7 ms·
Regardless of which side of the political spectrum one is or what qualifications one has or what terrible deeds one has done (or alleged to have done), the fact
by wtmt 6y ago
Regardless of which side of the political spectrum one is or what qualifications one has or what terrible deeds one has done (or alleged to have done), the fact is that phishing attacks aren’t very easy to avoid (you’d be fooling yourself if you believe you’d never fall for one). You can ace all the phishing email tests your company routinely sends you and still fall for a more sophisticated attack or fall for something that in retrospect seems stupid because you were preoccupied or stressed or had other serious things going on in life.
Victim blaming and questioning how she could believe that she’s qualified for some position is the wrong thing to talk about, and is also disgusting in certain ways.
What would be better, at least in a tech focused community, is to find out more details on how this happened and where the gaps (that are obvious in hindsight) are. I wish someone like Brian Krebs (of Krebs on Security) could get more information on this and do a detailed write up. That would be more insightful and useful to everyone than rants about the victim.
- ghaff 6y agoThank you for posting that. There are obviously way too many people here (and elsewhere) who think they're way too smart to fall for phishing and other forms of scams unlike "stupid" grandmas, journalists, etc. The reality is that we all do things when we're distracted and not really paying attention. Or we get caught up in the excitement of something and we don't stand back and ask ourselves whether it really makes sense. And anyone who thinks otherwise is just arrogant and misguided.
- dissidents 6y agoIt may well be true that phishing scams can be easy to fall for, but it is not relevant to this story. Razdan tweeted that she was joining the Harvard's Faculty of Arts & Sciences as an Associate Professor. Regardless of how convincing the phishing attempt was, this is incredibly naive; Razdan does not have a PhD or any publications and Harvard's FAS does not have any professors in journalism. Edit: https://twitter.com/ruchirsharma_1/status/1350067266289856512 https://twitter.com/ruchirsharma_1/status/135006726628985651... It seems that this may not even have been a phishing attempt.
- pmiller2 6y agoNot to mention that universities typically don't hire people at the associate professor level. The first rank is called "assistant professor," followed by "associate professor," and then "full professor." Associate and full are tenured ranks, which is why there isn't much hiring at that level. Also, one would expect any open position at a US university to be advertised, most likely in The Chronicle of Higher Education. This is something perhaps only someone who's got a little familiarity with the academic job market may know, so, I suppose one could be forgiven for not knowing it, but I would assume that one would at least google for open positions at Harvard to find out if it really exists. That said, naïve or not, I also don't think victim blaming is a productive thing to do here. All it does is discourage people from speaking out about their experiences, which means we can't learn from them. It may also discourage people from seeking help when they think they might be getting phished.
- LordAtlas 6y agoThis thread says people from industry are sometimes hired without needing Ph.Ds - https://twitter.com/gauravsabnis/status/1350414118986121216 https://twitter.com/gauravsabnis/status/1350414118986121216
- pmiller2 6y agoOk? I never said anything about PhDs. What I said was that people typically aren't hired in at the associate level. Those that are would typically be professors who have tenure at another institution, meaning that they're already at the associate level or higher. People who are denied tenure at their current institution and want to continue in academia would apply to an assistant professor job and negotiate a shortened tenure clock, meaning that they would be assessed for tenure in fewer than the standard 6 years that a brand new, never held a professorship of any type assistant professor would have. Again, this is a lot of esoterica about the academic job market that not many people outside of those circles is going to know, so I don't blame anyone for not knowing it.
- 6y ago
- pwillia7 6y agoThis reminds me of how if you ask almost anyone if marketing works on them, they'll say no or not the deceptive parts. Yet, logically, marketing must work on most people or Coke wouldn't spend 4 billion dollars a year on it. Feels hubris-y to me. We forget we all have the same equipment. https://www.investopedia.com/articles/markets/081315/look-cocacolas-advertising-expenses.asp https://www.investopedia.com/articles/markets/081315/look-co...
- CyberRabbi 6y agoPeople always say marketing doesn’t work on them until you ask them to name non-Coke carbonated beverages...
