when the company has no loyalty to you, why be loyal to the company?
No need to be, but this is a bad example because if the company can prove you were wreckless intentionally, they have an easy court case and someone now liable for all damages
How would they prove it?
By showing how you drew a comic about it them posted it to lemmy ofc
Given the example from the comic the email he sent would be sufficient proof.
“I was sick the day of training and HR never rescheduled. Why, did I do something wrong?”
Reckless*
Oddly, "wreckless" might mean the exact opposite.
I will think about this every time we have a meeting to discuss the stupid "shame and train" faux phishing attacks they run on us at work.
Pro-Tip: If you set up the right kind of filtering you'll never see those stupid things. (Fight club rules).
The one they use at my work is extra silly, as it adds an extra email header saying it’s coming from a phishing campaign
Ours do that too. It's so obvious that I'm not sure if they think we're all stupid, except then I remember that some of my coworkers actually are stupid, so it's probably aimed at them.
except then I remember that some of my coworkers actually are stupid, so it's probably aimed at them.
I work in IT and have done these campaigns, if you're on Lemmy, you're probably not the target audience lmao
There's an older guy in my group who rants and raves about how all the new training is a waste of time. Discrimination, harassment, safety, information security, all of it. But he specifically hates the fraud and phishing training.
He's the only one in our group that has failed any of the test emails.
I've worked with a dude for years who I would consider smart both technically and non-technically. One time we got an email at work with an attachment that was something like "microsoft_update.exe.txt". The email said "due to a technical limitation on the email system, this file needs to be renamed to drop the .txt and executed to apply a critical to your computer."
It was, in my mind, such an obvious phishing attempt that I laughed out loud and said "who the fuck would ever fall for this?" Then my coworker popped his head over the cube wall and said "WAIT WHAT? We weren't supposed to run that?!"
Fortunately, the security team sat nearby and heard the whole thing and rushed over to quarantine his PC
quarantine his PC
You mean shut it off and steal and the Ethernet cable? Lol
You DONT want to turn it off. Digital forensics work WAAAAAAY better if you have a memory dump of the system. And all the memory is lost if you turn it off. Even if the virus ran 10h ago and the program has long stoped running, there will most likely still be traces in the RAM. Like a hard drive, simply deleting something in RAM doesn't mean it is gone. As long as that specific area was not written over later it will still hold the same contenta. You can sometimes find memory that belonged to a virus days or even weeks after the infection if the system was never shut down. There is so much information in ram that is lost when the power is turned off.
You want to 1: quarantine from network (don't pull the cable at the system, but firewall it at the switch if possible) 2: take a full copy of the RAM 2.5: read out bitlocker keys if the drive is encrypted. 3: turn off and take a bitwise copy of the hard drive or just send the drive + memory dump to the forensics team. 4: get coffee
Why would you be doing digital forensics?
To find out if nuking that one workstation is enough or if you have to take more drastic measures.
I feel like most companies wouldn't bother with all that. They'd probably just nuke the workstation and call it a day.
And then get ransomwared a bit later.
Oh yeah probably
Even a smart person can have a bad day / moment of weakness. If you are super busy / stressed out and some email comes that looks like a bullshit request from HR or IT or whatever, it can be tempting to just try to knock it off your plate real quick so you can get back to whatever fire you were fighting.
My tactic these days is I pretty much don't click on ANYTHING in an email, so it's an ingrained habit. If it's a link to something, it's usually one I can navigate to myself using my browser. If it's an attachment, we use a file sharing system that stores these so I can just go to that and see what's in there.
It's inconvenient, and you don't always have these work-around options, but by trying to make into an automatic habit, it has saved me a couple of times.
Lmao, the other day I had to whitelist some domains used for phishing training emails in the anti-phishing software we use just so they wouldn’t get nuked, then I had to whitelist them in another anti-phishing software so they wouldn’t have - huge red header injected on the top of the email body warning the user it was phishing.
The Microsoft 365 admins at my workplace were doing something like this. It's got some sort of built-in phishing simulation functionality (I think it's this: https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-simulations). The idea is that the recipient clicks a button in Outlook to report it as suspicious, and get a "congrats you did the right thing" notice.
However, it seems like IT security were unaware of the test, because they started blocking the emails and blackholed the domain the emails linked to (meaning it doesn't resolve on our network any more). They also reported the domain as phishing to some safe browsing vendor we use, which propagated into the blocklist Chrome uses. It was a shared domain Microsoft use for this training (it was one of the domains on this list: https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-get-started?view=o365-worldwide) so Microsoft probably had to deal with un-blocking it...
Alternatively, over-report. Spelling mistake on an email from a colleague? Seems phishy to me. Email from a colleague with an attachment? Phishy! Unsolicited email from a client? Phishy! Email from 'social committee' sent to everyone in the team? Phishy!!!
Please don't.
I have to initiate those, or it looks bad for compliance. We sell software, we get SOC 2 attestations yearly. We start getting points marked off for very general security and compliance measures customers will question our products and not renew or not purchase in the first place, because if we can't even secure our own employees and promote awareness, what does that say about our product?
Sincerely, the guy everyone hates and makes your work life harder.
