Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

81–90 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#81

Your security is increasing at risk from organisations and corporations whose own grasp of security is appalling. Because instead of dealing with it they externalise risks and consequences onto the public and customers. Even worse, is where attempts to query that security is actively punished . This is typical now. Listen here (at 42:20) with an example regarding the UK NHS whose incompetence plays directly into the…

Even worse, is where attempts to query that security is actively punished.

like this case: https://news.ycombinator.com/item?id=37250024

Re: Thanks FedEx, this is why we keep getting phished

#82

Earlier quoted context omitted.

I've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.

For some things, you must use paper (or as it turns out, USB). Why the bank decided to use USB for this purpose, instead of paper, is very strange.

Here in Poland, I've already had several banks and at least one insurer send me CD-ROMs. Never heard of anyone sending USB sticks before, but I'm not surprised. The problem is, approximately no one owns a CD/DVD reader anymore, and there are no modern read-only physical media. With SD cards also going the way of the floppy, USB stick is just about the only medium you can hope most customers have means to read.

Re: Thanks FedEx, this is why we keep getting phished

#83

The biggest banks and brands in India as well as the government organizations do this type of poorly thought communications all day. The other day an email from the oldest and biggest bank of India landed in my inbox Truncated Subject line on mobile said "Cash Withdrawls made ..." My heart skipped a beat because I did no such thing with my account. Turns out it is a marketing mailer with subject "Cash Withdrawls made…

Well, the marketing person who came up with message can pat themselves in the back because you bet the engagement on that one was thru the roof.

Re: Thanks FedEx, this is why we keep getting phished

#84

Earlier quoted context omitted.

I've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.

For some things, you must use paper (or as it turns out, USB). Why the bank decided to use USB for this purpose, instead of paper, is very strange.

Danish institutions (including banks) seems fine with PDFs.

I think that's shown by the post statistics: around 25 letters received per resident, per year.

I can't remember the last letter I received which only contained papers.

Re: Thanks FedEx, this is why we keep getting phished

#85
post #27
post #9

Not that I’m endorsing the use of smart phones, but FedEx does have a mobile application. Why not just use that for notifications regarding deliveries?

You mean everyone should install a piece of software from a company that appears to be ignorant about security?

And buy a very expensive tracking device with frequent security issues?

I am lucky to live in a country in which a large religious population eschews the smartphone, so saying "I don't have one" is acceptable and common here. But I have colleagues who tell me that they are expected to have a smartphone from everything to banks to government services to simple small restaurants.

Re: Thanks FedEx, this is why we keep getting phished

#86
post #36

Earlier quoted context omitted.

Clearly the safer option is sending the terms via CD https://t3n.de/news/sparkasse-digital-strategie-cds-per-post... Since no-one has a CD drive in their computer anymore, the security risk is negligible

The CD contains PDF with scanned terms and conditions?

Since nobody has cd drives anymore, I don’t think it functionally needs to? You could save on shipping costs by just mailing blank disks instead, plus hey free disks! It’s like aol all over again.

Re: Thanks FedEx, this is why we keep getting phished

#87

Earlier quoted context omitted.

I've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.

For some things, you must use paper (or as it turns out, USB). Why the bank decided to use USB for this purpose, instead of paper, is very strange.

[deleted]

Re: Thanks FedEx, this is why we keep getting phished

#88

Earlier quoted context omitted.

There's an EU law demanding such documents to be delivered on a "durable medium". Some banks and financial institutions may have a strange approach to those, even though email attachments seem to be enough for others.

I've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.

Likewise. I have multiple accounts across different EU/Eurozone states and with the exception of the original contracts that I've had to sign to open said accounts, I've never had to deal with anything other than e-mail or in-app communication.

Re: Thanks FedEx, this is why we keep getting phished

#89
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Healthcare companies in the US send the most scammy looking links for payment processing you’ve ever seen - things like my-healthcare-billing.net

It’s insane.

Re: Thanks FedEx, this is why we keep getting phished

#90
There really needs to be some kind of cryptographic authentication system for text messages and caller ID that gives the recipient absolute certainty about the identity of the sender. Registering a name in this system should require real-world proof of identity including a business address and the contact information of real people. There should be serious financial penalties for identity fraud. It should be an open standard that can be implemented in open source software. And all the big phone manufacturers should be legally compelled to use it.
Post reply on HN