Should Failing Phish Tests Be a Fireable Offense?
krebsonsecurity.com
krebsonsecurity.com
They also did have a reporting system. Presumably you wouldn't get a strike if you clicked and reported. People who reported "legitimate" phishing attempts were rewarded. Spear phishing is a totally different game and nobody in their right mind would fail people for clicking on a (well crafted) spear phishing email.
I would add in my proposal that if a percentage of employees under a director fall for it, the director gets let go. If a number of directors are let go, the C-Level is let go and so on.
I mention the pencil whipping because I have seen financial institutions put on a really good show, but under the covers they are not doing proper management of ssh key trusts, ssh multiplexing, port forwarding, sudo or network access or encryption keys and they know which engineers to put in front of the auditors.
I only entered that area once, as I was a low-level programmer.
It was also the only company where I never ever made a query on the production server :) (I worked for another financial institution on a more senior role and I did have scary access to the production DB).
They have to compromise between security and keeping it easy for people to apply.
The more companies that have complicated application portals, the fewer applicants they’ll have. Particularly from occasional job-seekers that already have other jobs.
how did it get you, if you don't mind sharing? It seems if someone who works in IT (guessing you do) and is very careful fails it, this is an impossibly high standard to meet.
curious how they got you.
The email was a newsletter I didn't care about, and the unsubscribe link was (fake) malicious. That one impressed me because it preyed on what is now a pure reflex to click the unsubscribe link.
The latter is why password managers can be so valuable. I never type my passwords in so if my auto-fill doesn't activate I immediately become suspicious.
If it's the former, it seems like your company must be using an insecure browser or the site was running some kind of 0-day? I never think twice about clicking links.
I hope you don't work for any sensitive position.
AFAIK most enterprises don't mandate ad blocking or noscript.
I've heard more people at enterprises using ad blockers for security so I wouldn't rule that out but in general this is hitting that the broad vs. targeted distinction I mentioned: each time you use an exploit you're risking discovery, which will lead to it being patched & AV signatures going out. Using an ad network increases the number of people who are not your target getting the payload, not to mention any scanning the network does, and since ad networks require payment there's another trail pointing back to you which might not otherwise be the case if you are hosting things on compromised servers.
If Firefox or Chrome has an RCE + privilege escalation in it that can be triggered just from browsing to a page then, congrats, you got me.
https://news.ycombinator.com/item?id=20028108 from earlier this week shows that just loading a page can lead to network information disclosure or other compromise / attack vectors. It's not a zero-day, it's a feature.
Just starting your web-browser would exécuté some Java vuln and scareware you.
https://thecoinshark.net/microsoft-email-clients-was-hacked-...
The breach centered around a hacker getting hold of a Microsoft customer support worker’s login credentials; from there, the hacker could dive into the content of any non-corporate Outlook, Hotmail, or MSN account
This is a security concern for any mail that an administrator can read, although it isn't at the same level as being compromised just through parsing an email.
[0] https://www.vice.com/en_us/article/xwndwn/microsoft-outlook-...
For the remaining 99.999% of the population, I really don't think opening a web page in an up-to-date browser is cause for concern. Certainly if that browser is also in a VM. People have more pressing concerns in their lives.
That's a learned trait. I don't click unsubscribe links; I click "report spam" and "report phishing" button.
If only Gmail would let me create filters to automatically mark entire domains as spam though. That would be nice...
If you got my email address because I applied for a job, then I do not want to be marketed to.
If you got my email address because I signed up for a service, then I do not want to be marketed to.
If you got my email address because I purchased something, then I do not want to be marketed to.
If you got my email address because someone else "legitimately" entered my email address into your field, then I do not want to be marketed to.
In short: your definition of "legit" likely does not meet my definition of legit. The only email that I deem to be legit is an email that:
1) is @from a domain name that I recognize (walk like a junk, talk like a junk, it's junk) 2) is @from the same domain name as the correspondent (no third party bulk email or proxies; eg mailchimp et al) 3) does not have a no-reply@ as the reply-to address (I must be able to talk to a human) 4) does not hyperlink to third party domains (from@domain must match hyperlinked domain text)
Any legitimate email outside of those parameters are specially treated with liberal amounts of filtering.
This is the nature of any relationship. You can't be ruthless in eliminating aspects you don't like, if you don't want to end it entirely because it's net positive.
You are incorrect and interpreting my comments very narrowly.
Doing specific business with somebody should not give that somebody carte blanch to use my email address for whatever reason they wish. I absolutely can be ruthless in eliminating aspects I don't like and if businesses don't like that: tough shit. My world doesn't revolve around your business. If that means that the business relationship ends right there, then I'm better off for it.
I know it sucks when an IP gets burned, but when you're acting in good faith it's a rarity - or has been in my experience.
I have filters for almost everything, my boss goes into one folder and gets set one color, automated notifications from my internal system another (green if everything is OK, orange if there is something I really need to look at).
What I really* want is a desktop client that exposes a nice clean Python (or similar) API so I can automate even further - I mean Python has everything I want if I want to do that from the CLI/cron but having it built in would be really nice.
As I’m the head techie (by dint of been the only techie) , I’d be the one purchasing from them in the first place.
