4 ms·
Best solution to the example u gave would be to use PGP to verify email signature and ensure the sender is really who he say he is. Of course, PGP has its own
by crypt1d 10y ago
Best solution to the example u gave would be to use PGP to verify email signature and ensure the sender is really who he say he is.
Of course, PGP has its own problems but thats another story.
- prawn 10y agoSusceptible to the same social engineering. "My PGP thingy isn't working right now. We could wait until IT have fixed that but I'm worried that we're going to run out of time." I'm aware that Nigerian scammers supposedly fill emails with typos to eliminate clever marks, but if scammers could more accurately emulate emails/styles and write more convincingly in English, I think we'd see a lot more people scammed.
- crypt1d 10y agoThats why I said prevention and education. PGP prevents the user from overlooking the domain/email from where the message came. Educating users and introducing policies (mandatory PGP, etc) minimizes the possibility of someone performing these kind of social engineering tricks. After all, people are always the weakest link, and you cant fix people :)