I tried to make the case to IT that hyperlinks are not a threat vector on their own. They should train against opening attachments and entering credentials once the link is clicked. I haven’t heard back yet, I’m not sure they liked my message. But they did send a message letting us all know that reporting non-phishing surveys wastes their time.
Unfortunately, theres very good statistics that show 1-click attacks are quite common beyond just phishing for login creds. Granted, not nearly as common as the latter, it’s still a moat you had to dig :(
The argument regarding hyperlinks is generally that there are 1-2 click zero-day vulnerabilities pretty frequently, so clicking a hyperlink will take you to a server controlled by the attacker which may or may not employ one of those. Additionally there’s a constantly rotating array of obscure HTML/CSS hacks to trick even the savviest of users into thinking an attacker controlled window is something else or otherwise compromise a users system without utilizing zero-days. And finally good ol’ social engineering typically relies on several vectors at once, so by the time someone’s clicked the link there’s a good chance they might go further for the attacker before they clue in.
So yeah, theoretically if everything was as it should be, clicking the hyperlink and downloading and executing literal malware wouldn’t work, but security is about trying to make sure the weak points of every part of the chain don’t line up, because when those holes in all of the layers of security line up, you’ve got a nice big compromise to clean up, and those buggers are like bedbugs, once they get in, you can be chasing them for months or years until you’re finally rid of them
The web is very locked down already. People click so many links from email, but also outside of email. Clicking a hyperlink in an email is not a threat vector. If it was, we can’t vote on when to meet, open shared documents, or basically do anything other than plaintext email. Aha! That’s the solution. Plaintext email - all attachments and HTML are blocked.
I tried to make the case to IT that hyperlinks are not a threat vector on their own. They should train against opening attachments and entering credentials once the link is clicked. I haven’t heard back yet, I’m not sure they liked my message. But they did send a message letting us all know that reporting non-phishing surveys wastes their time.
Unfortunately, theres very good statistics that show 1-click attacks are quite common beyond just phishing for login creds. Granted, not nearly as common as the latter, it’s still a moat you had to dig :(
The argument regarding hyperlinks is generally that there are 1-2 click zero-day vulnerabilities pretty frequently, so clicking a hyperlink will take you to a server controlled by the attacker which may or may not employ one of those. Additionally there’s a constantly rotating array of obscure HTML/CSS hacks to trick even the savviest of users into thinking an attacker controlled window is something else or otherwise compromise a users system without utilizing zero-days. And finally good ol’ social engineering typically relies on several vectors at once, so by the time someone’s clicked the link there’s a good chance they might go further for the attacker before they clue in.
So yeah, theoretically if everything was as it should be, clicking the hyperlink and downloading and executing literal malware wouldn’t work, but security is about trying to make sure the weak points of every part of the chain don’t line up, because when those holes in all of the layers of security line up, you’ve got a nice big compromise to clean up, and those buggers are like bedbugs, once they get in, you can be chasing them for months or years until you’re finally rid of them
The web is very locked down already. People click so many links from email, but also outside of email. Clicking a hyperlink in an email is not a threat vector. If it was, we can’t vote on when to meet, open shared documents, or basically do anything other than plaintext email. Aha! That’s the solution. Plaintext email - all attachments and HTML are blocked.