I know I'm pushing a boulder uphill with that one but it really is the way to go, better for both the individual and the company.
I know I'm pushing a boulder uphill with that one but it really is the way to go, better for both the individual and the company.
Figure out a company uses <some-saas> register a phishing domain (e.g. gith.ub) send them an email with important info about their account, and a PDF attachment with more details.
If it's that easy to compromise a system all you have to do is get a few employees to open the PDF right?
This has benefits for the employee, not just the company, in that it keeps the employees personal data out of the hands of the IT department.
This might just result in employees finding ways to remote access their work computer from their personal computer from wherever they are, but at least that's an additional wall for would-be attackers to hurdle.
I don't install anything personal on my work computer, but I wouldn't hesitate to open an email or pdf from a seemingly trusted source. I don't really blame the dev here.
What you propose is a reasonable solution, but I feel like it slams in the face of actual human behavior. Most people act the way I describe, even most tech professionals.
I think the clear move here should be to avoid pdf, just like the move is to avoid doc