7 ms·
All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com
by cedilla 1y ago
All that anti-phishing training that taught us to look closely at the URL and now it's all just safelinks.protection.outlook.com
- fp64 1y agoI find it very difficult to inspect the email headers in Outlook, I think for the iOS app it's not even possible. It's almost like they want to make it less transparent and secure
- syllogism 1y agoIn Europe there are legitimate and extremely established services that require you to input your bank login details into something other than your bank's website. It's madness.
- bombcar 1y agoMultiple US hospitals and insurance companies use genuine links like doctor-services-for-u.biz - infuriating.
- dtech 1y agoThere's no legitimate case for that since PSD2 (mandatory since 2020). Are you not confused by that? PSD2 doesn't share your credentials. I'm an European and have never needed to use nor encountered those services.
- siva7 1y agoPSD2 is just MFA, it doesn't prevent shady companies still asking your login credentials, even if you must authorize that login from your official banking app. Klarna is one of many examples - they ask me for my bank credentials on their own website so they can crawl all my finance data .
- bradfa 1y agoPlaid and Finicity do this in the USA for some linking of banking to other financial products. Feels SO insecure. Connecting my credit union checking account through Plaid even ironically brought me to a login page which explicitly states I should never give my banking password to any other entity. If I need to link my accounts and these services are the only choice then I change my banking passwords immediately after.
- chrisweekly 1y agoI thought Plaid used OAuth2. Hmm.
- cpburns2009 1y agoPlaid asks for your raw bank credentials so that it can scrape up data. That's why I've always refused to use it.
- WOTERMEON 1y agoI really hope to never be in the position where I have to use it
- karel-3d 1y agoPlaid whole business model is that it uses OAuth2 on banks that support it and export the data through APIs; and for the banks that don't, they ask for name/password and scrape it through "fake" web browser that mimick user behavior on the backend. (I worked for a Plaid competitor. The long-term goal for all similar companies is of course to use OAuth and APIs, because it breaks less often; but since the banks don't offer that, scraping it is!)
- _boffin_ 1y agoMX?
- StopDisinfo910 1y ago
- dcminter 1y agoWhere a bank doesn't offer compliant APIs, screen-scraping integrations are explicitly allowed. Not sure how common that is at this point.
- _boffin_ 1y agoThousands and thousands of institutions, they scrape.
- dcminter 1y agoNot sure what you mean specifically, but generally the organisations doing screen-scraping¹ would prefer to use compliant APIs as they don't require anything like as much maintenance (bank adds a button to the login flow? Kaboom! Integration is broken...) or resources (e.g. running headless browsers). Some markets are pretty much exclusively compliant - I don't think there are any Nordic banks that don't have fully PSD2 compliant APIs for example whereas, if I remember rightly, the Spanish banks were all over the place. I'm fairly out of date though, so things may have improved or exceptions for scraping expired. ¹ Note that I'm talking exclusively about banking integrations here, not AI nonsense.
- fancyfredbot 1y agoCare to mention what these legitimate and established services are?
- deleted 1y ago[deleted]
- JLCarveth 1y agoPlaid is used by a lot of the major Canadian banks.
- raudette 1y agoFlinks is also an often-used aggregator in Canada. "Connecting" savings accounts from EQ Bank or Wealthsimple to an account at TD Bank requires providing TD credentials to Flinks.
- joshuaissac 1y agoSofort used to do this. I don't know if they still do.
- FinnKuhn 1y agoPaypal, Klarna
- BrandoElFollito 1y agoAre you talking about the possibility to pay via your bank account directly on a checkout page? If so this is the bank page you are using. Can you give some examples?
- BlindEyeHalo 1y agoI find this hard to believe and have never seen that ever.
- jeltz 1y agoIt used to be common 5 years ago before PSD2.
- brettermeier 1y agoDon't understand the downvotes, i never saw that too, and i am shopping online very often.
- consp 1y agoIf you used the first gen "pay later" services they'd scrape you for "compliance checking" or simply mask it as a transaction which is actually just personal information scraping. Most of the times you did not see it, as it's obfuscated as a part of the transaction. They are also the companies complaining a lot about the "failure" of the PSD standards since it limits how much and how obfuscated they can scrape everything (and there are records).