I find a filter that sends everything to Marketing/Hardware and marks as read fairer than flagging them as spam.
If you filter out all the people telling me they’ll be out the office, birthday announcements etc, all the vendors trying to sell me stuff and all the automated stuff (which I do automatically), I get less than 5 emails a day (I put my boss on Trello, it’s just better for what we need) which I check once at 11 and at 10 to 5.
I’m ruthless about my time since I’m the only programmer.
I automatically unsubscribe people who mark email as spam but lots of marketers dont do that so you will still receive emails.
Most legitimate companies will respect the unsubscribe links as that is required by law and they invested more infrastructure around that functionality.
I wouldn't click on links from phishing attempts or emails from sketchy services I never signed up. Anything semi-legit is better handled through the unsubscribe link first.
That way they’ll also protect themselves against an external vendor that gets used to spearphish you.
Firstly all external senders have the mail reformatted with a red bar at the top and some text, and secondly all hyperlinks are forced through a proxy, which makes it effectively impossible to know what the URL is from the email.
I'd received a (rare to my work account) fishing email and I was about to click on a link in there just before I started thinking. I'd been trained to trust emails with the red bar, as most external mail I get is trustworthy, and I reflexively check links before I click them but this was just another going through the proxy.
I'm not sure how much these changes help less technical users, but it made me less secure.
It's the same reason you automate things. People make mistakes. It's not about messing up once. It's about always being absolutely positively sure that you aren't making a mistake.
If you've ever clicked on a link from an email, you are vulnerable.
Even trained intelligent people have momentary lapses of concentration. Imagine opening a link from email on your phone then looking away for a second while it loads, but then the address bar has disappeared and you've missed the ssl indicator.
I mean, sure, if it's 20 times, we're getting into outrageous territory and you have reasons to suspect employee is trolling you. But other than that, the reality is that your employees _will_ get phished eventually. Reduce the risk and work on reducing the harm caused when it happens, instead of antagonising your workforce.
Edit: also, if you could just "filter out" the test means that the tests were about as good as most corporate "compliance" training is. Just as the firings, it feels designed more to coddle the C-levels than actually achieve anything.
...there is no way you can equalise "you're going to lose your job" with anything less than "we're going to give you enough money that you won't really need the job anymore."
And with a Starbucks card or casual Friday? I'm not even sure if you're being serious, because that sounds like a joke.
Both of these things together leave a system in place where:
users are highly penalized for failing a phish test (or real life phishing attempts)
User's that fail the test (or real phishing attempt), but follow it with a timely notice have less pain.
Users that notify on apparent phishing attempts get small rewards.
That does not seem like a joke to me.
a) Some test phishing urls include the plaintext mail address of the employee. Easy to retaliate against someone you don't like.
b) Does the phishing test service detect if the link is accessed via a sandboxed env?
Does it really matter? I used to play these games with my org's absurdly obvious phishing trainers, but the truth is it's not my job to determine whether an apparent phishing email is genuine or not. If you know that getting phished is a fireable offense, then just don't access the links, obvious fake or not.
I forward all emails that are not directly from people in the company to the trash.
I also forward anything with the word "phishing", "test", "audit", and our our IT and security department.
The other strategy I have is simply not checking email.
This is so useful, while others are taking security test, and failing phishing link test. I am in the clear.
What test? I did not get the email. You clicked what? Humm, I did not get that email. Man you got a virus -- I run Linux and access my email via Emacs/Mu4e -- also I did not get that email.
All problems solved!
In any company likely to be doing phishing testing internally, there are two kinds of people who might try this. One is the infosec group, which isn't going to do this because they're running the test. The other is engineers who think they're clever and are equipped to fsck around with things.
The former are professionals. The latter are dangerous and not actually an exception. The frequency with which their confidence is justified approaches zero and in the vast majority of shops simply not worth the time it takes to contemplate.
A good infosec group is a wonderful thing. It's unfortunate that you don't have one.
That sounds about right. Your average developer dealing with malware is roughly as safe and sane as playing pool with 6-kilo balls of pu-239. Especially since a lot of places, developers are trusted with things like access to production from their workstations.
> This is a site called hacker news, if you're a web developer and you can't figure out how to pull an html page without executing the scripts involved (a TRIVIAL thing to do) you shouldn't have a job.
You know what's interesting? Even if you can do that, you've already made a mistake and leaked information. You've demonstrated for an attacker deliverability, who is curious and amateurish enough to think they can handle it (but hasn't thought it through), and some useful information about how they believe they are protecting themselves. Fetching a malicious server's HTML safely isn't as easy as might be readily supposed - both curl and wget (https://www.cvedetails.com/vulnerability-list/vendor_id-72/p...) have suffered remote exploits in the past. Those are almost certainly the tools a random dev would reach for and they cannot be assumed to be safe. The odds that said random dev is equipped to set up a sandbox to do so reasonably safely are not great, and the odds of them doing so much smaller.
Curiosity isn't a bad thing. It's a wonderful and powerful trait that has driven humanity relentlessly forward through the ages. Unfortunately, it can also be used against people. Being curious when playing with fire can be dangerous. Especially if you just think the fire is pretty and haven't figured out that it burns yet.
