FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…
Thanks FedEx, this is why we keep getting phished
521–530 of 576 posts
Re: Thanks FedEx, this is why we keep getting phished
#522Earlier quoted context omitted.
You're reminding me of the time I realized that Schwab (a massive American bank/broker) truncated all passwords to 8 characters.
Heh, that's the same company that sends physical mail to me every time I make a trade because they believe that email sent to my personal domain is "undeliverable" and automatically opt me out of e-statements no matter how many times I opt-back in. They have to be losing money on me by paying for so much postage at this point. (And no, nothing is wrong with my email, it's hosted by a professional email host with the…
Re: Thanks FedEx, this is why we keep getting phished
#523Earlier quoted context omitted.
Heh, that's the same company that sends physical mail to me every time I make a trade because they believe that email sent to my personal domain is "undeliverable" and automatically opt me out of e-statements no matter how many times I opt-back in. They have to be losing money on me by paying for so much postage at this point. (And no, nothing is wrong with my email, it's hosted by a professional email host with the…
My college had a credit union with an ATM in the cafeteria. It was in your interest to keep enough money in the credit union to pay for lunch etc. while you were a student there. When I graduated, I pulled the money back out. Apparently they issued the final interest payment after I'd emptied the account. For at least a year after that, I got monthly statements informing me that I had an account with less money in it…
Re: Thanks FedEx, this is why we keep getting phished
#524A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…
My company's security training tells me to carefully verify any URLs in received emails, but then they have some security software that rewrites all the URLs in incoming emails - presumably as a way of screening them themselves. This might be a reasonable trade-off for centralising monitoring, but it significantly hampers the ability to judge the legitimacy of emails myself. At least update your training!
Re: Thanks FedEx, this is why we keep getting phished
#525Earlier quoted context omitted.
Do you have any examples? I'm largely out of the Microsoft ecosystem these days, aside from the occasional Xbox usage.
Office.com redirects you to login.microsoftonline.com which isn't horribly bad, but is starting to get there. Now you have microsoft365.com and friends, too. At least when things were login.microsoft.com you could apply the "last part is definitive" now that heuristic is pretty useless. And if you watch the actual DNS requests during a login, whew. CDNs make it even worse, here's a few VALID requests from my DNS cach…
Re: Thanks FedEx, this is why we keep getting phished
#526Earlier quoted context omitted.
Retaliation for charge back probably elevates this from a civil matter to a criminal one; you should totally contact your local DA. They might think it's fun.
I wouldn't be surprised if it's just covered by the EULA. There's almost certainly a clause in there about Google being able to terminate service for any reason.
Re: Thanks FedEx, this is why we keep getting phished
#527Earlier quoted context omitted.
Yep. It's a bit like the theory that scammers mention they're from Nigeria because they're ingeniously weeding out all the people who've heard of the scam before, and not because they need an excuse for people to send money to Nigeria (and with their culture and education level the ALLCAPS and religious references look very official and honest indeed), and if the cost of that is that 99.99% of their emails don't get…
I've read one interview with a scammer who mentioned that the initial pitch is deliberately written that way to screen for gullible people, and I've read extended email exchanges with Nigerian scammers where their broken English becomes flawless after the initial reply. 419eater.com was a treasure. These days though, like most scams the 419 scams have been taken over by organized crime and worse. The average Nigerian…
Just doesn't make much sense for people whose time is valued in cents per hour and whose theoretical earnings are in the thousands to optimise for screening out non-gullible people, plus the 99.9% of gullible people that have some sort of spam filter in the loop. But hey, if someone's shared that Microsoft Research paper with the scammers and they've come to believe that using formats that almost invariably bump into spam filters is actually a shrewd move on their part, who am I to discourage them?!
I don't know about Boko Haram involvement, but I assume the organized crime guys have some sort of MLM-style operation scamming Nigerians into paying for the get-rich-quick opportunity.
Re: Thanks FedEx, this is why we keep getting phished
#528Earlier quoted context omitted.
I am currently sitting at my gaming PC, which does have a Blu Ray drive. I use it about one or two times a year. Just today I threw in a CD with the driver of my newly installed tp-link AXE5400 (WiFi PCIe adapter), because it wasn't detected on my PC and I didn't have internet without Wi-Fi. I immediately got a prompt if I want to run the "autorun.exe" on the disc. So that is still there (Windows 22635.3209, Windows-…
But back in the day, popping the disk in the drive would have just executed the autorun without even prompting you. Put the disk in the drive, suddenly new application running on your box as you (and generally, back in the day, as local admin). Not even a chance to say no.
Re: Thanks FedEx, this is why we keep getting phished
#529Earlier quoted context omitted.
3% of the internet is still an incredibly large amount of people.
Sure? But what definition of "popular" does "large amount of people" meet? "Of or relating to the general public"? The general public is using Windows 10 and 11. "Suitable to the majority"? Again, the vast majority is 10 and 11. Same for "frequently encountered or accepted" and "commonly liked or approved": the most frequently encountered is Windows 10. So too is the most "commonly liked". 3% is still 3% and far and…
Re: Thanks FedEx, this is why we keep getting phished
#530Earlier quoted context omitted.
I'm pretty sure that most of the on-screen keyboards for TV / streaming device platforms don't support emoji. (I've spent about 6 years of my career running video streaming services... People watch a lot of video on TVs, it turns out, so you probably don't want to let them put these sorts of characters into their passwords when they sign up on mobile or computer devices.)
For better and a (lot) worse most of the TV / streaming device platforms are Android-derived and have access to emoji keyboards if not intentionally disabled , even on TV form factors. I realize it is a wide spectrum of users and a long tail of devices, but at some point again it isn't a technical reason that we are banning emoji from passwords but a political and lowest common denominator reason. I'm not trying to i…
As I said, it's not about support for emoji as a class.
It's about support for specific emoji. Different OS's are on different versions of Unicode that support different sets of emoji. The older versions don't support the newer emoji.
So yes, in 2024, it would be incredibly easy to create a password using an emoji on your up-to-date Mac that simply can't be entered on your Android-based TV you purchased 3 years ago, because it doesn't have that emoji even though in supports emoji in general.
So no -- it's not for social reasons, it's very much for technical ones.
And trying to implement a rule like "emoji are allowed but only the ones that were present in Unicode 6.0" is incredibly confusing and opaque for end-users, so it's a better experience just to not allow emoji at all.