6 ms·
Once we get past the predictable schadenfreude, it's crazy to think how easily this could happy to, or because even of, any one of us. Do you think you'd think
by dewitt 11y ago
Once we get past the predictable schadenfreude, it's crazy to think how easily this could happy to, or because even of, any one of us.
Do you think you'd think twice before responding to a mail from your manager asking for information that they had reason to ask for? Would you challenge them to verify themselves over the phone at 11:00 PM, just to be sure no one spoofed their email address?
I bet I wouldn't, and I'm paranoid.
- chinathrow 11y agoDon't reply to mails at 11pm might help, for a start. I look at mail headers more often than necessary.
- ikeboy 11y agoDo you have access to data that would cause a news story if you sent it to the wrong person? If yes, then yes, verify it before sending. Also, spoofing an email address wouldn't help. If you respond, it will go to the spoofed address, which is the correct one. They need to send it from their own email address, which means that you only need to verify that it's send from your manager's address, or just manually send it to your manager.
- developer2 11y agoIt's likely that their SMTP server accepts messages with an SMTP "MAIL FROM" command and/or "From" header address that belongs to the company's own domain without requiring authentication. The attacker then adds a "Reply-To" header so that replies will be sent elsewhere (likely a throwaway free email account). This shows up in email clients as "From: legit.name@example.com". When the recipient replies, they don't notice that they're sending a reply to a different address than the one their client claimed was the sender of the original message. Receiving SMTP servers need to be configured to require SMTP authentication for messages claiming to originate from the company's own domain.
- noinsight 11y ago> Receiving SMTP servers need to be hardened to require SMTP authentication for messages claiming to originate from the company's own domain. Or validate SPF / DKIM and enable it for their own domain.
- viraptor 11y agoBut unless you actually break into someone's account, email spoofing should be a solved problem. Sure, you can set the from field to whatever you want, but in a typical company scenario, it will look very different in outlook - it will actually display the sender's email, and if you try to spoof that, you'll just get rejected at the server. Now if you ignore that and respond anyway... well, there's not much anyone can do about that.
- wickawic 11y agoSerious question: what would it look like on a smartphone email client?
- viraptor 11y agoNo idea. Work email doesn't go anywhere close my smartphone.
- paulddraper 11y agoHow do you reply to emails at 11pm? ;)
- employeeee 11y agoWe've been a target of this attack previously and it's not as simple as email spoofing as email addresses aren't (in Google Apps at least) displayed prominently, firstname.lastname@gmail.com with a corresponding name and profile picture is how we were targeted. Very easy to fall for (especially in companies that aren't strict about personal/professional email separation).
- hayksaakian 11y agoisn't this what DKIM and SPF and all those fancy email security things are for?
- tshtf 11y agoAn attacker-controlled domain, say snaapchat.com, can pass DKIM, SPF, and DMARC if configured appropriately.
- eli 11y agoBetter solution is to append a warning to any message that originates outside the domain.
- jcrawfordor 11y agoThis is actually a really good idea in corporate environments, and I would encourage everyone to think about doing it. It is a simple thing to push a rule to Outlook that e.g. displays emails from outside the corporate domain with a red tinted background in the email list. This helps people to think twice. It also compliments an email classification system well, although unfortunately most classification systems I've seen with good MUA integration are very expensive.
- teddyh 11y agoNo, this is what OpenPGP signed mail is for.
- tomjen3 11y agoI would post it on slack. Figure I know who my manager is there and even if i didn't, at must it would end up somewhere in the company.