This site may be called hacker news, but it's not full of the kind of hacker that congregates at DEFCON and understands the House of Prime. It's full of the other kind.
Look the problem with this kind of attitude is people take security less seriously when security experts go overboard. It’s classic boy who cried wolf. If you want people to take security seriously it starts with honest conversations where you treat people like adults and don’t immediately go to hyperbole.
Adults are perfectly capable of believing that their expertise extends further than it actually does and taking risks they do not fully understand or appreciate. I see it daily in the developers I work with. I have worked with more than one developer brimming with confidence in their ability to tackle areas beyond their expertise, who will try to engineer on-the-fly around any shortcomings pointed out in their approach (this is unrealistic, in real attacks adversaries don't give you friendly feedback iteratively).
I'm plenty willing to listen and take on board feedback here. What attitude should I take? How do I convince responsible adults, in a constructive and serious way, that they are not equipped to entertain their curiosity in this arena and should not try? How should I communicate to you, and to hundreds of developers at once, this message without going overboard or crying wolf?
It's one thing to play with malware and phishing at home, on your own hardware, on your own network, and with your own data. That's all your own risk to assume as you like. It's quite another to do so with company hardware, network, and data. That's not your risk to run and not your risk decisions to make. If you can advise me on how to communicate this to engineers who honestly and earnestly believe in their ability to safely handle things well beyond their expertise, I am absolutely all ears.
Here's what you can do: tell them what can go wrong, with specifics, and don't make assumptions about them. Be realistic about what the likely consequences are and what the worst case is.
If we wanted perfect security we'd never connect machines to the internet and superglue the usb ports shut. But in a realistic world, the level of security we choose is measure against how much risk we're willing to take. Lets say my risk profile is this: I don't work for the NSA and I'm not important enough that someone is going to try a unique zero day exploit on me. But it would be trivial to figure out my work email based on my linked in and my name, so I don't really care about them discovering deliver-ability. If the phishing attempt is bad, I'll probably spot it immediately and not bother to even open the email, but if it's good I'll probably at least investigate because I'll want to know if it was a legitimate email. Chances are, they're just trying to convince me to type my password into a web form (and assuming I use the same password everywhere). Of course, chances are also that, just based on my past experiences, about 90% of phishing attempts come from corporate security departments anyway. If someone really has a very clever zero day exploit of wget then they'll get access to a container with little sensitive data that I rebuild about a hundred times a day.
Yes it's not my hardware, but on the other hand, my company has entrusted me with local admin to get my work done and use of the internet. That's the risk profile they're comfortable with, and sometimes I get external emails and need to figure out if they are legit or not, and I don't work for a giant company with a huge security department so sometimes I need to take a glance to see if it's a legit email or not.
My only issue with what you've described is that I cannot scale it. When I have hundreds of developers to educate, sitting down with each of them and spending hours hashing out what they do and don't know and educating them over the gaps can at times become somewhat time-consuming.
How do I deal with hundreds of developers, the vast majority of whom have no significant background in security, many of whom earnestly and honestly believe that their understanding of web development protects them? How do I collectively treat them like adults and not lose their empathy or attention in a scalable way? A highly individualized approach isn't workable in this context.
* That their attack was delivered successfully to inboxes.
* What email addresses are live.
* Who is curious enough that they will investigate.
* Who believes they understand and can handle the risks.
These are not small things for an attacker to learn. Further, in a world where drive-by browser attacks are real, it's worth thinking very carefully if clicking a link in a phishing email should be regarded as essentially harmless.If the company just says "don't do it" there is still social pressure to be polite and not slam the door in someone's face. But if there are consequences that everyone knows about then no one is going to begrudge you if you tell them they have to swipe their own way in.
Heck, put up signs that say "allowing tailgating is a serious offense" so that visitors are aware as well.
Tailgating is a problem for your physical security staff, not your run of the mill white collar employee.
It's one thing to say "don't let people tailgate", it's quite another to actually enforce a policy that says that unless you provide proper physical security onsite. During security awareness training I always stress that people know who to notify onsite as well as telling them that they can choose to challenge them directly if they encounter someone tailgating.
99.99% of the time, saying to the tailgater "you need to swipe" is enough. If you do work somewhere where people are physically trying to break in often, then you ought to have real security personnel.
My employer recognizes this and uses mantraps to physically prevent tailgating at unguarded entries.
The implications are enough to make it a shitty situation for such a person have to turn around and say "sorry person that looks c-suite, you can't come in with me."
I’ve done it to VP level and I’d do it to my CIO too. I’d be that guy who badged the CIO but I try to take basic security and company policy seriously. I’d like an intern who is professional enough to “challenge” someone. Not sure I would’ve at that time.
We had a secure building with glass entry turnstyles. In my second week, a suited important-looking person was standing behind the gates at 8:20AM (we started at 8:30AM). It was busy and everyone was ignoring him (that seemed odd).
The suited guy picked me from the line of drones going through the turnstyles and asked if he could jump in behind me (he didn't even mention if he worked for the company).
I was still doing the HR training program stuff (the general wear deodorant, don't plug in flash drives from outside, don't ask for teamviewer, etc stuff) and the last thing we did the day before was end on the tailgating policy.
