lemmy.blahaj.zone

SPRUNT, to memes in New email from test@scam.com

My company sent me a fishing test email from a “no-reply@companyname.com” email address. I sent it to our security department and asked if I would ever get legitimate emails from that address. They never responded except to say that I passed the phishing test, so I set up a filter to automatically forward emails from that to our security department with a message questioning its validity. Let’s security tell me if emails are legit or not.

Concave1142,

My normal method is I will hit the phishing attempt icon that IT Security added to our Outlook on anything that I did not request or sign up for.

I’m sure the IT Security person who saw all the “free gift card” emails had a great Christmas if they claimed all the gift cards emails they deem legit.

Zoboomafoo, to memes in New email from test@scam.com

I eventually clicked the link in the test email out of curiosity, I got a nice popup telling me I fucked up

Edgarallenpwn,
@Edgarallenpwn@midwest.social avatar

Have fun watching training videos for an hour and a half. It’s just free money

Zoboomafoo,

Nah, I got fired like a week later for no reason

Edgarallenpwn, (edited )
@Edgarallenpwn@midwest.social avatar

Damn that’s extreme. Sorry to hear that.

Thorry84, to memes in New email from test@scam.com

Where I work you only pass the test if you report it to IT, otherwise it’s 3 hours of training with the rest of the idiots.

bamboo,

Does IT want useless reports? Because that’s how you get useless reports?

Alteon,

Yes. They do.

CurlyMoustache, (edited )
@CurlyMoustache@lemmy.world avatar

There are no “useless reports” when compared to the alternative

BeardedSingleMalt,

This is how they justify their jobs.

CalamityPayne,
@CalamityPayne@jlai.lu avatar

No. Technically illiterate users, that’s how we justify our jobs.

LemmyIsFantastic,

I think you mean satisfy regulatory requirements.

theneverfox,
@theneverfox@pawb.social avatar

Justify their jobs? Their job is to set shit up, then be around at all times to help already frustrated people to do something they just forgot how to do today for no reason. And then, to politely listen as the person makes excuses to preserve their ego

Security compliance? That’s handed down to them. If they had a hard on for cyber security, they could make 2-3x as much and no longer have to explain to people that they joined the wrong teams call

I make a point to get to know the service staff. Chat with the custodian. Go to IT when you don’t have a problem… Get to know them a little as a person. Then, when you have a problem, you don’t have to make a ticket and wait for them to get to you. You already know them, and they feel respected as a person - they might not drop everything, but they’re going to bend the rules and quietly tell you how to navigate the system to get what you need as painlessly as possible

They’ll also know if you’re an idiot or not already - they might know to trust you at your word, or they might know tech makes your eyes go glassy and hold your hand patiently… But either way, the respect makes them want to help you, and the preexisting relationship makes the whole experience less painful

It is a shit job… It’s the overlap between being in the service industry and a tech worker. Almost all of them couldn’t make it in a more specialized role that would pay far, far more, and if you walk in during downtime half of them will be practicing their programming hoping to get a better job

Black616Angel,

No, it’s better to get some useless reports than to get no reports at all because “somebody will surely report this”.

Also people stay alert when punishment is an option.

Thorry84, (edited )

The IT people send out the phishing mail themselves as part of a test. It isn’t an actual phishing mail, just something made to look and act like one. In the end they have a report which people fell for it, which ignored it (or were ooo) and which reported it.

Reporting is done via the report phishing feature in Outlook. For consumers it’s sent to Microsoft, but for businesses you can configure those reports to do what you want. It’s actually a really good feature and people should always use it.

bamboo,

Does your IT team tell you that they’re performing the test and to report, or is reporting phishing always constantly recommended. I’ve managed a small org ( <100 ) email server and we tried to have people report suspicious emails and it was so much noise and wasted so much time. Of course the CEO isn’t requesting you buy gift cards, what am I going to do about it. I’d say the money would be better spent on a better system rather than hope one human forwards it to another human.

