4 ms·
How do people not smell these from like a mile away? Must be proposals to people very new to this sort of work. To get me interested enough to even open a docum
by gexla 3y ago
How do people not smell these from like a mile away? Must be proposals to people very new to this sort of work. To get me interested enough to even open a document, there's a lot you would have to get right before I hit that step.
- crazydoggers 3y agoMaybe this is a generation that has grown up with virus and spam protection good enough this almost never gets by, so they are unaware? For us old timers this was pretty much an e-mail every other day sort of thing. I remember putting up a website for contact work and getting spam virus crap within weeks from just automated bots. On top of that, I wouldn’t even open a compressed file from someone unless I had a previous relationship with them, and even then I still would scan it since their computer could be compromised. I don’t care if it’s a contract offer, from my attorney or the president of the United States.
- crazydoggers 3y agoJust to be clear, a password protected zip file should be an enormous blinking red light. 99% of the time, password protected zips are used to prevent virus scanners from scanning the content of the zip. Typically email providers like google will provide you with a warning that they have been unable to scan the file. As for emails about contract jobs, even 15+ years ago these could be very targeted, specifying your company/resume etc. Now it will be getting even worse with chatGPT to write these emails in far less time and far more convincingly from non-native speakers. Also note, unzipping files to look into them isn't automatically safe either... there are plenty of older CVEs where zip software had vulnerabilities allowing code execution, and a zero day is always possible. That's on top of the fact that zips can conceal file types of other software that might also have current CVEs. Short story, and this should be followed by everyone in the tech community, never ever open attachments from anyone you don't know, and treat all attachments from people you do know as requiring scanning first. Not doing so puts your coworkers and your customers at risk. If you're accepting proposals for contract work, your process should always require one-on-one communication prior to accepting any attachments.
- cramjabsyn 3y agoLike what?
- deleted 3y ago[deleted]
- thih9 3y agoBeing convinced that you’re good at detecting social engineering attacks just makes it easier for you to fall for a social engineering attack.