I told the suited guy that I couldn't let him in due to company policy. He smiled and said "all good" and went back to the corner.
He ended up being the head of logistics. Apparently, he liked to scope out the new hires and "test" their compliance. He tried this with 5 or 6 of the new hires and only managed to get let in once. The lady that let him in wasn't fired, but she did get a warning.
It’s also a safety issue. In a building evacuation, you should be able to account for every employee or visitor.
https://www.msn.com/en-us/sports/tennis/not-so-fast-roger-fe...
Rules are rules in Australia, even if you are a 20-times Grand Slam champion and one of the most recognizable people on the planet.
Roger Federer found that out this week when he was blocked access to a locker room at the Australian Open by a security guard who took his job very seriously.
A video circulating Twitter on Saturday showed the Swiss double defending champion stalled at the entrance for lacking his tournament accreditation.
Electric mortise locks and strikes will click, though sometimes they are held in unlocked state for a few seconds so you won’t hear a second click, or the second click might be reverting to locked state. Depends on hardware and configuration, and maybe a what the person in front is doing with the handle, and when/whether the exit sensor trips. Different things on the door can make clicking sounds, they’re a bit different from each other, but pretty close. Magnetic locks, forget it. Sliding doors, forget it.
I’m an engineer interested in security, I pay close attention to these systems, I’ve run their cabling and installed their admin panels, and I doubt I could tell even if I were actively paying attention.
I wouldn’t expect any physical force to be used. If asking politely doesn’t work, call security. If they threaten you into letting them in, comply, then call security.
We don't actually. All sane employers have them record and report the incident and not engage, because petty shoplifting isn't worth somebody getting shot and it's built into the margins anyway. If the store is big enough, they may have "loss prevention", who are people who are very much not tiny and will verbally engage the shoplifter and pretend to be scary, but they are also not allowed to engage physically, because again, it's not worth somebody getting shot, and liability is going to be a nightmare even if they were stealing.
If building security matters you implement mechanisms to enforce it, not burden all your employees with taking up the shortcomings.
Tail-gating should be impossible if you care about security.
If you’re just trying to ensure only employees are on-site, tailgating is less of an issue (unless somebody got fired but their colleagues were never told).
I have zero experience with this, but I imagine the policy would be "Don't enter the building if someone is too close behind you."
If you don't feel comfortable asking for space (fine!), turn around, go back to your car, and call building security as necessary.
Is this shortsighted?
After the incident, he was contacted by the building management, who asked him what happened and warned him not to do it again.
This seems like a reasonable policy since many people would not have thought in advance what to do if a potentially threatening person tries to tailgate.
We have the advantage that all entrances end up going through a central area, and we have ample camera coverage, such that security can reliably find people who tailgated if they are informed.
Tailgating is actually a very frequent and problematic occurrence for us, sometimes by people who will be aggressive, and this has seemed like the safest solution for us.
We have passcarded doors and then inside we have gates like many subway stations do that are timed only long enough for one person to pass through.
So I can hold the door open for someone on the way in—especially if they have their badge out— but there's nothing I can do about those giant plexi gates once inside. They have to swipe.
And since they’re entry and exit, there’s many methods to enter by triggering the exit side, from umbrellas to a small dog.
The specifications for those gates almost certainly include a requirement that they allow a sufficiently determined person through without breaking themselves, and probably sound an audible alert.
The gates at my work are enter/exit as well but we have to swipe out.
The social stigma, unpredictability and inconvenience of having to pay the fine is a big part of it (not having a ticket is just stressful). Another part is that you don't need to prevent freeriding, nor recoup all the lost ticket sales. You just need enough of a nudge to keep most people honest most of the time.
Obviously "not having too many unauthorized riders" is a very different objective from "only allowing authorized access and refusing all else".
Nuisance riders are: disturbing peace, damaging proprty, assaulting passengers or staff.
Police behaviour, not fares.
(And have social and justice systems which can effectively deal with individuals in need of help or discipline / isolation.)
They allow one authorized person to pass from one side through but sensors on both sides can easily detect if another person is trying to piggy back from the other side of the door. And there's no way over or around them. In higher security environments where unauthorized persons getting on the other side of the door is already an unacceptable risk they can also allow security personnel to trap someone in the door (rotate only 90 degrees).
And as far as usability and efficiency goes, they can allow traffic both ways at the same time (as long as both people are authorized).
Granted, they might not know the difference between one person and a handcart versus two people where one is in a wheelchair, but I doubt many would-be infiltrators would draw attention to themselves that way.
They also have people who go out and try to tailgate, and say they left their badge on the other side of the door and ask if you can badge them in, or let them borrow your badge to get theirs. If you help, they walk in and get security and HR and you're done.
There is no point in badging an unlocked door, or in expecting people to do so. You have to actually close it between entries. This is a physically and socially ridiculous thing to do with traditional doors; if it's what you want, you need a turnstile.
The whole idea of 'challenging tailgating' falls apart because someone walking in after you is not performing a strange act.
You would have to actively close the door _on_ people, including your colleagues, which goes against social norms to such an extreme extent that it's just not happening.
