this post was submitted on 01 Nov 2024
79 points (82.6% liked)

Technology

59069 readers
3573 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
top 19 comments
sorted by: hot top controversial new old
[–] [email protected] 9 points 2 days ago

Sometimes I get phishing sent to protonmail. These guys think that protonmail users will be a good target for their scams? Lmao

[–] [email protected] 96 points 2 days ago (6 children)

Attacks begin when users are lured into “visiting suspicious websites or click on phishing links that download malicious software onto their computer.”

🤦

[–] [email protected] 5 points 1 day ago

Also:

The threat affects all email platforms providing web logins, albeit Gmail, Outlook, Yahoo and AOL are by far the largest

This is really just a generic article saying "be careful what you click on"

[–] [email protected] 9 points 2 days ago (1 children)

After reading various news amd stories about phishing, I no longer think anyone is really "too smart to be phished". Not the matter of "If", but "Under what circumstances".

[–] [email protected] 5 points 2 days ago

congrats! you're the first person I've seen actually get what "phishing" means.

every fish can be caught, they react on instinct. same for people and links. they were made to be clicked so we instinctually click them.

[–] [email protected] 3 points 2 days ago

Thank you, I saw Forbes and was immediately suspicious of click bait.

[–] [email protected] 3 points 2 days ago

An old time classic.

[–] [email protected] 15 points 2 days ago (2 children)

As someone who actively defends and trains against these attacks, I still see people downloading and executing suspicious files regularly.

[–] [email protected] 6 points 2 days ago

It's always the same people in my experience. No matter how many times they go through the training it never seems to stick.

[–] [email protected] 0 points 2 days ago (4 children)

Yeah, I dunno what the facepalm is supposed to be about. 99% of the rest of the world has about 1% of the tech knowledge that the average Lemmy user is going to have. These scams are wildly effective, and it's not really a matter of general intelligence as far as who falls victim to them.

[–] [email protected] 7 points 2 days ago (1 children)

Hell I almost got snagged by one recently, and a goodly portion of my last job was dealing with phishing sites all day.

They've gotten good with making things look like a proper email from a business that would be sending that kind of email, and if you're distracted and expecting something you can have at least a moment of 'oh this is probably legitimate'.

The giveaway was, hilariously, a case of using 'please kindly' and 'needful' which uh, aren't something this particular company would have actually used as phraseology in an email, so saved by scammers not realizing that americans at least don't actually use those two phrases in conversation.

[–] [email protected] 1 points 1 day ago

americans at least don't actually use those two phrases in conversation

Well now they’re gonna know!

[–] [email protected] 6 points 2 days ago* (last edited 2 days ago)

You don't need to have advanced technological know-how to know about phishing scams. Practically every company has a boring training course you have to go through at least once a year.

I work in cyber security and they still feel the need to tell us about phishing scams, like we don't know about 100 other scarier things.

[–] [email protected] 12 points 2 days ago

For me, the article makes it seem like there's some new announcement that the FBI has put out about a newly discovered vulnerability. Turns out, the announcement is about vulnerabilities we've known about for a long time.

[–] [email protected] 4 points 2 days ago

Years ago I might have agreed, but with digital technology having become so central to one's daily life I find it hard to excuse those who fail to educate themselves about the very basics.

[–] [email protected] 82 points 2 days ago (1 children)

I was lured into reading a suspicious Forbes article.

[–] [email protected] 19 points 2 days ago* (last edited 2 days ago) (2 children)

Incidentally, we try not to use these sorts of "Forbes contributor" articles on Wikipedia when possible. They're effectively just blogs masquerading under the credibility of Forbes staff's actual journalism.

That said, I don't see anything wrong with this excerpt. This is legitimate attack vector.

[–] [email protected] 6 points 2 days ago

Tying it to big name providers like they have a security hole in the title is clickbait at absolute best.

[–] [email protected] 9 points 2 days ago* (last edited 2 days ago)

It's always being an attack vector. Phishing scams have been the oldest form of fraud from the beginning.

It's basically the same principle that con artists have been using for decades long before the invention of the internet