this point. (And no, nothing is wrong with my email, it's hosted by a professional email host with the…

A different bank that I use will occasionally tell me that I'm about to be opted out of email because I haven't opened any of their mails and they don't think they're getting through. Which I assume is just because I have thunderbird set to not show remote images and that breaks their tracking.

Re: Thanks FedEx, this is why we keep getting phished

#523
post #417

Earlier quoted context omitted.

Heh, that's the same company that sends physical mail to me every time I make a trade because they believe that email sent to my personal domain is "undeliverable" and automatically opt me out of e-statements no matter how many times I opt-back in. They have to be losing money on me by paying for so much postage at this point. (And no, nothing is wrong with my email, it's hosted by a professional email host with the…

My college had a credit union with an ATM in the cafeteria. It was in your interest to keep enough money in the credit union to pay for lunch etc. while you were a student there. When I graduated, I pulled the money back out. Apparently they issued the final interest payment after I'd emptied the account. For at least a year after that, I got monthly statements informing me that I had an account with less money in it…

Back in the 1970s, I lived for a while in Boston. I needed both Canadian and American accounts, for reasons. So I opened an account with the Boston branch of the Bank of Nova Scotia. Things worked ok for a while, and then I moved back to Canada. I withdrew the pittance I had in the account, and asked the bank staff to close the account. For the next two years or so, I got account statements, showing the glorious zero balance. I think it only stopped when I moved and didn't notify them of a forwarding address.

Re: Thanks FedEx, this is why we keep getting phished

#524
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

My company's security training tells me to carefully verify any URLs in received emails, but then they have some security software that rewrites all the URLs in incoming emails - presumably as a way of screening them themselves. This might be a reasonable trade-off for centralising monitoring, but it significantly hampers the ability to judge the legitimacy of emails myself. At least update your training!

M365 has an option to rewrite URLs in incoming emails. It's horrible, at least for people that can actually read URLs. Every link turns into a 300 character mess that I have no idea if its valid or not. The only way to tell is to click it. Maddening!

Re: Thanks FedEx, this is why we keep getting phished

#525

Earlier quoted context omitted.

Do you have any examples? I'm largely out of the Microsoft ecosystem these days, aside from the occasional Xbox usage.

Office.com redirects you to login.microsoftonline.com which isn't horribly bad, but is starting to get there. Now you have microsoft365.com and friends, too. At least when things were login.microsoft.com you could apply the "last part is definitive" now that heuristic is pretty useless. And if you watch the actual DNS requests during a login, whew. CDNs make it even worse, here's a few VALID requests from my DNS cach…

Yea, it's really fun to log into some some Microsoft site and get redirected 10 times. The domains it goes through are staggering, some of them don't even look like MS names at all. More than once I've been convinced that there is something fishy going on. Only to realize that, nope, that's the way MS wanted it.

Re: Thanks FedEx, this is why we keep getting phished

#526
post #455

Earlier quoted context omitted.

Retaliation for charge back probably elevates this from a civil matter to a criminal one; you should totally contact your local DA. They might think it's fun.

I wouldn't be surprised if it's just covered by the EULA. There's almost certainly a clause in there about Google being able to terminate service for any reason.

Not all contracts are legal.

Re: Thanks FedEx, this is why we keep getting phished

#527

Earlier quoted context omitted.

Yep. It's a bit like the theory that scammers mention they're from Nigeria because they're ingeniously weeding out all the people who've heard of the scam before, and not because they need an excuse for people to send money to Nigeria (and with their culture and education level the ALLCAPS and religious references look very official and honest indeed), and if the cost of that is that 99.99% of their emails don't get…

I've read one interview with a scammer who mentioned that the initial pitch is deliberately written that way to screen for gullible people, and I've read extended email exchanges with Nigerian scammers where their broken English becomes flawless after the initial reply. 419eater.com was a treasure. These days though, like most scams the 419 scams have been taken over by organized crime and worse. The average Nigerian…

419eater is also full of scammers whose English notably deteriorates, scammers who have almost endless time to comply with bonkers requests, and scammers that are quite far into the discussion when they go to some effort to produce "official documents" that look like they were produced by a child. And personally, I've experienced the reverse, where even when it's a well constructed item-for-sale scam by someone with access to a PayPal account they can't help but use email addresses that look a bit too Nigerian to be an elderly Scottish lady and English that just doesn't match the ad copy and is obsessed with explaining the safety and urgency of the transaction rather than the "product". Most of the others have to mention Western Union to Nigeria at some point...