Some people do ask for the owner of a badge to do a second pass but security always appears at that point.
At first I thought it was weird, but since being here I've noticed more and more unmarked and federal police vehicles parked downstairs, and several offices/floors that are unlabeled and used mainly by those guys.
I'm guessing there's some kind of diplomatic etc services that go on here which not everyone's privy to.
I agree, this should only be for 'positive' results (getting hooked).
"No tailgating" can be supported through decent vetted entrances and exits.
"No phishing" could have mailserver and mail client support to properly flag the origin of emails and/or enforce "no remote loading" or "restrict html" or "check attachments" sorts of things
You can contact security, presumably a company with such a policy has 24/7 on site security.
I think some kind of strike system is completely reasonable and if you’re working on sensitive information or systems then phishing most definitely needs to count as a strike.
How could you ever possibly know that?
I got caught by a phishing link once because I had just gotten off the phone with a co-worker John and got an email 5 minutes later that said "hey James, it's John". Didn't even think twice about clicking it.
This is the key. If you think security teams aren’t hated enough for having to change your password every 90 days. Just wait until their “games” are the reason for people getting fired. This is a guaranteed way to get your users to not only not want to help you. But actively work against you. And if enough people scream the C ring will eventually listen. And I don’t think the security team will win.
I think there are probably a great many sysadmins, security analysts, and ciso's who can only dream of a day when run-of-the-mill employees are having casual conversations about phishing and identity security at the office.
It creates distrust.
That is why you pay consultants. They send out the phishing test, and hopefully regular people bond with the security people in an effort to pass it.
I mean, after all, security and regular people in the company should want the same thing (company success... which implies not giving away things to phishing probes)
Not destroying the company through your own negligence should be basic standard practice. Repeatedly failing a phishing test even when given proper security education (like PhishMe provides) is negligence that can destroy an entire company.
I worked in security at a company where the IT security department didn't report up the IT chain but was under HR alongside the Internal Audit department. Enforcing policy and holding people accountable were fundamental expectations of our managers all the way up, no different than someone repeatedly harassing a coworker or watching porn at work.
The issue is that people are trained and required to ignore warning signs most of the time, so it is impossible to crack down too harshly.
Employees by definition do not really care about destroying the company, because they do not own it and can walk away if they like. So the company does not have unlimited leverage over them.
A problem here is that a company whose leadership is receptive to your argument would probably already have mandated some form of security/phishing training. The ones who are likely to fall victim to these problems are the same types who do not plan for this stuff to begin with, and also would not be receptive to your hypothetical argument, imo. (e.g. "I don't have time for thought exercises, how many performance bugs have you fixed this week!?")
The path to victory is far more often along the lines of teaching your leadership to care for themselves about security, rather than trying to beat them over the head with heavy-handed hypotheticals of doom and gloom if they don't listen to you and do what you say. They need to feel it in their bones themselves. Otherwise you're never going to get cultural buy-in from the rest of the organization.
... by George W. Bush...
... in 2004 (Homeland Security Presidential Directive 12, HSPD-12).
Even Google has recently given up on passwords.
then throw in all the people excluded from being judged and it can affect morale to where people get ambivalent about other security issues.
"Opening an email" is not actually an issue (spearphishers that sit on drive-by 0-days in current browsers or email programs are not a threat model that most orgs can possibly defend against). Opening attachements is hard to measure and again needs context: What kind of software and sandbox was the attachement opened with? Attackers using some ancient forever-day word processor exploit is realistic. Attackers sitting on fully patched VM outbreaks is unrealistic. If the used VM has unimpeded network access, then the attacker needs no VM outbreak. If the target opens a phish link in a current browser, but then refuses to enter valid credentials (because user is wary), then the user can be argued to have passed the phish test.
If you make failure fireable, then you need to demonstrate that the victim was actually successfully phished.
If failure requires remedial training, then you can afford a high false positive rate: Clueless victims learn not to click on links, and sophisticated "victims" get to talk with a security person about why their action was dangerous or harmless, and in accordance or in violation of policy.
In a world with drive-by exploits and where opening a link leaks information, it perhaps could be considered unsafe to open essentially random links from emails. I've definitely worked with developers who seem to believe that curl is magical and inures them against every possible attack.
Curiosity is a wonderful thing! It's just sometimes it can be dangerous to a person and to the people around them. It might not be a bad thing for people to learn a smidge of caution.
I was promptly informed that I had failed the test and I would be receiving a formal reprimand.
Did that make the company more secure?
"But... this employee has been dead for 20 years..."
id=SSBsaWtlIFN3ZWRpc2ggUGhpc2g
Curiosity shouldn't preclude security, and intent shouldn't preclude policy if the operator operated knowingly.
This isn't to attack maxk42, but to engage the question head on.
Oh boy, I hope I never work in this kind of organization.
I think a reasonably paranoid approach like "Hackers might think of ways to abuse this that I haven't thought of" is best. Unless your job is to take a risk and visit a phishing site, don't take the risk. Even with Lynx.
[1] Exactly what an attacker would say!
Which you're giving away any time you browse any external web site.
>Lynx supports cookies too so it would be possible to track a user between sessions.
