6 ms·
During covid when WFH, I received a legitimate looking SMS message with a link, so rather than clicking it, I curl --verbose'd it (and one subsequent redirect)
by notbeuller 3y ago
During covid when WFH, I received a legitimate looking SMS message with a link, so rather than clicking it, I curl --verbose'd it (and one subsequent redirect) before seeing it was an obvious phishing / troll. The next day, my VPN & SSO was disabled with instructions to contact corporate security. My use of curl had been detected and while they didn't accuse me of anything, they claimed that they wanted to make sure that I hadn't been hacked. I've never felt safe since then - I don't know how "deep" this spying goes. Yes it's their equipment, their network, etc. But I hate the way this makes me feel.
- cmrdporcupine 3y agoYikes, that would be a clear sign to me of a... culture fit... problem at work. And I'd immediately begin looking elsewhere.
- dudul 3y agoAgreed. Where do you guys work to be monitored like that? I dick around all day at work, I watched YouTube video in the background, I still use paper notes so my cursor can be still for an hour sometimes, etc and I never received anything like that. That's over 4 employers since I went full time remote. Not saying they're not "watching" me, but they don't seem to care. Is there a typical profile for companies that go that far in the 1984 crazyness?
- prmoustache 3y agoBesides paper notes and brainstorming with my own self on my whiteboard, I sometimes disconnect from the vpn and put myself offline in MSTeams for several hours, telling my manager and direct teammates that they can use pagerduty to ping me if urgency calls for my immediate availability, when wanting to focus on a specific task/piece of code/resesrch/document/architecture decision. Context switches can really kill productivity. So much that sometimes I do much more work in a 2h window between 7am and 9am than the next 6-7 hours.
- dehrmann 3y agoHard disagree. I've worked at multiple companies that care about security. Monitoring employee equipment use for activity that could indicate a compromise is a positive signal.
- IshKebab 3y agoI agree. I worked at a company that has this endpoint monitoring software and occasionally got emails saying "was it you that ran this command". I just said "yes" and they were like "ok carry on". I'm not sure how much value there is in that kind of monitoring, but it isn't necessarily bad.
- EastSmith 3y agoI guess the Q that bothers me the most is who has access to my activity, when it was accessed and why.
- dehrmann 3y agoI'm personally not too concerned with cases like this. I mostly avoid personal activities on work equipment unless they're benefit-adjacent. My thinking is if they over-snoop and see health or financial data they shouldn't see (and it gets out), it'll look bad because I was managing benefits that are part of my employment. Outside of that, I keep my use very benign. I'm logged into the Financial Times and Stackoverflow. Most companies with knowledge workers won't look at any metrics they collect unless it's a security thing or they have a reason to look. But yes, assume that they can look if they want to. Once they start snooping around, they're probably going to fire you regardless. They just need a story to tell.
- xlii 3y agoI sympathize - it must’ve been stressful to go through this. Yet I just can’t stop to imagine the other side’s perspective and it’s making me laugh: I’m sitting in front of the monitoring dashboard, chewing a sandwich, and then a spike of intranet activity shows on one of the charts. I look at the dashboard and immediately notice that it’s effect of some SMS broadcast. Nothing to see here: lazy Tuesday. Then on the dashboard with user agents new column shows. 1 request. Curl’s user agent sticks out like a sore thumb. “Oh, someone probably just copy & pasted contents of the text message to check it out through curl in order to be safe” wouldn’t take place in Top 10 thoughts that’d I have after seeing that.
- notbeuller 3y agoIf I'm using curl, I'm probably also using git, ssh and wget. I think an active threat would be more likely to try to blend in (a giveaway would probably to use a user agent that declared I was using a different OS because it was hardcoded into the payload.) What I end up thinking about is that even though I'm back at the office full time (and I'm one of the weirdos that actually prefer it) I have doctors appointments, school teacher meetings and such that have all moved online. So convenient!, except there's no way I can realistically attend them privately, so a 5 minute meds appointment is now once again a 3 hour travel ordeal. End-to-End encryption doesn't matter if your employer is scraping your device. I know this is all obvious, but it didn't need to be this way.
- deleted 3y ago[deleted]
- MagicMoonlight 3y agoThat seems pretty reasonable. Out of nowhere a user started running commands targeting malicious links. Could be control signals for an attack.
- maxflow2 3y agoYeah. Like... monitoring network activity on the VPN for security is one of the areas I would be surprised if the employer IT wasn't doing. I don't know why that would surprise anybody.
- _8j50 3y agoWait, so you curled a phishing link while connected to a corporate network and you didn't think that would be monitored? I am sorry but your company's security team is not doing well if you're surprised by this. What is your expectation if I may ask? Because I spend a LOT if time just looking at what what people are doing via email, endpoint and network logs (looking for malicious activity, don't care about their performance or going to naughty sites), do you not know that is happening?
- marcosdumay 3y agoAt the beginning of the covid it became popular to hire some companies that send those links, and then report back who opened them to you, so you could train the people. You may have been caught in one of those exercises. But anyway, always assume your workplace's VPN logs every access. The obvious retention period vary from one place to another, but the logs seem to always exist.
- NoZebra120vClip 3y agoWere they taking issue with your use of a tool, or the fact that you apparently click on phishing links? Was that a test run by your company's cybersecurity department? Is your phone personal? BYOD? Company-issued? I can't fathom how "detecting curl" can put you in the doghouse, but I would shut you down too, for accessing malicious websites.
- bombolo 3y agoIt's the url, i'm sure it had a get parameter to identify him.
- NoZebra120vClip 3y agoSure. Companies run phishing trials all the time; it is a favorite pastime of security consultants. They want to see how many of their employees will click on suspicious links. It's extra-difficult to deal with SMS when it comes in from the airwaves, and not a company-controlled system that can be firewalled and IPS'd. It seems misplaced to blame the company for surveillance when they're trying to keep everyone safe, including the devices in your home. It seems far more preferable to have a sting operation and catch mistakes, than to for-reals access malware and have it install on those same devices. That's exactly what they're trying to prevent and mitigate. It would be the same whether you're at home on a personal device, or you're at your desk in the office with boss over shoulder. You would have a right to object to oppressive or intrusive company surveillance, but this doesn't even come close. Of course, we have few details here, and I have leapt to a very particular conclusion about that situation; who knows what really happened. But in the interest of general knowledge, employees should be aware that phishing tests will be run, and you can expect to have a little chat if you fail the test (or actually get phished.)
- bombolo 3y agoTrying to keep everybody safe using misguided strategies that do not work, instead of doing something that works (like using 1 internal domain and nothing else, for example).
- bombolo 3y agoAh yes the famous phishing tests. They bypass every spam filter, and if your company is like mine, that uses a new external website every week for something, it's completely impossible to tell apart phishing from actual email.
- devnullbrain 3y agoI've successfully navigated dozens. Git gud?
- bombolo 3y agoOP hit the URL… Maybe your company isn't as bad as mine? If the test bypasses the spam filters and is correctly signed from an internal sender… what kind of idiot test is it?