6 ms·
The majority of successful attacks are business email compromise. In that context take9 makes sense in my mind because there _is_ responsibility for users to be
by redman25 1y ago
The majority of successful attacks are business email compromise. In that context take9 makes sense in my mind because there _is_ responsibility for users to be mindful of clicks.
Not every phishing email can be caught before it reaches users and campaigns to raise user awareness I think are important.
- beardedwizard 1y agoI think you are drawing the wrong conclusion - users cannot be mindful of clicks, we should live in a world where click is assumed and go from there.
- cmeacham98 1y ago> users cannot be mindful of clicks Why not?
- esseph 1y agohttps://gist.github.com/StevenACoffman/a5f6f682d94e38ed804182dc2693ed4b https://gist.github.com/StevenACoffman/a5f6f682d94e38ed80418... https://daniel.haxx.se/blog/2025/05/16/detecting-malicious-unicode/ https://daniel.haxx.se/blog/2025/05/16/detecting-malicious-u... Because deception is easy
- x0x0 1y agowe've been trying "dear user: caveat emptor, every email you get has eg a 0.01% chance of being a security hole" for 30+ years and it's resulted in comprehensive failure. See also the campaign to make users competent sysadmins of their own devices. Hell, I almost got got because the morons running our cell networks let anyone text and claim they're fedex. No reason to authenticate a thing like that. I was waiting for a delayed / lost package so it wasn't crazy that fedex would be texting me. If they'd used a better link forwarder domain I probably would have clicked.