You're downloading cookies for most external web sites.
If the worst you do is the same as going to espn.com, then reprimand people for going to any external web site.
But your point is spot on, don't take it upon yourself to do things that aren't in your job description. Otherwise you become that person who takes it upon themselves to "fix" things and makes the problem worse for the people responsible for fixing things.
I made my own signs for wayfinding (Main Building ——>, and “Floor 7” when the stairwell was missing it).
Some are still up a few years later.
That's a great way to never go anywhere in your career.
I know you say the team would be pissed, but it's actually the exact opposite! Firstly, most sophisticated companies have automated the abuse inbox management process, but even when it's not automated, I'd rather 100 easily ignorable reports about boner pills than one person not send an actual spear-phishing email. Plus we can use the generic spam reports to better train our spam filters so please do keep sending them, even the Nigerian prince stuff.
It may not be a perfect approach since we do use it for MFA...
It would also be interesting to hear whether someone actually considers me to have failed anything when visiting a (faux) attacker’s link on my own device off the company network and entering no credentials.
Whilst that information might not be sensitive it could be used at a later date to extract sensitive company information.
There should be a line drawn between real security-conscious workplaces, and the kind of self-important chickenshit places that seem to delight in playing games and harassing their employees with this kind of thing.
Users know what phishing is, even the most naive of them. You need to do your darndest to make sure nothing gets in to your network first off. If people are repeat offenders then you have to chat with them first off and figure out what's going on . If they're being intentionally obtuse - clicking emails to see what happens even if they know it is phishing - then look into firing them, otherwise just act like you're on the same team, provide them with education but not overwhelming amounts, and it s eems to work has been my experience anyway
Seriously, you should give people who fail phishing tests cupcakes and additional future phishing tests. If there is a continued failure or inability to learn then there is a problem to be fixed perhaps with firing.
Cultures of fear breed disaster.
This usually happens, especially if they're using something like PhishMe. If you fail the phishing test, you're immediately told you were tricked, and scheduled for mandatory training within a few days. After you complete the training you're put on a re-targeting list.
What we're talking about isn't firing someone for making a mistake. It's firing someone for gross negligence over and over again even when given proper training and incentives. At some point it becomes clear that the employee is a danger to the company. If they're that careless with their emails even after getting caught and going through training, what else are they neglecting to do? And who might be injured/killed because they don't care?
It's definitely true that anyone can be spearphished or can fall for a sophisticated enough phishing scheme, but if someone is continually failing the most basic phishing tests (responding to random emails asking for your password for example) I think that's grounds for firing.
It's akin to locking up after you leave. Is it a fireable offence to fail to lock up the office when you leave? Probably not the first time. But if you never lock the door, at some point it becomes a liability. Sure a professional could break in even if you lock the front door, but it's not like locking up is pointless.
On the other hand, firing a front-line call center employee because they failed the spear-phishing tests is fairly pointless and more damaging than helpful.
Where exactly the line falls would be up to the business and like so many things, involves too many factors to be reasonable to discuss here. With the typical concentrations of power and authority in a business, it's only going to be the minority of employees that would be faced with termination for this problem, because only a minority will have the power to do significant damage to the business in general.
I think it's not too difficult to think that the article is mostly talking about the situations where it isn't proportional to the degree of damage that can be done by the employee.
The email itself looked like a standard spam email, but the link was really weird, having a few tokens as part of a query string. Normally fishing emails have simple URLs in them.
So I did the obvious thing of opening the link in a fresh, zero data, locked-down VM just to see where it would take me.
I got the message that I was an idiot, and my company also was notified that I'm clueless about information security.
I can only imagine how difficult it might be to explain to someone what I had done, and why I probably shouldn't have to go on some tedious training course let alone be fired. Luckily all I saw was an increase in the number of these emails I received.
As far as I could tell nothing bad could happen (even JS was off in the browser I used to open it) when I followed the link, but is there something I should be aware of?
https://www.mike-gualtieri.com/posts/stealing-data-with-css-...
The security teams are correct in the training they run about these: report the suspicious email and leave the investigation to them, don't try to DIY the investigation. Note you aren't penalized for false positives (reporting a legitimate email as a phishing attempt).
Turning off JS does not make you safe.
I spot a critical flaw in this methodology.
But you can't stop curiosity.
I wonder how many such phishing e-mails a company gets a day.
If the volume is not that high and it's something manageable by the (proper) security team, I wonder if a company could implement a policy where the employee can report a phishing e-mail to the security team and get to sit with them to watch them investigate. If that's not possible, maybe have the security team write up about investigations into phishing e-mails from time to time and send the results to employees as internal memos.
from: jim.bob.sales@bigcompony.com
"hey cindy it's bob your bosses boss boss. I forgot my password and have a MAJOR presentation coming up. Can you give me yours for login so i can see our powerpoint?"
Don't open it.
"But what if it's Taco Tuesday and a full moon?"
Don't open it.
Everyone can be spearphished.
I mean it. Everyone.
There's a con out there for everyone just like there's a lid for every pot.
Also fraudulent invoices are another form of spearphishing that you'll still have a pretty hard time against.
