Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

From this and other comments in this thread it seems you have failed these phishing tests as soon as you click a link. Is the assumption here that you are completely pwned as soon as you visit an url controlled by an attacker? I can't imagine myself compromising company data/funds via a website where I ended up through a newsletter unsubscribe link so this seems quite unfair on the part of the phish-testers.


That's exactly how my organization does it as well. I had to go to an incredibly asinine training because I clicked on a fake phishing link after verifying that the domain was owned by a computer security company that sold phishing prevention services. The link just went to a static "you could have been phished" page and a few weeks later I got an email telling me that I had to got to a phishing awareness training. There was no attempt at all to actually collect any credentials from me.


This is exactly the case. If you click on a link in the fake phishing email you've failed the test. It does not require you to install anything, open an attachment, etc.


I was once at a place where the company homepage was owned. Fun times.

Just starting your web-browser would exécuté some Java vuln and scareware you.


If you think visiting a webpage in Chrome, or any other browser, even inside a VM, is totally safe, especially against a nation-state level actor, I have some bad news for you.


You would literally have to never click on any link that isn't 100% under your own control in that case. Yes 0-days exist, but if I'm in an environment where that level of security is necessary, why do I even have access to a web browser?


If you think that just clicking a link is so dangerous that it needs to be a firing offense, then you should probably lock down the computers so that the browsers cannot view anything besides approved domains.


With that logic just having your mail client/web mail parse a malicious mail from a nation-state level actor is enough to compromise your machine.



From the original article which that page links to [0]:

The breach centered around a hacker getting hold of a Microsoft customer support worker’s login credentials; from there, the hacker could dive into the content of any non-corporate Outlook, Hotmail, or MSN account

This is a security concern for any mail that an administrator can read, although it isn't at the same level as being compromised just through parsing an email.

[0] https://www.vice.com/en_us/article/xwndwn/microsoft-outlook-...


If you are in a high enough position that nation states are burning zero day exploits to launch targeted attacks against you, there should probably be a security professional filtering your email. (This is also a situation where disabling Javascript would be very reasonable.)

For the remaining 99.999% of the population, I really don't think opening a web page in an up-to-date browser is cause for concern. Certainly if that browser is also in a VM. People have more pressing concerns in their lives.


A nation state level actor will always get in.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: