Live data from Hacker News

SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

fredbenenson.com

71–80 of 152 posts

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#71
post #62

> Can this be fixed? For popular senders: sort-of: in your incoming mail server, substring-match the display name of the sender against popular brands, and ensure the actual domain matches. This works remarkably well for proper brands (FedEx et al), but breaks down when the brand name regularly occurs in "normal" names, the sending brand sends mail from all over the place, or "innocuous" impersonation takes place all…

Use @ as your email address when signing up, and check the To header when receiving emails. And/or, long-press or right-click on any link to inspect the linked domain.

What fraction of people do you suppose actually have a to do this with?

Even some highly technically inclined people (like myself) can be entirely ignorant of the process. It's not as if consumer ISPs provide the service.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#72
post #60

I wonder why Gmail and other email providers don't just run an LLM/ML pipeline to detect phishing emails. It seems that matching an email's content with the sender's domain (and possibly analyzing the content behind links) would be enough to show, with high certainty, a warning like "Beware: this looks like a phishing email." Is it too expensive? Too many false positives?

To my understanding, they already do use some form of ML for this and it's part of how things get routed to the spam folder without explicit rules.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#73

relatedly, my wife received polititexts destined to her conservative father. The latest was actually genius IMO, in that it stated "Dear STEVEN, due to inactivity, your registration will be changed to DEMOCRAT in 20 minutes unless you navigate to this link." It, I assume, redirected to some support page to donate to the US conservative party or its affiliates. The social engineering is getting more effective

I don't know if the fact that it fully slipped into the absurd or the fact that it probably still worked on people is sadder. I do love the idea of voter registration oscillating back and fourth at 20 minutes intervals forever. Would make voting in the primaries way more exciting as the voter base kept flipping.

To me as a Canadian, the absurd part is that ordinary people are expected to have "registered" with a party (as opposed to registering with the independent organization that runs elections, like we do; they automate getting most of the voter roll from Revenue Canada, but this requires your explicit consent on the tax form).

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#74

We've been getting similar phishing emails claiming to be from SendGrid, except they're along the lines of "we're adding a rainbow banner to the footer of all emails to show LGBT support, click here to opt out". It's especially funny because SendGrid isn't even one of our vendors.

That example is in TFA.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#75
post #3

Before anyone launches themselves into the sky: the title is clickbait. This is about phishing attempts that use ICE to persuade you to click. Sendgrid the company is not emailing about supporting ICE. But technically Sendgrid the infrastructure is.

I seriously hope HN discourse has the bare minimum of “open the link and read it before commenting”.

That is the expectation but no way to enforce it of course.

What happens a lot, at least for me, is that people will start reading the comments to see if they want to bother reading the link. Then they might start commenting on what's already been said. It's easy to slip into that pattern.

Though you also frequently see top-level comments that appear to be based on the headline alone.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#76
post #73

Earlier quoted context omitted.

I don't know if the fact that it fully slipped into the absurd or the fact that it probably still worked on people is sadder. I do love the idea of voter registration oscillating back and fourth at 20 minutes intervals forever. Would make voting in the primaries way more exciting as the voter base kept flipping.

To me as a Canadian, the absurd part is that ordinary people are expected to have "registered" with a party (as opposed to registering with the independent organization that runs elections, like we do; they automate getting most of the voter roll from Revenue Canada, but this requires your explicit consent on the tax form).

This is just for primaries, you register to vote with the state as well.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#77
I received one, though it was for adding a footer honoring MLK. I kinda thought it was odd, but did't think much of it, since I'm apparently not in the group that would be offended in any way. I wonder if the variation they use is random, or in any way location-based to maximize response (I'm in Texas).

I've also received a bunch of API failure phishing emails, as well as some implying we needed to change our auth to Sinch.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#78
post #73

Earlier quoted context omitted.

To me as a Canadian, the absurd part is that ordinary people are expected to have "registered" with a party (as opposed to registering with the independent organization that runs elections, like we do; they automate getting most of the voter roll from Revenue Canada, but this requires your explicit consent on the tax form).

This is just for primaries, you register to vote with the state as well.

Still absurd that "free" "democratic" elections are allowed to require party membership, even for the primary.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#79
I can't think of one email I received from sendgrid I would consider legitimate. Anytime I receive an email distributed by sendgrid I have found it actually had no value to me. Sometimes it's from a business I have dealt with but I never wanted or was interested in the content.

Re: SendGrid isn’t emailing about ICE or BLM – it’s a phishing attack

#80

I can't think of one email I received from sendgrid I would consider legitimate. Anytime I receive an email distributed by sendgrid I have found it actually had no value to me. Sometimes it's from a business I have dealt with but I never wanted or was interested in the content.

Same impression. SendGrid, MailChimp, any of those are just enabling spam at the end of the day.
Post reply on HN