Spear phishing with Slackbot for fun and profit
ericwbailey.design
ericwbailey.design
The solution might be a verified name system, if you change your name of display name, it gets "moderated" by an admin first. In a corporate environment there is no need for people to change their name often, maybe once ever when you either actually change your name or decide to use an alias in real life.
This is similar to HN not allowing someone to use the displayname "dang", or if display names were a thing, it gets moderated somehow.
Probably good idea to do that on the profile pic too!
I'm not sure if there is a cool technical word for this in security jargon, but the "Full Name" "Display Name" and "Profile Photo" are what I'd call "trust-centric fields" and need to be treated differently to say "What I do" or "Phone Number".
In a corporation this is easy, someone's job is to vet changes to this. Whoever sets up systems for employees for example.
Outside of a corporation it may rely on flagging and moderators.
Obviously it is definitely a field that needs to be secure, I.e. I can’t set your phone number.
With any luck, this style of insufferable faux self-deprecation will not be fashionable with the next generation.
From this, you think the author is suggesting that white male users are more technically illiterate than other individuals? Your detectors are tuned for too much recall.
Not so much executives though. Usually elderly widows.
The real problem can be condensed into – how do you prevent your employees from getting phished? And well, if you had a solution to that you would be worth many billions of dollars.
All of these solutions require process and manpower, and are not automated solutions.
Security Awareness Training. Preferably with automated tools and continuous. KnowBe4 is the platform I've used but there are others.
If someone is auditing whether employees are falling for real phishing attacks, that's interesting and I'd be curious to know more about that product.
With "audits" I refer to checkups that policies are being followed. As for whether or not your phishing audits are good, I cannot say :) I have seen some very good ones, as the best audits are based on (different tiers of) successful phishing campaigns seen in real life.
If you feel that your company could do better, you could always try to speak to your security team about this. It helps the people working there as much as it helps the company, folks falling for phishing happens in all walks of life.
This is absolutely untrue and it is phishing-vendor propaganda.
If there are any "potential malware vectors" from visiting a website, there are so many other ways you are exposed to those "vectors". For instance, Hacker News is a website that features links to arbitrary user-submitted website. Any click on a website on Hacker News could expose you to all the same "vectors."
(Maybe that's why nobody here reads the article before commenting?)
If an attacker has a way to get malware to you based on your browser accessing some web page and rendering it, they have so many easier ways to do that. They can buy ads leading to the web page they control. They can make organic content that highly ranks a web page they control. They can even render custom iframes inside tweets (https://developer.twitter.com/en/docs/twitter-for-websites/c...) and promote the tweet.
If you're concerned about browser zero-days - and you should be! - phishing is the least of your worries. Automatic browser and OS updates with very short remediation times and aggressive policies on BYOD devices staying up to date will get you a lot farther.
And these policies are actually genuinely compatible with the jobs of a lot of people who, well, have to click on links to do their jobs. If you fall for the phishing-vendor propaganda, you'll end up with people trained not to click on links that look like phishing links but who will happily click on links that don't (because their job requires them to), which defeats the point entirely. Hence my question about whether you're measuring results from the phishing vendor, who is incentivized to tell you that paying them is doing something worthwhile, or from actual phishers.
Finally, TFA was about spear-phishing and about convincing people to do things, not about distributing malware. A "don't click on links" security culture does nothing to protect against "don't trust emails that tell you to do wire transfers."
I have in fact spoken to my security team and convinced them to stop running phishing tests that mark clicking the website as a failure, based on exactly the above reasoning.
This is fair. I'll think about it and do some more research. It'd be nice to be wrong, in this case :)
> A "don't click on links" security culture does nothing to protect against "don't trust emails that tell you to do wire transfers."
I thought this spoke for itself, but just in case: You can do both. A good policy takes all reasonable steps, of which these are good examples.
Security Keys.
e.g. https://krebsonsecurity.com/2018/07/google-security-keys-neu...
Notice that Google deployment was almost five years ago. Completely fixes the problem. Your employer presumably doesn't do this, mine doesn't either. That's not because the solution doesn't exist, it's because they don't care.
I was on the security team and had permission, which is important if you are going to do stuff like this.