How do you get that authority to do that? What does "shut down" entail? Does that mean you can unregister or hijack domains? I'd like to know more about this, as well as the accountability process and where I can report abusive behavior that will actually get addressed.
No reason to ask at all honesty, it's just been one of those curios that pops up in mind occasionally
Typically a registry will just fwd it on to the registrar. That said, registrars tend to take complaints from the registry more seriously imo.
So I forwarded it to spoof@ebay.com with the message "reporting phishing email" or something. Somehow that report got "handled" by a clueless, non-technical, front line rep who thought I thought the email was real and was inquiring about the contents of the email. Pissed me off that the email wasn't handled by the correct department. I won't be bothering to forward any more phishing emails anymore.
You and I can tell the difference, but to the sort of people who run vulnerable servers, perhaps a legitimate email about server security looks indistinguishable from the others ("Hi I'm from Microsoft technical support. Please let me in to your computer to help you fix it").
Wow, that's a phrase I haven't heard in ages.
Most webmaster@ or admin@ e-mails aren't monitored at all, or so flooded with spam that it's easy for things to get lost.
That's not it, not all of the time anyway.
Over the summer I discovered a third party mail server with a missing DNS entry. It was like that for months and all their mail was getting flagged as spam.
I sent them an email (from an account that wasn't flagging their mail as spam) pointing it out. They fixed it within 24 hours but I never got a single reply.
Is it possible that they (perhaps mistakenly) believe that communicating with you could open them up to civil liability?
I'm curious, for vulnerability-by-inaction like this, would there be a legal difference if sent emails were posted to a public blockchain?
The intent being, if you're later sued for harm caused by your compromised hardware / IoT devices, you cannot claim ignorance as easily.
End goal, of course, being that people care more about patching their devices.
That's not necessarily easy to prove, in the same way the defendant could claim emails were trapped in spam filters, etc. or more realistically, the burden of proof is on the claimant so the defendant wouldn't say anything if they're smart.
There, nothing was admitted.
I would hope any well-intentioned and reputable company would not mind, but some might not want to admit any of that! Plenty of ammo for anyone who subsequently blames you if you then fail to remedy the situation in a timely fashion.
If the company is too small to monitor their own pages then I'd expect them not to be worried about this sort of liability (ie knowing of a breach, they're too small to be sued for much, presumably: if they were bigger they'd know about it already).
Both have an abuse / phishing declaration form online. I signaled both pages, and they are still up for the moment.
Politeness essencially disappears once you can't see somebody's face. 10 minutes in any online game should be proof of concet enough.
I also think the rude behavior is a combination of both anonymity and "I'm never going to see or hear from this person again".
But seriously, thank you for taking the time to do this.
They view the message as showing up a failure on their part and they do not want anything showing that they have made a mistake in some way. So, they do not acknowledge your message as it provide a means of tracking that failure.
For those cases where it is not fixed, there is no-one who cares to do so.
In the past, I have made communications with website admins about various aspects of their sites (non-security related) when they poorly relate to those of us who are getting older and have increasing eyesight difficulties. The usual response has been "No one else has complained, so take a long jump off a short pier - our site is perfect." I sometimes try to explain that people won't continue to visit if the experience is bad, nor will they bother highlighting that there are problems. They will generally still respond with "shut-up and go away."
You just leave them to their ineffective site and move on. Very occasionally, you get back a thanks and see improvements made, but that is rare.
* their IT person I think was really just the person who was best with computers.
I usually only notify .edu or nonprofit organizations and completely ignore large corporations. Sending an email to a larger organization usually gets lost and nothing comes of it.
Out of curiosity, do you receive answers at all?
If not, there could be a technical reason rather than the decline of human decency: your including the link to the phishing page gets the message filtered away by automated security software.
I can't be bothered to report it to them.
Have browsers extensions improved for this? When I last checked 5 and 10 years ago, it didn't seem to work.
I haven't looked into it in enough depth to be 100% convinced to trust it with my financially-linked passwords. (In reality, it's almost surely good enough, but I haven't reached that informed conclusion yet.)
[0] - https://www.blog.google/products/chrome/chrome-password-mana...
1Password X for Firefox and Chrome, 1Password on Safari have pretty much solved this problem. The vast majority of passwords I fill are CMD + [shortcut].
Generating and saving new ones works like that maybe 50% of the time. The failure rate however is driven less by the extension technology and more by the password form itself.
The obvious solution is to remove all users from the internet.