3 ms·
I wonder if phishing simulations are allowed. There's nothing explicit in the code of conduct (at least none that I could find with a quick search). Smishing si
by ryanSrich 3y ago
I wonder if phishing simulations are allowed. There's nothing explicit in the code of conduct (at least none that I could find with a quick search). Smishing sims are a great way to train staff on phishing, and disallowing them would be somewhat antithetical to their explicit mission here of protecting they users.
- acdha 3y agoDoes it really make anyone safer? I’d think that time would be better spent deploying WebAuthn so phishing is impossible, and working vendors to reduce the number of legitimate messages which are indistinguishable from phishing.
- flutas 3y agoAt least for the company I work for, to maintain our insurance, we had to be enrolled in a service (KnowBe4) that does nothing but: 1) produce shitty AI voiceover "please don't click email links" videos 2) randomly email, text, etc us with fake stuff trying to get you to click the links. I always report the emails as phishing to Google just hoping one day something gets flagged somewhere on Google's side, but I doubt it will ever happen.
- ryanSrich 3y agoNo one is making you use Knowbe4. As someone that founded a company in this space, the amount of people that hate SAT and Phishing sims purely based on their experience with certain companies is tremendous.
- flutas 3y ago> No one is making you use Knowbe4. My company is, but that's me being pedantic. What I meant "we had to be enrolled in a service" in the "any company that provides this service" and was just giving the current company as an example.
- ryanSrich 3y agoTraining and simulations absolutely do reduce the likelihood of an event. Most companies don't use these tools correctly, and certainly the technical audience here on HN will despise them. But phishing simulations can reduce your risk.
- acdha 3y agoIs there any solid research published on that? The anecdotal evidence I’ve heard from people at pretty large companies was that it only helped with a modest reduction the lowest-skill phishing, whereas actually securing their systems had far more impact.