4 ms·
.... They didn't fail the test. They are having hard times and thought they were getting a holiday bonus which does happen. Where/Why they failed is because t
by damm 6y ago
.... They didn't fail the test. They are having hard times and thought they were getting a holiday bonus which does happen.
Where/Why they failed is because times are tough and if all you had to do is fill out a form for 650$ would you really not do it?
It's not awareness it's people are effed and struggling
- burnthrow 6y agoIn summary, they failed the test.
- acdha 6y agoAlternatively, GoDaddy has failed to secure their work environment and are blaming the workers instead. Think about why we care about phishing: it’s mostly about people giving credentials to an attacker. Drop $20/person on some FIDO tokens and the risk factor drops considerably. Repeat for the risk of malware - if someone in accounting can run arbitrary software, they aren’t the root cause.
- kenjackson 6y agoIt’s defense in depth. Just because you have one line of defense doesn’t mean you shouldn’t have another. The way defense in depth typically works is assuming the previous lines of defense have been thwarted. Even if you can’t foresee that happening, assume it did. And it sounds like these employees were trained on this. The thing I don’t like is the XMas bonus aspect. But the general idea doesn’t seem unreasonable.
- acdha 6y agoHow much depth is it really adding, though? Harassing non-specialists seems to have relatively limited value – plenty of security staff get phished – and there is a risk of making people think of the security group as adversaries. I would certainly agree that the exercise could have some value but I think it would be wise to weigh that against the costs and especially to think about how you can make it supportive rather than punitive. In particular, most people are not only not given good tools for making untrained security decisions and many of them will be told to violate that advice regularly. For example, what percentage of vendors, outsourced HR, etc. will tell people to open unexpected attachments or click on links which are difficult to distinguish from phishing? SolarWinds was far from the only company training their customers to ignore security errors on installers, too.
- at-fates-hands 6y ago> Alternatively, GoDaddy has failed to secure their work environment and are blaming the workers instead. This. I've worked at careless companies who don't deal with their security very well. I now work at a large health care company who takes security incredibly serious. All the USB ports are disabled. Nobody has admin rights on their laptops. You can't install any software unless you download and install from their internal app store which only allows apps that have passed a rigorous gambit of testing beforehand. And you have to put in a request for the software in the first place. It took me three months to get Photoshop approved because I was designated as a developer and not a web designer. It went through three escalations and took several debates between senior managers who finally approved my request. We don't have "phishing tests". If something pops up on the security team's radar, then they push it out as an email alert company wide. That's about it. Maybe if GoDaddy put as much effort into securing their network as they do putting together these stupid tests, they probably wouldn't need them to prove that yes, humans are fallible.
- btilly 6y agoI'm sorry, but your 3 months to get Photoshop approved demonstrates why so many wouldn't want to work in such locked down environments. And what was the cost to the company in having those debates between senior managers? Just to get a standard tool that they already approved onto a developer machine? Can you imagine the overhead that they are causing themselves?
- NullPrefix 6y agoThey failed the test the moment they started working at godaddy.
- DoofusOfDeath 6y agoI'm not sure I follow your logic. IIUC, a traditional phishing test involves: (a) Prior training for what employees are supposed to look for, and how to respond if they think they're being phished. (b) Unannounced drills to confirm that employees act in accordance to (a). If some GoDaddy employees did not act in accordance to the training, how is that anything but a failed test? [EDIT] I just realized that "how is that anything but a failed test" could sound reductive. FWIW, I would call this a test failure and also a really unwise test design.
- jldugger 6y agoHonestly, blaming the employee here is the fallacy. Employees don't fail phishing tests, companies do.
- lazylizard 6y agoif they're still employed at godaddy why are they having hard times? if they're greedy for an extra $650 windfall... thats what a real phish will dangle as well?
- notgoodrobot 6y agoMany people have spouses out of work right now. It's possible to have a job and be in a bad situation. Regardless of whether the employees actually need a bonus. Dangling the idea of a bonus as a test, shortly before the holidays and during a pandemic seems like a recipe for bad publicity or at least some frustrated employees.
- lawnchair_larry 6y agoWhat makes you think GoDaddy employees are struggling financially? They all have their jobs, and their costs are likely lower than pre-pandemic. Many are suffering and unable to work, but that wouldn’t include this set of people.