Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

91–100 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#91
post #79

Earlier quoted context omitted.

How do those booking.com scams work?

In a case I read (can't remember where), reservation data was somehow leaking (either from booking or from hotels), and scammers were sending messages purporting to be the hotel saying the room was cancelled or mischarged or something like that.

It's even worse than that. Scammers are sending messages through booking.com, so you get a message from the hotel, in your booking.com inbox, with a link to a payment site that just makes a payment to the crooks. The root cause is either hotel employees installing session-stealing malware, either accidentally or by being part of the scam.

Re: Thanks FedEx, this is why we keep getting phished

#92

There really needs to be some kind of cryptographic authentication system for text messages and caller ID that gives the recipient absolute certainty about the identity of the sender. Registering a name in this system should require real-world proof of identity including a business address and the contact information of real people. There should be serious financial penalties for identity fraud. It should be an open…

This will never work as long as calls and SMS messages are routed over the existing telecom networks. The infrastructure is simply too insecure to enable this kind of scheme.

If calls are routed over internet then it becomes more viable but obviously there is still a large coordination problem and misalignment of incentives.

Re: Thanks FedEx, this is why we keep getting phished

#93
post #80

I found a Reddit post today about a German bank mailing USB sticks containing their new general terms and conditions: https://www.reddit.com/r/de/comments/1ax7ky3/milde_interessa... You can't make this up.

(translation provided by ChatGPT) > Terms and Conditions, Price and Service List, Conditions. > Dear customer, > our price and service list, our terms and conditions, as well as further conditions which will come into effect on May 1, 2024, can be found on the USB stick. > With kind regards, > The Sparkasse Bremen AG

[flagged]

Re: Thanks FedEx, this is why we keep getting phished

#94

Earlier quoted context omitted.

I've never heard of this "EU law". Which one are you talking about? I live in the EU and my bank pretty much only contacts me through email.

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...

It defers to a repealed 97/7/EC, replaced by 2011/83/EU:

> Durable media should enable the consumer to store the information for as long as it is necessary for him to protect his interests stemming from his relationship with the trader. Such media should include in particular paper, USB sticks, CD-ROMs, DVDs, memory cards or the hard disks of computers as well as e-mails.

USB sticks are on the list, but so is paper and e-mail. This USB stick could have been an e-mail.

Re: Thanks FedEx, this is why we keep getting phished

#95
post #43
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Did you click on the "Report Phishing attempt" button installed by your IT center in your mail client? Sorry for the probable sarcasm. In a company that size, if the IT center does not provide a means to report phishing attempts then there are more serious problems than a dodgy email campaign.

This is even worse in companies that have security offices actively sending out phishing emails worded as internal emails from your company that shame you if you click any of the links in them.

email is well and truly dead.

Re: Thanks FedEx, this is why we keep getting phished

#96
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Regarding the external domain thing, I can say that dealing with domains in a big company gets about as bureaucratic and terrible as just about everything else; I experienced this myself - at a youngish company when I needed a new sub-domain off the big official domain, it was just talk to $dude on the DNS team and he’ll help you out. And he did. A few years later once things had “grown up” a bit, I needed to update a record and I asked the same guy. He told me I needed to fill out a 25 question form and they’d review it. I about half copy and pasted it from another team member’s project and they accepted it.

Obviously it doesn’t excuse the practice, but I can see why people use alternative domains to get things done. The above anecdote was also purely within the company; I’m sure that if you add in a partner/managed service, it only amplifies the complexity.

Re: Thanks FedEx, this is why we keep getting phished

#97
post #32

A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…

Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…

> The same guys also force us to change our passwords every 6 months and block the last twenty

It's good we have 26 letters, that comfortably leaves you a margin of 6 combinations :-)

Re: Thanks FedEx, this is why we keep getting phished

#98
post #2

Suggest Law: If a company's electronic notification to you is so phishy that a "reasonable man" would have obvious cause to doubt its legitimacy, then all financial and legal consequences of ignoring it are on the sender . Edit: " sender " here refers to the sender of the electronic notification .

The management will overreact by implementing 100-factor authentication, requiring 30 letter password with mandatory Unicode symbols

Re: Thanks FedEx, this is why we keep getting phished

#99
post #80

Earlier quoted context omitted.

(translation provided by ChatGPT) > Terms and Conditions, Price and Service List, Conditions. > Dear customer, > our price and service list, our terms and conditions, as well as further conditions which will come into effect on May 1, 2024, can be found on the USB stick. > With kind regards, > The Sparkasse Bremen AG

[flagged]

often, chatgpt translates better.

Re: Thanks FedEx, this is why we keep getting phished

#100

In a Blackhat talk several years ago Adam Shostak had a clever term for companies interacting with you in ways that were indistinguishable from scammers. But I can't remember what the memorable term was.

Anyone found this? Can you remember the episode?
Post reply on HN