- PeterStuer 1y agoAre you sure? Never seen any such thing.
- didsomeonesay 1y agoName and shame: Klarna did this. Not sure if they still do because i stay well clear of them.
- devoutsalsa 1y agoI recently reported an email with “glint.email.microsoft” as a phishing attempt, but it turned out to be a corporate survey.
- Thorrez 1y agoWell it's probably hard for anyone except Microsoft to get a domain with the .microsoft TLD.
- milkshakes 1y agowhat percentage of the online population do you expect to understand this?
- r_lee 1y agolegit. I could imagine something like x-mucrosoft.email etc. being used and the users would just be like well there was email.microsoft so same thing!
- greengreengrass 1y agoI have often wondered why we don’t see more usage of the brand gTLDs, which many of these big firms own. I muse that this is (part of) the reason why – there simply isn’t the understanding or recognition outside tech circles (or even within tech circles) to comprehend that it is possible to use such a gTLD without a conventional .com or similar suffix tacked on the end. I tend to see it localised to use for marketing micro sites that do not ask for credentials so have no need to establish user trust, or occasionally internal technical uses that will never touch the typical customer’s eyeballs. The other reason I hypothesise is that corporate big brother snooping systems that have whitelists for their trusted services – with entries like mail.google.com or calendar.google.com – are simply too painful at this point for big tech to break for their customers by dropping the .com suffix, so big tech doesn’t bother. No hard data on any of that, though.
- Thorrez 1y ago
- jcims 1y agoOutlook has a rule filter for header content. Just saying I haven't failed a phishing test in ~10 years.
- sciencejerk 1y agoMind sharing your filter rules? KnowBe4 uses X-PHISHTEST header and I think I saw Proofpoint using something similiar a few years back
- jcims 1y agoStraight from the source: https://help.proofpoint.com/Proofpoint_Essentials/Security_Awareness/Educate/Searchable_Header_in_Mail_Server https://help.proofpoint.com/Proofpoint_Essentials/Security_A... xD The vast majority of security controls are designed for the careless and the clueless.
- jsmith99 1y agoMy IT department use the official Microsoft phishing test. The emails arrive in inbox with 0 headers. (There's also a helpful Microsoft page of all the dodgy sounding domains they've registered for this.)
- monocularvision 1y agoI did this and it worked for a few months before word got to security who then forced everyone to remove the rule.
- prmoustache 1y agoI just don't check my emails anymore. If it is important, people will complain on teams that nobody answer with some sort of urgency and then I'll look for it specifically.
- Workaccount2 1y agoMy It department does mandatory phishing training every year, and then for the "test" e-mails, they spoof a domain and whitelist the DMARC on their side so it goes through. So we get e-mails from @microsoft.com and it's only if you dig in the metadata that you see it failed authentication. The only tell in the e-mail is checking the URL, which doesn't tell you much because tons of regular e-mails use tracker redirects too. They even send emails from our own domain or the domain of our payroll company. I won't type out my rant, but our IT department is a few guys who couldn't figure out what to do when their competitive xbox FIFA 2006 dreams failed, heard IT pays a lot with not much work, and then sat through the certs.
- stronglikedan 1y ago> heard IT pays a lot with not much work I want to live in this fantasy world! (Our IT dept is so overworked that I go out of my way to work around them purely out of empathy.)
- throwawaylaptop 1y agoEvery industry has its bad employers and good. I know teachers that make $50k and no pension, with others making $93k, halfways to their pension at 35yrs old, get almost 12 weeks off total a year, and work from 8am to 3pm (1 hour lunch, 1 hour for 'prep' aka Netflix) and home by 335, and no, they basically never do any work at home. She technically has students (10 year olds she sends links to for their chrome books) about 5x53 minutes a day.
- fair_enough 1y agoThat sounds like a good semi-retirement gig just to get out of the house for a little while. If you're teaching the tech-related electives rather than mandatory core courses, the students are likely a lot more pleasant to deal with. I took German just to get away from the all the kids taking Spanish or French who were just there because they have to get their foreign language credit.