Live data from Hacker News

Launch HN: Riot (YC W20) – Phishing training for your team

news.ycombinator.com

91–93 of 93 posts

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#91
post #72

Earlier quoted context omitted.

This is my major concern. Heaps of legitimate companies send emails with links to things like ' http://dh380. party server>.com'. We're being trained to accept this sort of silliness

I don't think it's realistic to live in constant fear of browser sandbox escapes, or to consider visiting an arbitrary URL "silliness." If your threat model includes people willing to burn Chrome 0-days on you, you need an air gap. The much more relevant battle is preventing credential theft, which you can solve completely at the technical level with U2F. And if you can't, user education on "check the URL before typi…

While I agree with you, I'm far less concerned for my family/friends/colleagues about a sandbox escape compared to accidentally putting information in to a malicious site

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#92

Pricing feedback. I would love this type of training for our small team of 12 people BUT at this time, I cannot spend $199/Month even though one could argue that there is no cost high enough for security. Perhaps add another smaller tier for companies with 20 or less employees in the 2 digit range ?

100% agree. CEO of 13 people services biz here. We're currently priced out of this when it could actually be useful. One thing of note: when we consider security tools / training, monthly is not the right frame of reference. It's either brought back to a daily expense (i.e. how does it compare in my daily costing vs. billed revenue per day), or annually, compared to an insurance premium. I know ho much my cyber liability insurance costs me and it's easier to compare on a yearly basis. FWIW, it would be an instant buy for us at 199 per year. Above this, it'll fall in the budget security bucket and under comparison with others.

Re: Launch HN: Riot (YC W20) – Phishing training for your team

#93
post #91

Earlier quoted context omitted.

I don't think it's realistic to live in constant fear of browser sandbox escapes, or to consider visiting an arbitrary URL "silliness." If your threat model includes people willing to burn Chrome 0-days on you, you need an air gap. The much more relevant battle is preventing credential theft, which you can solve completely at the technical level with U2F. And if you can't, user education on "check the URL before typi…

While I agree with you, I'm far less concerned for my family/friends/colleagues about a sandbox escape compared to accidentally putting information in to a malicious site

Yes, and "consider the URL and how you got there before typing in your password or credit card" is a lot more realistic than "don't click links." Still, clicking the link fails the phishing test all by itself.
Post reply on HN