6 ms·
> Clicking a hyperlink is certainly bad. HN must be a boring place if you are not prepared to click on external links.
by zulln 6y ago
> Clicking a hyperlink is certainly bad.
HN must be a boring place if you are not prepared to click on external links.
- ubercow13 6y agoThe point is to recognise the email/situation as phishing or otherwise malicious before deciding to click the link. The chance of clicking a malicious link on HN is pretty low if you stick to the front page.
- marcosdumay 6y agoOk, so you close a tiny window, while leaving the entire web open as a giant door by its side. And you do by a really invasive means that will make sure that everybody that knows what they are doing but are curious to safely inspect it further will be marked as clueless. Leading to false positive and negative errors larger than the signal, but you still expect to get useful data from it.
- stingraycharles 6y agoThere’s a fundamental difference between HN links and links in targeted emails. I cannot start phishing GitLab employees using HN posts, the threat model is just different.
- nathantotten 6y agoI’m not so sure about that. With enough dedication and time I think you could target a specific company from HN. Start writing a few good blog posts that would appeal to your audience, only run attack when some attribute is true to that company (i.e. their Corp IP addresses). You could even combine the two. Post the blog to hacker news, then send phishing email pointing to HN post. That is a trusted link. Then the user will likely click the source link in HN. Obviously, a lot harder and lower chance of success, but not impossible.
- 411111111111111 6y ago> [...] only run attack when some attribute is true to that company (i.e. their Corp IP addresses). [...] Obviously, a lot harder and lower chance of success, but not impossible. In general maybe, in this particular case it's gonna be challenging however, as gitlab is a remote company so most employees will logon from residential ips
- asutekku 6y agoI would imagine they would be using some sort of company vpn to access the files they need to use.
- owenmarshall 6y agoMost companies I’ve encountered have moved towards split-tunneled VPNs so an employee clicking on a phish page would traverse the employees gateway, not corporates.
- tbyehl 6y agoMy experience is the opposite: Part of the justification for moving away from standards-based VPNs is to prevent split-tunneling. My present employer's VPN client goes a step further and mangles the routing table to deny access to my own LAN while connected.
- 411111111111111 6y agointeresting, i heard that some employers did set the default route to go through their vpn, havent had that experience myself either though. it was always only the 10.0.0.0/8 and some /24 ranges from 192.168.0.0/16 at my current job
- o-__-o 6y agoliberty mutual, the largest insurance provider, is in the process of moving from default route on the vpn to no vpn at all and zero trust networks for their apps.
- goatinaboat 6y agocannot start phishing GitLab employees using HN posts You definitely could perform a watering hole attack if you compromised a site that always gets on the front page of HN. If I were an evil hacker and I wanted to compromise HN I would instead attack a site like rachelbythebay.com or some other popular blogger then just wait for HN’ers to click the link.
- andrewflnr 6y agoGo for medium.com
- xondono 6y agoJust make a post about rust. Everyone clicks on them. Everyone. (Myself included)
- _asummers 6y agoReflections on trusting rust.
- steveklabnik 6y agohttp://manishearth.github.io/blog/2016/12/02/reflections-on-rusting-trust/ http://manishearth.github.io/blog/2016/12/02/reflections-on-... Not a phishing attempt, I swear!
- jdxcode 6y agoEspecially if it has a controversial title, "Why rust is not a real programming language" "It's a complete waste of time to learn C++ in 2020" "Rust is 2x as fast as C++"
- kchr 6y agoEmotion - the perfect bait.
- xondono 6y ago“Rust is a complete waste of time” And then just point to an article about Rust the game. Jokes aside, I love the name, the pun is nice, but man it makes searching a pain. I’ve ended up too many times in pages related to the game or to actual rust (as in iron).
- yjftsjthsd-h 6y agoEh; I'm 95% here for the comments.
- amelius 6y agoSome people never do ;)
- Rebelgecko 6y agoUsually I mouseover and see where the link would take me. If it's something like micr0soft.co, it raises some red flags. For something like a targeted phishing email, it's even more reasonable to be concerned about things like browser 0 days
- unethical_ban 6y agoEmails and HN are different. Then someone will point out watering hole attacks, where adversaries find where targets hang out socially, and attack that. And then I'll point out that the inherent risk in HN links vs. unfamiliar emails are very different.