I don't know, I'm also on the operations side in a large enterprise and I help with our internal phishing efforts. Pretty sure I'm familiar with the same tools that you are and I vehemently disagree with your assessment.
What’s the point?
If Security/IT is so dense that they see any value in testing before training, we’ve already identified a problem: culture or a “our employees are too smart for this issue”.
How do you know if your training is working if you have no baseline?
I’m also curious about what training methods work best (including a no-training control group).
Now, if someone is told that official policy states you must only use approved devices and services and you violate that and that introduces additional weaknesses, then yes. But that’s different.
I mean phishing experts in active campaigns get phished. So, regular Jane and Joe? ‘Course not.
I've worked low wage jobs for the Government and Private Industry where we were hit with ransomware and phishing attacks. I think you are underestimating how many workers are really in that position. I'm not sure if you're American, but it's very common in America.
At Inky (https://inky.com) we're using a combination of computer vision, anomaly detection, and domain-specific hacks to identify zero-day phishing emails "from first principles" (as I like to say). And it works! But the pushback from the security establishment is impressive. I like to say that there are two widely-held but false beliefs about phishing: 1) phishing is solved; 2) phishing is unsolvable.
The truth is that we can already see clearly that within 3-5 years machines will be good enough at identifying phishing emails that attackers will move to another vector... but you'd never know it listening to "Security Thought Leaders."
Claiming that a complicated problem involving a lot of humans, that is very much not solved at the moment, can expect to be fully "solved" in 3-5 years stretches my credulity.
I fully expect the next decade to look much like the past several decades, with both sides of the security arms race making incremental adjustments and improvements.
I've had two different large, corporate employers do the phishing training thing. I've failed occasionally at both of them. You can make a phish as close to indistinguishable from a legit email as you want.
In my experience these "phish-your-employees" programs have 2 side effects, both possibly unwanted:
1. Reluctance to even look in Outlook for fear of getting a drive-by. I know these haven't shown up in a while, but Outlook is a strange beast. That is, I'm just not going to look for, or even open, emails. 2. Enthusiastic reporting of false positives. After getting burned by a decent phish, I reported a few legit emails, including one that had a salutation of "Dear Joe User:" or something equally generic and stupid, but was a genuine email. There's sort of a Poe's Law in the relationship between phish and real emails. This wastes security staff's time. Or maybe you want that. They tend to be a bit weird and annoying.
How long do you think most people could get away with that without being fired? I'd guess I'd last about a week at most.
I’ve almost direct-deleted an email like this, but it turned out that the sender got married and changed their name.
I used to work in a casino that sent out a notice to all employees urging them to report more suspicious activity. There was no information or training given on what specifically to look for.
After some time the initiative was deemed a great success. Although there had been zero improvement in the rate of dangerous activity stopped or prevented, there had been a giant increase in the amount of reports that turned out to be false.
Educate all you want; no consequences, no behavior change. Incentives matter. Employee opsec metrics should be a part of corporate cybersecurity insurance pricing IMHO.
For instance, let's say I'm a junior developer and I'm told that merging code that fails a suite of unit tests is a serious offense.
If I one day forget to run the test suite and merge code that breaks stuff ... it might be my fault at an acute level.
But at an organizational level, someone should be saying, "If it's that important to not merge code that breaks tests ... then we should change our process so you _cannot_ merge code until all tests have passed."
And if nobody gets faulted at the organizational level, then the junior dev is really just a scapegoat.
I have had this fantasy of trying to see if I could trick the IT people who send them with a phishing attempt. It would involve perhaps reporting that my virus scanner had reported something suspicious in an email to get them to open something.
Or maybe register mimecastprotection.com, then send out a fake email to IT as if it was a big marketing announcement from Mimecast that "We've changed our name! We are now Mimecast Protection as part of our commitment to serving you!"
My theory is that a really well crafted phishing email is going to be very hard to avoid.
It also makes no sense to blame users for thinking an email message is from their bank when there is no obvious, visible difference between messages from their bank and messages from criminals.
He said employees had training and still failed. No one got fired for it though.
I think having a “guest” wifi discourages employees from using visiting random streaming websites on their work computers.
http://www.paulgraham.com/spam.html
If Phishers are concentrating on fooling human beings in the same way that spammers were back in the day, they might be vulnerable to such techniques.
Once my implementation started to work I was really amazed how such a simple algorithm could be so successful.
My god are people bad at security. Security people especially so. Actual security is not bound to the mechanics of securing things. It is bound entirely to risk. Did you just fire the best accountant your company has because they were too focused on solving your huge tax liability to notice a phishing attempt. Risk.
Everyone is fallible including your IT security group. If phishing attacks are actually causing appreciable damage to your company, it's the security group who needs replacing. Can they report quantitatively how much more value your organization has captured with it's 90 day password replacement policy, and does it account for all the passwords written on post-it notes laying round, and the productivity impact of constant forgotten passwords?
The purpose of security is to mitigate the risk of loss, but so is insurance. Don't fixate on the machinery of security, and don't fire people for poor email filtering who's value is not to filter emails.
I got reamed on another forum for saying someone shouldn't be allowed in a certain role, after they sent $1 million to a fake bank account to someone posing as a supplier. But if your work place doesn't have controls in place to prevent that, it's part of your job to be that control and take additional steps to protect yourself and your employer.
