Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

551–560 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#551
post #471
post #444

Earlier quoted context omitted.

> just keep the parcel at the depot for a week until they have a driver who can actually make the trip. Depot workers can get up to the weirdest stuff. One time I was returning unused product (oil well perforating guns, a UN 1.4D explosive device) via Yellow Freight. I handed over the cases and signed all the appropriate paperwork to handover custody at the depot and went on about my day. The supplier called me ~10 d…

One of the big problems I find in the shipping industry is the reliance on insurance. The idea that most packages are insured or easily replaceable. When I was a bit younger and doing some seasonal postal work in a processing plant this was the mentality. The mentality being that sometimes things will go wrong and ruin a package, but hey, whatever. Machines would sometimes destroy a package, packages would get thrown…

Like most problems, it’s an externality problem.

The true cost of destroying or misplacing a parcel is often higher than the nominal value of the item inside. Sometimes it’s a sentimental good, sometimes it’s time sensitive and not having it in time results in additional costs to the recipient, sometimes the recipient spends significant time attempting to locate the package.

None of these are appropriately compensated for.

Make these companies liable for the economic cost of the goods plus $200 and they’ll start taking more care.

Re: Thanks FedEx, this is why we keep getting phished

#552
post #444

Earlier quoted context omitted.

At one of my addresses FedEx will happily sell anyone overnight shipping and then just keep the parcel at the depot for a week until they have a driver who can actually make the trip. I have had like 6 very urgent packages delayed like this. Once my wife ordered something perishable and they pulled this then told her she had to drive into town and pick it up at the airport. I've also been nearly run off the road by F…

> just keep the parcel at the depot for a week until they have a driver who can actually make the trip. Depot workers can get up to the weirdest stuff. One time I was returning unused product (oil well perforating guns, a UN 1.4D explosive device) via Yellow Freight. I handed over the cases and signed all the appropriate paperwork to handover custody at the depot and went on about my day. The supplier called me ~10 d…

> dropped off oil well perforating guns at Yellow Freight

Holy fuck. We never shipped these using commercial couriers, but transported them using company trucks and company labor. We'd also have a heavily armed security person escorting them at all times.

For reference, these are long tubes containing many shaped charges. Sometimes you can have hundreds or thousands of shaped charges for a single perforation job. AFAIK, the oil field is the only industry that uses shaped charges outside of the military. Their primary application is piercing tank and ship armor. They kind of "implode" rather than "explode", and generate a sort of lightsaber-beam of superheated copper that lances straight through armor. In this video[0], blue is just a steel casing, yellow is the explosive, and red is the copper which pierces the target.

Not a good thing to "go missing".

0: https://www.youtube.com/watch?v=NoetLNb1Fc4

Re: Thanks FedEx, this is why we keep getting phished

#553
post #259

Earlier quoted context omitted.

"50% success rate delivering packages" is a totally different level of risk from "automated system gives your garage access code to anyone who claims to live there" i mean in the first case what's at risk is the five-dollar trinket you bought off amazon

Or the irreplacable trinket that your aging grandmother sent you.

hopefully you'd opt for a more reliable shipping service for important packages

Re: Thanks FedEx, this is why we keep getting phished

#554
post #471
post #444

Earlier quoted context omitted.

> just keep the parcel at the depot for a week until they have a driver who can actually make the trip. Depot workers can get up to the weirdest stuff. One time I was returning unused product (oil well perforating guns, a UN 1.4D explosive device) via Yellow Freight. I handed over the cases and signed all the appropriate paperwork to handover custody at the depot and went on about my day. The supplier called me ~10 d…

One of the big problems I find in the shipping industry is the reliance on insurance. The idea that most packages are insured or easily replaceable. When I was a bit younger and doing some seasonal postal work in a processing plant this was the mentality. The mentality being that sometimes things will go wrong and ruin a package, but hey, whatever. Machines would sometimes destroy a package, packages would get thrown…

> It'd be interesting to see a competitor that made it their goal to handle packages with more care

There are "personal courier services" or "white glove courier services" where you hire a specific person to move your package from point A to point B. They stay with your package the whole time, and either carry it on a plane or drive it themselves.

It's expensive, obviously, but the service does exist.

Just like you, I'd love to see a middle-ground, scalable option exist.

Re: Thanks FedEx, this is why we keep getting phished

#555
post #245

A while ago my wife applied for a home equity loan. At some point I got a call from someone claiming to be from the bank she had applied through (I forget which one), calling to make sure I approved the loan since the home is in both our names. He asked for my name, which I gave him, and then the last four digits of my social security number, which I also gave him. He then proceeded to ask for my full social security…

I swear, it's like banks are trying to train people into being scammed.

