> Would love to hear your war stories on phishing scams, and how you train your teams! I was working on anti-phishing in 2003, before it had the name phishing. We were trying to teach our users not to fall for the scams. It didn't work. People will fall for the same scam over and over. The conclusion we came to was that the only solution to phishing was education, and education was also nearly impossible to get 100%…
> The conclusion we came to was that the only solution to phishing was education, and education was also nearly impossible to get 100% coverage. A friend works for a company that fires employees after failing three phishing tests. It doesn’t solve the problem for those people, but it does work for that company. What has priority depends on your management style :)
The only way this kind of policy makes sense is if you have to actually give the phishing site some kind of credential in order to fail, vs. merely opening on it.
If someone has a Chrome zero-day, we're done anyway. Just post it on HN.