Received an email about phishing? Oh, you better believe that's phishy!
except too many companies take that extra step of being annoying:
- you get a write up if you fall for the phishing
- you get a write up if you don’t fall for it but also fail to report it
- you get a write up if you don’t fall for it and do report it but don’t use the correct report form
We're supposed to forward the spear fishing emails to IT but I always just report as spam and go about my day. Was only nervous the first couple times I ignored an obvious internal phishing test but apparently they don't care if we don't fall for it.
you also fail if you use the right form but don't staple a cover sheet for the tps form followup.
My company is using some tool to generate those kinds of false scam emails every few weeks, so I created a rule in Outlook that if the header contains the word "gophish", it put a label "lol phishing" on it, so I know to just delete them...
I worked at a place that actually tracked whether you reported the fake phishing emails or not...
Plenty of companies will assign you extra training because you aren't reporting.
Ugh. I got one of them recently and clicking on it and hitting report as spam apparently registers as me having interacted with the email so I have to do the security course again.
This would explain why this works so often
Why did the hacker leave their purple dildo out on their desk? Awkward 😬
Ah, an email from yourcompaniesit@msn.com. Must be from IT.
(I deal with vendors that still use yahoo.com emails …)
The thing that doesn't make sense to me is when vendors have their own domain and site but they use a freemail account (Yahoo, Hotmail, Gmail, etc). If you really want to run your business using a free service, at least use an email forwarder at your domain.
The password is either admin or password
Summer2024 Autumn2024 Spring2024 Winter2024
Are the most common passwords for regular employees. Update the year with the current or previous one.
Source: I was in IT.
P.s. if you have access to the physical location. Look for post-it notes under the keyboard.
Under the keyboard? The company you worked for must be some sort of security company or financial institution. I've seen them stuck on the damn monitor.
"what is your password?"
"uh, it's just the letter A"
https://www.youtube.com/watch?v=uRGljemfwUE. A classic.
I'm sorry, there isn't an option to arrange icons by "penis."
Comic Strips
Comic Strips is a community for those who love comic stories.
Rules
-
😇 Be Nice!
- Treat others with respect and dignity. Friendly banter is okay, as long as it is mutual; keyword: friendly.
-
🏘️ Community Standards
- Comics should be a full story, from start to finish, in one post.
- Posts should be safe and enjoyable by the majority of community members, both here on lemmy.world and other instances.
- Any comic that would qualify as raunchy, lewd, or otherwise draw unwanted attention by nosy coworkers, spouses, or family members should be tagged as NSFW.
- Moderators have final say on what and what does not qualify as appropriate. Use common sense, and if need be, err on the side of caution.
-
🧬 Keep it Real
- Comics should be made and posted by real human beans, not by automated means like bots or AI. This is not the community for that sort of thing.
-
📽️ Credit Where Credit is Due
- Comics should include the original attribution to the artist(s) involved, and be unmodified. Bonus points if you include a link back to their website. When in doubt, use a reverse image search to try to find the original version. Repeat offenders will have their posts removed, be temporarily banned from posting, or if all else fails, be permanently banned from posting.
- Attributions include, but are not limited to, watermarks, links, or other text or imagery that artists add to their comics to use for identification purposes. If you find a comic without any such markings, it would be a good idea to see if you can find an original version. If one cannot be found, say so and ask the community for help!
-
📋 Post Formatting
- Post an image, gallery, or link to a specific comic hosted on another site; e.g., the author's website.
- Meta posts about the community should be tagged with [Meta] either at the beginning or the end of the post title.
- When linking to a comic hosted on another site, ensure the link is to the comic itself and not just to the website; e.g.,
✅ Correct: https://xkcd.com/386/
❌ Incorrect: https://xkcd.com/
-
📬 Post Frequency/SPAM
- Each user (regardless of instance) may post up to five (5 🖐) comics a day. This can be any combination of personal comics you have written yourself, or other author's comics. Any comics exceeding five (5 🖐) will be removed.
-
🏴☠️ Internationalization (i18n)
- Non-English posts are welcome. Please tag the post title with the original language, and include an English translation in the body of the post; e.g.,
Sí, por favor [Spanish/Español]
- Non-English posts are welcome. Please tag the post title with the original language, and include an English translation in the body of the post; e.g.,
-
🍿 Moderation
- We are human, just like most everybody else on Lemmy. If you feel a moderation decision was made in error, you are welcome to reach out to anybody on the moderation team for clarification. Keep in mind that moderation decisions may be final.
- When reporting posts and/or comments, quote which rule is being broken, and why you feel it broke the rules.
Banned Artists
The following artists are banned from the community.
- Jago
- Stonetoss
It should be noted that when you make reports, it is your responsibility to provide rational reasoning why something should be removed. Saying it simply breaks community rules is not always good enough.
Web Accessibility
Note: This is not a rule, but a helpful suggestion.
When posting images, you should strive to add alt-text for screen readers to use to describe the image you're posting:
Another helpful thing to do is to provide a transcription of the text in your images, as well as brief descriptions of what's going on. (example)
Web of Links
- !linuxmemes@lemmy.world: "I use Arch btw"
- !memes@lemmy.world: memes (you don't say!)