Can’t make the wrong people look bad.

  • Mic_Check_One_Two@reddthat.com
    link
    fedilink
    arrow-up
    2
    arrow-down
    1
    ·
    4 days ago

    My point is: you didn’t get phished until you give away any info other than “someone received the email and clicked on the link”

    Never heard of drive-by malware attacks? Malicious ads? Zero-click attacks? That link is Schrödinger’s zero-day ransomware attack, which may or may not exist. And there’s no way for you to know which it is, until after you’ve already clicked it. Sandboxing your browser is fine, but they weren’t testing to see if your browser would allow an attack to happen. They were testing to see if you would allow an attack to happen.

    The actual method of attack (and any protections you have set up for your browser) is irrelevant, because they’re not testing to see if your browser is hardened. If they were going to do a software audit to see if browsers were vulnerable, you probably wouldn’t ever even hear about it. Because IT would handle it directly, via the access they already have to your company computer.

    Tricking you into disclosing sensitive info is only one specific type of attack. The phishing link isn’t checking to see if you’d give info away. If they were testing that, they could do it in other ways, like a fake email from your manager asking for the info. No need to click a link to fail that test. But with the phishing link, you fail the test when you click it because it ultimately doesn’t matter what loads after you click the link. That link exists in a quantum state where every single piece of malware that ever did/will exist can load as soon as you click it.

    • raspberriesareyummy@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      4 days ago

      Never heard of drive-by malware attacks? Malicious ads? Zero-click attacks? That link is Schrödinger’s zero-day ransomware attack, which may or may not exist. And there’s no way for you to know which it is, until after you’ve already clicked it. Sandboxing your browser is fine, but they weren’t testing to see if your browser would allow an attack to happen. They were testing to see if you would allow an attack to happen.

      To consider an employee clicking on a potentially malicious link as “allowing an attack to happen” takes a special kind of incompetence on the part of the IT (security) team.

      If simply clicking a link compromises a system, that’s on corporate IT, not on the user. As you say, “they weren’t testing to see if your browser would allow an attack to happen”. Because - in a corporate setting - if it would, they done fucked up. And if it wouldn’t, then clicking a link alone is no problem.

      But with the phishing link, you fail the test when you click it because it ultimately doesn’t matter what loads after you click the link.

      I dislike that you incite me to respond to that because I don’t want to insult you personally, but I have very strong feelings about this attitude. This particular, take from a corporate IT department, is moronic. If clicking a link to check where it leads compromises IT security, that is 100% the fault of corporate IT. That is what they must fix with firewalls and filter policies.

      As an IT security responsible, if you push responsibility for single keypress actions to the user, you are an idiot, and a liability to your company’s IT security, and you should not be allowed anywhere near a sensitive system or policy.

      The role of IT security is not to set legal frameworks in which when a fuckup happens, a responsible person that is not them can be found. The role of IT security is to protect the intranet and users from external attacks, be it hacking or phishing or malware - and to protect the same intranet from internal attacks in the best way feasible. That includes a user intentionally clicking a link if that is sufficient to compromise intranet systems.

      About the only thing you can make users responsible for is to not disclose information through phishing or social engineering attacks, and to not intentionally sabotage anything.

      • chiliedogg@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        3 days ago

        The point is to have multiple layers of protection. With users who are vigilant it’s less likely for something to get through even if IT fails to filter out an attack.

        Think of it like gun safety. Even though a gun is unloaded you don’t aim it at someone.

        • raspberriesareyummy@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          3 days ago

          No argument there - training cybersecurity awareness is fine, but singling users for clicking on a link alone is moronic. Most security fuckups in my experience result from stupid IT policies and rarely do the responsible admins / managers ever get flak for their fuckups.

          • chiliedogg@lemmy.world
            link
            fedilink
            arrow-up
            1
            ·
            3 days ago

            In my experience (I’m not in IT), the IT folks only get recognized for fuckups. When they do things right nobody notices and thinks they’re a waste of money, resulting in the company cutting back on their budget then freaking out when they’re not equipped to do their job and something goes wrong.

            • raspberriesareyummy@lemmy.world
              link
              fedilink
              arrow-up
              1
              ·
              3 days ago

              Ok let me rephrase: IT management never gets the flak they often deserve.

              But also there’s a distinction to be made between competent IT and IT service contracts where the contract officers are corrupt and/or incompetent and then the service is awful as a whole.