2 ms·
Phishing is frankly an embarrassment for the mainstream security community. The temptation is to "blame the stupid users" -- but the truth is that even a script
by dmbaggett 7y ago
Phishing is frankly an embarrassment for the mainstream security community. The temptation is to "blame the stupid users" -- but the truth is that even a script kiddie can take a real email from a mainstream brand, "Save As HTML...", change one link, and resend... and snare even sophisticated victims. This BlackHat talk (https://www.youtube.com/watch?v=Z20XNp-luNA https://www.youtube.com/watch?v=Z20XNp-luNA) shows just how easy it is to phish even users who think they are too good to be fooled.
At Inky (https://inky.com https://inky.com) we're using a combination of computer vision, anomaly detection, and domain-specific hacks to identify zero-day phishing emails "from first principles" (as I like to say). And it works! But the pushback from the security establishment is impressive. I like to say that there are two widely-held but false beliefs about phishing: 1) phishing is solved; 2) phishing is unsolvable.
The truth is that we can already see clearly that within 3-5 years machines will be good enough at identifying phishing emails that attackers will move to another vector... but you'd never know it listening to "Security Thought Leaders."
- rurp 7y ago> The truth is that we can already see clearly that within 3-5 years machines will be good enough at identifying phishing emails that attackers will move to another vector... Claiming that a complicated problem involving a lot of humans, that is very much not solved at the moment, can expect to be fully "solved" in 3-5 years stretches my credulity. I fully expect the next decade to look much like the past several decades, with both sides of the security arms race making incremental adjustments and improvements.