3 ms·
My company's security training tells me to carefully verify any URLs in received emails, but then they have some security software that rewrites all the URLs in
by anonymous_sorry 3y ago
My company's security training tells me to carefully verify any URLs in received emails, but then they have some security software that rewrites all the URLs in incoming emails - presumably as a way of screening them themselves.
This might be a reasonable trade-off for centralising monitoring, but it significantly hampers the ability to judge the legitimacy of emails myself. At least update your training!
- lhamil64 3y agoMy company does that too, it's really annoying. They also sometimes send out mass emails for things like surveys but link to some third party service. I've even seen them put, in the email, things like "the link goes to a trusted third party and is perfectly safe". Why should I trust that if I'm already suspicious of the emails legitimately?
- ToucanLoucan 3y agoOur last round of security training was roundly mocked by our software division, especially around the subject of one of the rules emphasized over and over being to "never click URLs in emails" and the sign-in process for the website alongside the distribution of lessons was done exclusively through magic links... in emails. Our CEO is actually a developer himself on our core product (and a bit of a paranoid fella on the cybersecurity front to boot) and he was absolutely furious about this vendor being chosen...
- Corrado 3y agoM365 has an option to rewrite URLs in incoming emails. It's horrible, at least for people that can actually read URLs. Every link turns into a 300 character mess that I have no idea if its valid or not. The only way to tell is to click it. Maddening!