Recently there were reports of an active shooter on site. Everyone got email alerts about it. Many (most?) employees ignored the alert because the From address was an unknown external domain. Fortunately there wasn't an active shooter (although the person who was arrested was armed).
And then the company sent out an email asking us not to ignore those types of emails even if it appears to be a phishing attempt.
I think from now on, just for the heck of it, I'll click on the links but modify some of the characters in the URL. Hopefully someone else in my/some company will be notified that they need training.
My general approach is to create computing environments which make it generally impossible to send/receive general communications, and access sensitive information (or the web), at the same time on the same machine. The communication channels available to an agent while accessing a customer file are heavily sanitized, and the environment does not allow for opening links; images are transcoded in fresh containers on a remote machine with no general access to the database or the internet.
The real question is: do many businesses understand the risks well enough to make that determination well?
However, if there are staff that repeatedly fail these tests and receive constant training, then that's a question for the business in how willing they are to accept the risk.
Given that there are tools that can quite often successfully block these types of emails before they get to the end user. Most often when we are crafting these emails we need to ask the IT teams to unblock the domain.
In my opinion I think in most cases no, however depending on the industry and the strike rate you might have a case for it at some point.
I may or may not open any emails from that address period, depending on how paranoid I'm feeling.
Or... and catch me if I'm talking crazy here... or do you want to fix the email software so I can trust that only the IT department can send me emails from itdepartment@example.com which actually make it through the firewall and email filtering software and internal email security policy to reach my email account?
I think a better question would be is Sr Leadership supporting the security and risk mgmt teams in developing proper training as well as implementing and spending the money on the proper controls to help reduce the risk to the end user of being spear phished?
Our (large) company recently had a sort of big (we think) leak of internal source code from a GitHub Enterprise server - done by an internal person who DL'ed a bunch of code and put it outside.
Basically no security system in the world would have stopped that, as long as we think the idea of sharing source code internally is a good idea.
So yea - the guns all point out, and if anyone inside your organization ever tries to phish you, there's a good chance you'll never see it coming.
In one way, it's pretty easy to answer: if firing offenders results in real costs from successful phishing efforts decreasing more than the cost of hiring and training people and any side effects from worse morale... then yes.
But unless you're working with state/military secrets where lives could be at risk, or on the security teams of financial institutions where a mistake could lose tens of millions of dollars...
...then probably not.
But if you’re running a monopoly, you’ll continue to exist, just in a poorly functioning state that people have to deal with anyway.
Sigh...
Are people really so gullible & trusting?
That's not how spear phishing or even phishing works. The email looks like it came from a fellow employee/boss/trusted party.
If a company gets owned because they failed to implement SPF or DKIM properly, IT is at fault, not the employee.
Yes, and it is not a “bad” thing outside the niche of security I think. We should all hope to live a life where we can implicitly trust other human beings.
Someone forwards me an e-mail from our Dutch office that says, essentially, "The world is burning down, we are boarding a plane in a couple of hours to go to IFA (show), and we don't have the latest copy of product X to demo for customers."
I do builds by hand of this product because I can't get resources allocated to automate it
I have never heard of any of these people before. I reply asking, "I am sure I can accommodate you, but, Who are you and why I haven't been told about this before now?"
To my shock, the guy replies, "I'm the European Vice President for product X, we didn't ask before now because it has never been a problem in the past. Who are you?"
I reply, "I'm the only person in the entire world with the encryption keys to provision the product, and that has to be done on one single computer in Santa Ana. It's only a fluke that I am here today-- my car wouldn't start this morning, and I had planned to take the day off to fix it, and then by some miracle an hour later it started. That's why it's important to know about things ahead of time."
That's what working at a big organization is like, you interact with people who don't know all the time. And frankly, nobody is ever allocated time for "security" in their schedule. My dance card at that company was scheduled for 8 hours of development a day, no e-mail answering, no security, no time to do the build system. No time for meetings. Nothing.
But when your big org is hiring, let me know :)
The chaos that surrounds you, the facts that astound you, at last your number has found you, your bus number is one.
Most cases I've seen of successful (or nearly successful) spearphishing would have been solved by someone picking up a phone and calling their co-worker.
"I know you sent me an email, but can you just explain again why you want me to buy $1000 in iTunes gift cards and email them to you?"
"I got that invoice you sent. Just wanted to confirm the amounts -- $50k wire transfer?"
If they value "responsiveness to their authority over procedure" then people will send the entire financial records to "the CEO" for fear of getting fired otherwise.
Skepticism and rational thinking require effort, and thus as people are rushed or tired, those are the first defenses to fail. You can train to recognize patterns of phishing, but learning those patterns takes time, repetition and effort.
All that a good phish requires is finding the right buttons to push on the right person, and they have many potential victims to press them on, and little to no consequence to getting it wrong.
So, the answer is people are not particularly gullible, but the weak links are a constantly changing, largely unknown dynamic and the phishers can hammer at all of them simultaneously until they get through.
If successful phishing leads to significant data breaches, that's a technical/systemic problem, not a personal one.