4 ms·
It is inexcusable that Twitter is employing people who are susceptible to social engineering attacks like this. This is simple training and seriousness.
by MoZeu 6y ago
It is inexcusable that Twitter is employing people who are susceptible to social engineering attacks like this. This is simple training and seriousness.
- t-writescode 6y agoIt just takes one mistake to be spearfished.
- mikehollinger 6y agoI will freely admit that I fell for a phishing campaign. I’d just bought something on eBay (this was a while ago). I got an email about something in my account later that day that made it through my spam filters. I clicked on it, signed in, and then realized I’d done the deed. Nothing happened or was lost, but yes - it just takes one quick mistake.
- nevertoolate 6y agoI don’t get it. You know your ebay password?
- Thorrez 6y agoSome password databases involve copy and pasting or autotyping. If you want automatic hostname verification you need a password database integrated with your browser. On mobile many browsers don't support extensions so integrating my password database into the browser would be hard. In short, I do not know my ebay password, but I could have fallen for this phishing attack.
- carstenhag 6y agoOn mobile this is possible even without browser extensions - enpass, lastpass etc work just fine in Chrome or any other app, if it detects a password field.
- Thorrez 6y agoOh, you're right. I didn't know Android had that feature. Apparently I was way behind the times. I can no longer edit or delete my comment.
- mikehollinger 6y agoThis was 2008 - way before I’d discovered the value of a password manager.
- deleted 6y ago[deleted]
- function_seven 6y agoAll companies employ people who are vulnerable to social engineering tactics. All of them.
- bawolff 6y agoTraining that is notorious for being ineffective in practise and usually more about box ticking. Assuming that none of your employees fall for phising, much less targeted phising, is woefully unrealistic. Especially at twitter's scale. Assuming humans won't do stupid things 100% of the time is never an effective security control.
- andykx 6y agoThis is an excessively pessimistic take on security training. How many spear phishing attempts have been thwarted because the employee knew better? It’s not a solution to the problem, but it certainly helps.
- bawolff 6y agoI would actually be interested in seeing some studies on that. My gut feeling is for engineers, the phising training that most companies use is wholly ineffective at doing anything, and in particular it is especially ineffective against targeted attacks. But i have yet to see any research one way or another. I suspect less technical users might benefit from such training a bit more (but still not that much)
- AnimalMuppet 6y agoHow many? A fair number. Not 100%, though. If your system depends on your people 100% not falling for spear phishing, your security is dead.
- andykx 6y agoWell, that’s what I meant when I said that it isn’t a solution. You shouldn’t rely on training, but it’s disingenuous to say it can’t help.
- AnimalMuppet 6y agoAh. It seems I was in violent agreement with you.
- jacquesm 6y agoYou too could be social engineered. The worlds foremost security specialists are not immune, good chance that there is some social engineering vector that would work on you. Admitting that to yourself is a huge step forward in being able to detect it. Believing yourself immune increases your chances of being spearfished.
- Thorrez 6y ago> The worlds foremost security specialists are not immune I bet there are some that are immune. But yes, 99% of employees can be phished.
- spike021 6y agoYou say this like human beings can be perfect. Nobody is perfect. Everyone is vulnerable given time/effort.