Thorry84, (edited )

They don’t tell us they are testing, it’s done at random. Reporting is policy, it needs to be done with every phishing mail that gets past the filters. It’s one of the big ways a company is vulnerable, an employee clicks on a link in a mail, opens something they shouldn’t and before you know it there’s been a databreach. I don’t think they are especially worried about the employee leaking his personal info, they are worried about targeted attacks and corporate espionage.

I’m sure there are a lot of false positives. Even though I work in a technical company, we have plenty of people who aren’t as handy with tech. People get training regularly and if one person reports a lot of useless I’m sure they will train that person extra. I think for a lot of people except maybe sales something like 80% of all mail is internal. And the other part is probably 50% repeating automated mails. So the number of mails that could even be phishing are limited. It’s a mid sized company with about 1000 employees.

UserMeNever,

Sounds like your email software needs fixing…

Thorry84,

Sure let me go tell Microsoft

bamboo,

I see the benefit of reporting to catch false negatives of the filters, but in reality, if I received more than one report in a week or two, id consider a new system for scanning. A 20% false negative rate is pretty bad. Most emails should be easily identified, and I think it’s unreasonable for end users to check if the sender domain name is newly registered, has utf-8 characters which look like ASCII characters, etc. The metric for success shouldn’t be a high number of end users reporting phishing emails, but that seems to be what upper management wants to see, which just incentives less resources invested in better scanners with less than a 20% false negative rate.

Promethiel,
@Promethiel@lemmy.world avatar

The metric for success shouldn’t be a high number of end users reporting phishing emails, but that seems to be what upper management wants to see, which just incentives less resources invested in better scanners with less than a 20% false negative rate.

The eternal battle between the “oh we go by data backed metrics, much measured, I feel this is the best” executive suite and the poor saps beneath twirling the data backed signs going ignored until money or disaster strikes.

Pity businesses aren’t formed from the bottom up; it’s like an octopus deciding not to listen to its arm brains until the shark has a bite of its head.

ThePowerOfGeek,
@ThePowerOfGeek@lemmy.world avatar

Damn, that’s kinda harsh.

lurch, to memes in New email from test@scam.com

Mine gives useless bonus points for forwarding the test email or an actual phishing mail to their special security scanner account.

bamboo,

Why not just have the security scanner before it hits an inbox?

YoorWeb, (edited )

Filters will catch 90% of spam/phishing but there’s always something new that will slip through to inbox.

lurch,

There is, but if one gets through, they want us to forward it to this account that will be used to train, fine tune and improve the scanner for all mailboxes, as well as security training for employees.

bamboo,

That makes sense, I thought the security scanner was only triggered if someone forwarded an email after it landed in an inbox.

Kalkaline, to memes in New email from test@scam.com
@Kalkaline@leminal.space avatar

“Let’s also make our users follow really complex password requirements but have our password creation/change page be different from the actual login screen so they have a really hard time using a password manager”-dumbass IT department

Edgarallenpwn,
@Edgarallenpwn@midwest.social avatar

My current employer actually just changed our password policy to greatly extend the password expiration date. We have cranked up the password requirements a tad, every login has 2FA and permissions are locked down to the size of a gnats asshole. Users seem to like it better since they don’t have to come up with a new password as often and we are telling ourselves it’s harder to brute force.

Zoidsberg,
@Zoidsberg@lemmy.ca avatar

Change your password every 30 days, and never reuse one, and don’t use a password manager, and don’t write it down anywhere, and…

SPRUNT,

The “Forgot password?” link is my new login process.

BeardedSingleMalt,

15 character minimum passwords that expire every 90 days and require MFA to remote in from home with 3 separate login sessions just to get to your PC, along with stripped down rights for everyone, even IS. The rights are so strict that if you wanted to, for instance, update a trusted application like Notepad++ because a recent exploit was found which would be a security concern, you can't use the auto-update feature of the application; you have to download it manually from their repository, and run it using a special admin account created for you that doesn't have an associated email address but also has a 90 day password requirement. But you wouldn't been able to use their repository 6 months ago because we block any IP address outside the US and their previous service was located in UK, so if you wanted to keep that piece of software up-to-date with security and vulnerability patches (which they've harped on a number of times before) you'd have to find alternative download services located in the US regardless of how shady.