- eitland 6y agoI'm not sure if I understand you correctly, but at least around here thers RC Crown Cola, Solo, Farris, Pepsi, Pepsi Max, Eplerose, Oscar Sylte Pærebrus, Monster energy, Red Bull, 7-up etc and I don't think I am special at all for knowing them. In case it matters, a number of these don't advertise, at least not in the same league as coke (multiple national campaigns a year).
- CyberRabbi 6y ago> I don't think I am special at all for knowing them. I would guess that at least 80% of people off the street would only be able to name advertised carbonated beverages. In that case, yes I think you are special.
- sjs7007 6y agoIdk, it could still be wrong or not as useful as thought of. https://www.forbes.com/sites/augustinefou/2021/01/02/when-big-brands-stopped-spending-on-digital-ads-nothing-happened-why/ https://www.forbes.com/sites/augustinefou/2021/01/02/when-bi... :When Big Brands Stopped Spending On Digital Ads, Nothing Happened. Why?
- 6y ago
- networkimprov 6y agoThis. And the effectiveness of targeted phishing is why we must replace SMTP-based email, and eventually block SMTP on public networks. It isn't suited to the 21st Century Internet. Hence, the mnm project[1] (open source client & server) and TMTP[2][3]. [1] https://mnmnotmail.org https://mnmnotmail.org [2] https://github.com/networkimprov/mnm/blob/master/Protocol.md https://github.com/networkimprov/mnm/blob/master/Protocol.md [3] https://mnmnotmail.org/rationale.html https://mnmnotmail.org/rationale.html
- md_ 6y agoHmm, the value proposition of MNM here (in preventing phishing) seems to derive from the design goal of not allowing arbitrary content on first contact between arbitrary users, or do I misunderstand? This strikes me as a cure worse than the disease. There’s a strong social need for people—especially those who are public figures or soliciting job offers—to be reachable by “never before seen” contacts. There’s also a strong social need to allow people to send emails from self-provided (I.e. unverified) names or identities, given the currently burdensome process of getting “verified”. I think you could argue that there’s an opportunity to move business email to “real ID”-verified identities (e.g. with SMIME), but I struggle to see how that’s a problem with SMTP or how replacing the protocol will help there.
- darepublic 6y agoI remember in a state of heavy depression filling out some random email spam survey and being about fourty questions into it before asking myself what the hell I was doing
- mlang23 6y agoI have yet to see a scam which would fool me. And I have seen many already. All the scam and phishing mails I saw in my whole internet career were somewhere between totally obvious and embarrasingly blunt. I can't agree with your assessment. If someone is naïve, they are at risk. Same applies for overconfidence. These are personality traits which are easily exploited. In real life as well as on the Internet. We cant protect everyone from everything. Neither in healthcare nor in VR.
- quesera 6y ago> I have yet to see a scam which would fool me. And I have seen many already. That's because you have never been targeted. It's that simple. There is a small segment of society who are: a) savvy, and b) not actively engaged in commerce/business/community/career/friends/family, so any solicitation over email is likely suspicious. Everyone else is at some level of risk. And sometimes it only takes one failure.
- mlang23 6y agoInteresting. How do you know that I have never been targeted. Did you ask your crystal ball? Or is it that you just know everything? I am amazed and bow to your skills, great magician. Also, implying that I am not actively engaged with anything is a pretty personal attack. Reserve your patronising behaviour for your children please.
- aidenn0 6y agoEven untargeted scams can fool a savvy person by coincidence. I followed my accountant when he switched accounting firms. Within two weeks of that, I got a generic accounting email SharePoint document share. It linked to the actual ms domain and used some redirection trickery to end up on a pixel perfect copy of the office 365 login screen. I only didn't get scammed because my password manager refused to auto fill. Had the email come after I had learned the name of the new accounting firm, I never would have even clicked on the link.
- ghaff 6y ago
- gumby 6y agoA clever element of this is the cross-cultural nature: the Harvard name internationally known, yet someone not in that milieu would not be able to detect a number of "red flag" anomalies. In fact if the author was phished by someone in India (a likely case) then the perpetrator could make a cultural error that would be undetectable by the victim as they might share the same set of assumptions. I say "cross cultural" but by that I also mean "cross domain" which is how financial scams can entrap victims who aren't familiar with the details of financial jargon. It's also why people can believe conspiracy theories which are absurd to someone familiar with the domain.