Re: Thanks FedEx, this is why we keep getting phished

#556

DHL, FedEx, and UPS are experts in overcharging to process a form and not caring about customers. Duty and VAT are usually low compared to this processing fee, and shipping has already been paid. Here is the catch in the EU, this simple duty form can be processed by the receiver, an agent (some related to the carrier), or an attorney-in-fact of the receiver. The big three carriers (and many others) threaten you if yo…

I've often felt frustrated by the processing fees. Can you elaborate on handling this yourself? Which EU country are you based in?

I'm in Portugal. If you put enough pressure, they release for you to process, it is the law.

Re: Thanks FedEx, this is why we keep getting phished

#557

Earlier quoted context omitted.

This comment just unlocked a new fear of mine. I specifically got a custom domain and email address for any non-personal/"professional" comms, which is essentially just me@ .com. At least with non-ASCII characters in passwords, while I think it is stupid to not handle those properly, I can at least see some sort of an excuse there, no matter how weak it is. All it takes to mess this up is not thinking about handling…

FWIW I have an email that is me@...org, and I've been using it for over a decade now without a single issue despite having lots of accounts created using it.

Same. I've had this 2-char email addr for nearly two decades and this is the only issue I've had, but it's a doozy. It even took their tech support days to find it. I'm still boggled that it's a problem.

Re: Thanks FedEx, this is why we keep getting phished

#558

Earlier quoted context omitted.

I love how those emails have extra metadata in the headers like "X-Phishing-Test: True"

Indeed, though the sort of person who knows how to read and understand mail headers is probably pretty unlikely to fall for a real phish.

Everyone has their weak moments where they’re prone to falling for a real phish.

Re: Thanks FedEx, this is why we keep getting phished

#559
post #444

Earlier quoted context omitted.

> just keep the parcel at the depot for a week until they have a driver who can actually make the trip. Depot workers can get up to the weirdest stuff. One time I was returning unused product (oil well perforating guns, a UN 1.4D explosive device) via Yellow Freight. I handed over the cases and signed all the appropriate paperwork to handover custody at the depot and went on about my day. The supplier called me ~10 d…

> dropped off oil well perforating guns at Yellow Freight Holy fuck. We never shipped these using commercial couriers, but transported them using company trucks and company labor. We'd also have a heavily armed security person escorting them at all times. For reference, these are long tubes containing many shaped charges. Sometimes you can have hundreds or thousands of shaped charges for a single perforation job. AFA…

> Holy fuck. We never shipped these using commercial couriers, but transported them using company trucks and company labor. We'd also have a heavily armed security person escorting them at all times.

The manufacturer shipped them to us via Yellow, so we figured it was the simplest route to return the unused items via the same route, since they're properly credentialed and insured and all. It was a specialty project (perforating the casing in a newly drilled geothermal well at depths not more than 100m) so we only used in the realm of a dozen 50# cases of loose perforating guns and built the strings ourselves, bringing the high explosives (det cord that made up the string, detonators) from our own magazines.

> AFAIK, the oil field is the only industry that uses shaped charges outside of the military. Their primary application is piercing tank and ship armor.

They're quite often used in demolition as well, to shear through structural steel members. I've used them to bring down warehouses, bridge decks, bridge piers/supports, assorted industrial buildings and even hand built some crude shaped charges when scuttling a ship. I once went down a fun rabbit hole ordering custom built linear shaped charges for a demo project that saw the LSC's used so deep underwater that the static water pressure in the cavity of the charge would prevent the penetrator from forming properly. It was an interesting iterative design process with the manufacturer to make a sealed unit that maintained an air pocket inside the device at those depths and would seal flat agaisnt the object to be demolished. All akin to military uses sure (especially that last one, i bet the SEALS or some branch of frogmen have underwater satchel charges or limpet mines handy but those weren't available to us) but this was in the civilian construction domain.

> Not a good thing to "go missing".

Not at all!

Re: Thanks FedEx, this is why we keep getting phished

#560
post #456

Earlier quoted context omitted.

A bank called me to ask me security questions. I said that I would call back using the number on the bank's website. They said (and the bank confirmed when I did call the number) that there is no way to be transferred to the security question people when I call the bank - the only way is for them to call me. I explained that that was poor security practice. They said that I should just look at the caller ID to see th…

It’s a real mystery why, as soon as I heard about a bank founded by people who sounded like they had heard about the internet (Monzo, in the UK), I switched away from my venerable bank (NatWest) that, at the time still had security practices unsuited for the 18th century. Appropriately enough, the last thing they did was to insist —demand, really— that, in 2018, I fax them my demand. It just so happens that this coul…

One of my favourite things about Monzo is they have a little thing in the app that tells you if they are currently on the phone with you to verify against anyone claiming to be them.
Post reply on HN