4 ms·
I actually started coding in 2000 trying to hack my brother, so I can relate: phishing has been a never-ending story. It's still worth trying though!
by BenjaminN 7y ago
I actually started coding in 2000 trying to hack my brother, so I can relate: phishing has been a never-ending story.
It's still worth trying though!
- jedberg 7y agoDefinitely worth trying! Just want to help you set expectations. :)
- BenjaminN 7y agoThanks!
- johnwheeler 7y agoDid you try punitive disincentives?
- rwmurrayVT 7y agoThe company sends out fake phishing emails. The same people keep falling for it... I suppose the outlined punishments are not strictly enforced.
- brobinson 7y agoA better approach is to turn it into a game: reward those who report suspected phishing emails, security breaches, tailgating into secure areas, USB devices left around, etc. and have red teams doing this stuff periodically. Punitive measures don't really work. Friendly competition with rewards does work, though.
- johnwheeler 7y agothat's a good point :D
- jedberg 7y agoIn our case we were educating and protecting our customers. It's usually bad policy to carry out punitive punishment on your customers. :) In fact, the worst offenders were actually rewarded. They were the only ones who had two factor auth for their eBay accounts. Back then we didn't have soft tokens -- the only way to do 2 factor was to get a physical RSA token, which cost about $10 at the time. So only the "best" customers were worth the cost.