Just doesn't make much sense for people whose time is valued in cents per hour and whose theoretical earnings are in the thousands to optimise for screening out non-gullible people, plus the 99.9% of gullible people that have some sort of spam filter in the loop. But hey, if someone's shared that Microsoft Research paper with the scammers and they've come to believe that using formats that almost invariably bump into spam filters is actually a shrewd move on their part, who am I to discourage them?!

I don't know about Boko Haram involvement, but I assume the organized crime guys have some sort of MLM-style operation scamming Nigerians into paying for the get-rich-quick opportunity.

Re: Thanks FedEx, this is why we keep getting phished

#528

Earlier quoted context omitted.

I am currently sitting at my gaming PC, which does have a Blu Ray drive. I use it about one or two times a year. Just today I threw in a CD with the driver of my newly installed tp-link AXE5400 (WiFi PCIe adapter), because it wasn't detected on my PC and I didn't have internet without Wi-Fi. I immediately got a prompt if I want to run the "autorun.exe" on the disc. So that is still there (Windows 22635.3209, Windows-…

But back in the day, popping the disk in the drive would have just executed the autorun without even prompting you. Put the disk in the drive, suddenly new application running on your box as you (and generally, back in the day, as local admin). Not even a chance to say no.

IIRC holding down shift when inserting the CD prevented auto-run.

Re: Thanks FedEx, this is why we keep getting phished

#529

Earlier quoted context omitted.

3% of the internet is still an incredibly large amount of people.

Sure? But what definition of "popular" does "large amount of people" meet? "Of or relating to the general public"? The general public is using Windows 10 and 11. "Suitable to the majority"? Again, the vast majority is 10 and 11. Same for "frequently encountered or accepted" and "commonly liked or approved": the most frequently encountered is Windows 10. So too is the most "commonly liked". 3% is still 3% and far and…

It seems like a very good idea to not allow passwords that can't be input on 3% of commonly used Windows computers. 3% is still a very significant number when it comes to compatibility, customer support, etc.

Re: Thanks FedEx, this is why we keep getting phished

#530
post #469

Earlier quoted context omitted.

I'm pretty sure that most of the on-screen keyboards for TV / streaming device platforms don't support emoji. (I've spent about 6 years of my career running video streaming services... People watch a lot of video on TVs, it turns out, so you probably don't want to let them put these sorts of characters into their passwords when they sign up on mobile or computer devices.)

For better and a (lot) worse most of the TV / streaming device platforms are Android-derived and have access to emoji keyboards if not intentionally disabled , even on TV form factors. I realize it is a wide spectrum of users and a long tail of devices, but at some point again it isn't a technical reason that we are banning emoji from passwords but a political and lowest common denominator reason. I'm not trying to i…

> I can't believe it's a technical problem in 2023. Emoji are universal enough now in 2024 that OSes are broken if they can't send/receive emoji

As I said, it's not about support for emoji as a class.

It's about support for specific emoji. Different OS's are on different versions of Unicode that support different sets of emoji. The older versions don't support the newer emoji.

So yes, in 2024, it would be incredibly easy to create a password using an emoji on your up-to-date Mac that simply can't be entered on your Android-based TV you purchased 3 years ago, because it doesn't have that emoji even though in supports emoji in general.

So no -- it's not for social reasons, it's very much for technical ones.

And trying to implement a rule like "emoji are allowed but only the ones that were present in Unicode 6.0" is incredibly confusing and opaque for end-users, so it's a better experience just to not allow emoji at all.

Post reply on HN