Earlier quoted context omitted.
This is my major concern. Heaps of legitimate companies send emails with links to things like ' http://dh380. party server>.com'. We're being trained to accept this sort of silliness
I don't think it's realistic to live in constant fear of browser sandbox escapes, or to consider visiting an arbitrary URL "silliness." If your threat model includes people willing to burn Chrome 0-days on you, you need an air gap. The much more relevant battle is preventing credential theft, which you can solve completely at the technical level with U2F. And if you can't, user education on "check the URL before typi…
Launch HN: Riot (YC W20) – Phishing training for your team
91–93 of 93 posts
Re: Launch HN: Riot (YC W20) – Phishing training for your team
#92Pricing feedback. I would love this type of training for our small team of 12 people BUT at this time, I cannot spend $199/Month even though one could argue that there is no cost high enough for security. Perhaps add another smaller tier for companies with 20 or less employees in the 2 digit range ?
Re: Launch HN: Riot (YC W20) – Phishing training for your team
#93Earlier quoted context omitted.
I don't think it's realistic to live in constant fear of browser sandbox escapes, or to consider visiting an arbitrary URL "silliness." If your threat model includes people willing to burn Chrome 0-days on you, you need an air gap. The much more relevant battle is preventing credential theft, which you can solve completely at the technical level with U2F. And if you can't, user education on "check the URL before typi…
While I agree with you, I'm far less concerned for my family/friends/colleagues about a sandbox escape compared to accidentally putting information in to a malicious site