I wish I was joking.

danielf, to memes in New email from test@scam.com

The best way to avoid scam emails is just to change your email account’s password to a random string, not save it, then log out. I’ve also shredded my SIM card so I can’t receive scam texts.

Aielman15, to castles in Olavinlinna/St. Olaf's Castle [Finland]
@Aielman15@lemmy.world avatar

Really beautiful. Never heard of it, thanks for sharing!

squirrel,
@squirrel@lemmy.blahaj.zone avatar

Yeah, me neither. I came across it when browsing Wikipedia, looking for freshwater seals which live in the lake adjacent to the castle.

SharkAttak, to memes in I feel so appreciated!
@SharkAttak@kbin.social avatar

This has "You're the worst pirate I've ever heard of / But you've heard of me" vibes.

carzian, to memes in I feel so appreciated!

Great game, always upvote fire emblem

QuantumSparkles,

Which one is this? I’m assuming either Sacred Stones or the self titled GBA game from the look of it

BigWumbo,

Self-titled. Aka Fire Emblem 7: The Blazing Blade

Siethron,

The game that only has a good story if you bother to S-Rank Hector hard Mode.

BigWumbo,

There is another way?

Siethron,

True

DragonTypeWyvern,

Hector is Bestctor

RIP_Cheems, (edited ) to memes in Minmaxxing
@RIP_Cheems@lemmy.world avatar

I especially love the BLATEN RASICM perk being in the same dlc as Joshua Graham.

MartinXYZ, to memes in Minmaxxing

What is this referring to? I’ve played New Vegas and don’t remember anything about bisexuals…

captain_aggravated,
@captain_aggravated@sh.itjust.works avatar

(this is an outsider’s understanding; I have not played the game myself)

There are two perks you can get in the game: “Lady Killer”, which grants a charisma buff (or something like that) when talking to female characters, and also allows you to do +10% damage to female characters. “Black Widow” grants the same charisma (or whatever) when talking to male characters, and the same +10% damage to male characters. It’s possible to get both of these perks at the same time.

It is my understanding that the previous game, Fallout 3, prevented anything but heteronormative interactions ie to romance a female NPC the player had to choose a male character, etc. To quote hbomberguy, “It implies that Bethesda doesn’t think gay people exist.” By contrast, New Vegas allows any character to take either of the above perks, or both at the same time, allowing one to roleplay as a gay or bisexual character to an admittedly tiny degree.

EmoDuck,

Small addendum, it’s not quite a Charisma buff. Instead, you sometimes get special dialogue related to your perks which looks like this:

[Confirmed Bachelor] “Why yes, I also like to play ‘hide the snake’”

[Barter] “I’m not gay, but 20 caps is 20 caps”

“Sorry, not interested”

reeen,

And also, it’s confirmed bachelor and lady killer for men interacting with other men and with women, and cherchez la femme and black widow for female PCs against women and men (respectively)

IzzyScissor,

One of the companions has a super high science/medicine skill requirement or a quest before you can recruit him.

Unless you’re gay, in which case you just flirt with him and he agrees to join you. It’s pretty great.

SpooksMcDoots,

I’m pretty sure he will also take pity on you if you have low intelligence.

EmoDuck,

The two most attractive traits in a man, being gay or being incredibly dumb

Sagifurius,

I’m pretty sure I had a female character that slept with female characters in the casino gang missions

EmoDuck,

NPCs actually have sexualities. The only way to beat the game with sex% is to abuse a bug and change your gender mid game

oocdc2, to risa in Click Now to Become the Captain of Your Dreams!

To be fair, he did have a billion chances to take the exam; what impressed me was his tenacity.

Socsa, to memes in Minmaxxing

Then in the next one they force you into a cishet sob story about your kid.

Kusimulkku,

How do you know they’re cis

bigboig,

no trans perk 😔

Kusimulkku,

No cis perk either I guess

bigboig, (edited )

🤔 agender sole survivor

funkless_eck, to memes in Minmaxxing

this is also true in real life.

terminhell, to memes in Minmaxxing

It’s hard to not play a female in Skyrim, just cuz the Dibela buff you can get very early on.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #