I was promptly informed that I had failed the test and I would be receiving a formal reprimand.
Did that make the company more secure?
I was promptly informed that I had failed the test and I would be receiving a formal reprimand.
Did that make the company more secure?
I think a reasonably paranoid approach like "Hackers might think of ways to abuse this that I haven't thought of" is best. Unless your job is to take a risk and visit a phishing site, don't take the risk. Even with Lynx.
[1] Exactly what an attacker would say!
Which you're giving away any time you browse any external web site.
>Lynx supports cookies too so it would be possible to track a user between sessions.
You're downloading cookies for most external web sites.
If the worst you do is the same as going to espn.com, then reprimand people for going to any external web site.
But your point is spot on, don't take it upon yourself to do things that aren't in your job description. Otherwise you become that person who takes it upon themselves to "fix" things and makes the problem worse for the people responsible for fixing things.
I made my own signs for wayfinding (Main Building ——>, and “Floor 7” when the stairwell was missing it).
Some are still up a few years later.
That's a great way to never go anywhere in your career.
I know you say the team would be pissed, but it's actually the exact opposite! Firstly, most sophisticated companies have automated the abuse inbox management process, but even when it's not automated, I'd rather 100 easily ignorable reports about boner pills than one person not send an actual spear-phishing email. Plus we can use the generic spam reports to better train our spam filters so please do keep sending them, even the Nigerian prince stuff.
"But... this employee has been dead for 20 years..."
id=SSBsaWtlIFN3ZWRpc2ggUGhpc2g
It may not be a perfect approach since we do use it for MFA...
Curiosity shouldn't preclude security, and intent shouldn't preclude policy if the operator operated knowingly.
This isn't to attack maxk42, but to engage the question head on.
Oh boy, I hope I never work in this kind of organization.
It would also be interesting to hear whether someone actually considers me to have failed anything when visiting a (faux) attacker’s link on my own device off the company network and entering no credentials.
Whilst that information might not be sensitive it could be used at a later date to extract sensitive company information.
There should be a line drawn between real security-conscious workplaces, and the kind of self-important chickenshit places that seem to delight in playing games and harassing their employees with this kind of thing.