[HN Gopher] "Appointment" as professor at Harvard was an elabora...
       ___________________________________________________________________
        
       "Appointment" as professor at Harvard was an elaborate phishing
       attack
        
       Author : LordAtlas
       Score  : 177 points
       Date   : 2021-01-16 13:53 UTC (9 hours ago)
        
 (HTM) web link (www.ndtv.com)
 (TXT) w3m dump (www.ndtv.com)
        
       | wgriirwghawigi wrote:
       | Is it possible she made this all up, for (temporary) media
       | attention?
       | 
       | Here she is hijacking an event for aspiring journalists to try
       | and interview Barack Obama, who sees through this and publicly
       | shames her:
       | 
       | https://twitter.com/rose_k01/status/1350053978403291138
       | 
       | There are multiple interviews of her talking about her upcoming
       | appointment, her class structures, here (non-existent) syllabus.
       | 
       | It seems like another possible interpretation of the events is
       | that she made this all up, then blamed it all on a vague
       | "phishing attack" to defuse any responsibility. In the months
       | prior, her career received a boost from all the media attention.
       | Now, she also has some level of additional fame, that while not
       | exactly positive, could help her launch into the next phase of
       | her aspirations
        
       | LordAtlas wrote:
       | Thread by a US-based tenured professor on how hiring works in
       | academia:
       | https://twitter.com/gauravsabnis/status/1350414118986121216
        
       | screye wrote:
       | I do not have much sympathy for her, given my low opinion of
       | English-speaking Indian Media and their faux-elite mannerisms.
       | Certainly some level of Schadenfreude. But, I won't go into that
       | here.
       | 
       | This seems more like a targeted public embarrassment operation
       | than an attempt at identity theft. Objectively, Nidhi made a ton
       | of elementary mistakes that would be inexcusable for a
       | journalist. This includes non-technological mistakes such as not
       | contacting the Dean or prospective collaborators who presumably
       | voted to have her on the faculty. There is an immense amount of
       | hubris on display as well. That being said, the scammers were
       | incredibly sophisticated and committed to the ruse.
       | 
       | Either ways, this sets a bad precedent. The internet allows for
       | sophisticated scams like never seen before. A public
       | embarrassment in the world of twitter can easily end careers.
       | 
       | I hope she finds some quiet in the midst of this public show
       | where she has been made an unwilling jester. She should have
       | handled this in private. Now that it is out on Twitter, trolls
       | will make sure she never forgets what I presume has been
       | incredibly traumatic.
        
         | alisonkisk wrote:
         | She made it public because she had been doing PR telling people
         | she was a Harvard professor.
         | 
         | This "phishing" is suspected to be a cover up for her own fraud
         | getting caught.
        
           | randycupertino wrote:
           | Is there a source on this?
        
       | scarmig wrote:
       | Definitely a targeted, very personal attack, as you can scam an
       | order of magnitude more funds by focusing on the masses instead
       | of making fake interviews, offer packets, etc.
       | 
       | I'd love more details, because there's not much to learn here. I
       | walk away from the article with no idea about novel defensive
       | strategies people need to take and no idea what we as
       | technologists can do to help prevent this in the future.
        
       | MaxBarraclough wrote:
       | It sounds like the scammers did a lot of work, succeeded in their
       | deception, but still didn't end up turning a profit. What was
       | their plan here?
        
         | mlang23 wrote:
         | The one thing the attacker definitely achieved was to reveal
         | that a particular journalist is not very good at an essential
         | part of their job, fact checking.
        
           | mafuy wrote:
           | You may be interested in this:
           | https://www.youtube.com/watch?v=vJG698U2Mvo
        
             | mlang23 wrote:
             | How is this related to a job offer from a department that
             | doesn't exist at all?
             | 
             | And no, it wasn't particularily interesting since I am
             | incapable of falling for optical illusions.
        
         | lagolinguini wrote:
         | Nidhi Razdan gets a lot of hate, particularly from the right in
         | India.
        
         | z3t4 wrote:
         | I was probably a really bad joke by someone who did not like
         | her. I can't see how you could get any financial gain from it.
         | Scammers are usually slick, but very lazy.
        
       | vinni2 wrote:
       | I once got an email from our dean that he needed to see me
       | urgently in his office. I first believed this was true but then
       | this was very unusual to the dean who never communicated with me
       | before to urgently needing me in his office. Once I double
       | checked I realized it was a scam and many of my colleagues also
       | got the same email.
       | 
       | I immediately alerted the dean to warn everyone.
        
         | MeinBlutIstBlau wrote:
         | I figure if it's actually important, they'd personally meet me
         | or call. You don't respond over email hoping an instant
         | response. It's obvious from the start of the email.
        
           | ghaff wrote:
           | Maybe they have your email but not your mobile number? Or
           | they want a written record of when and how they contacted
           | you?
        
             | MeinBlutIstBlau wrote:
             | Depending on what rung you're on in the corporate ladder,
             | if the head of the institution "needed me" immediately, I'm
             | extraordinarily skeptical they do not have a means of
             | contacting me directly. Especially if they have assistants
             | and other immediate VP's. Hell a corporate directory to
             | look up my number...
             | 
             | If a CEO is gonna want me fired because I'm being skeptical
             | of the veracity of an email, I wouldn't want to work at
             | such a place.
        
               | ghaff wrote:
               | I guess it depends on the nature of the request. I got an
               | email from our CEO a few weeks ago asking for my number
               | to talk about something and I work for a 10K+ person
               | company. (I also know him pretty well and I was pretty
               | sure what this was in reference to.) A lot of execs don't
               | have a problem with reaching out to people directly. Now,
               | if he sent me an email asking me to go to some sketchy
               | website or complete some financial transaction for him
               | that would be something else.
        
       | jccalhoun wrote:
       | If this is legit, this is an insane amount of work to get
       | someone's money. I add "if this is legit" because it does seem so
       | unbelievable that someone would fake a 90 minute interview with
       | someone. This leads me to believe it was personal because a
       | scammer could have scammed a lot of other people in the amount of
       | time and energy they put into scamming this one person.
        
         | nullc wrote:
         | People make prank phone calls that require a lot more work than
         | a 90 minute phone interview.
        
       | Cyclone_ wrote:
       | It would be more helpful if she uploaded screenshots of the
       | emails, including the sending address, and pictures of the
       | letterhead. Assuming she's telling the truth about everything
       | this would be by far the most elaborate phishing attack I've ever
       | seen.
        
         | patja wrote:
         | She is remarkably circumspect about these details. Lots of
         | references to people being allegedly from Harvard or appearing
         | to be from Harvard. It does feel disingenuous to put that out
         | there and not provide a single example.
        
       | itg wrote:
       | According the the founder of Nieman Lab at Harvard, Harvard has
       | no school of journalism, no department of journalism, and no
       | professors of journalism. See:
       | https://twitter.com/jbenton/status/1350059632782356481
       | 
       | I find it hard to believe a journalist with 21 years of
       | experience wasn't aware of this. When someone reaches out to me
       | regarding a new job opportunity, I always do some basic research.
        
         | [deleted]
        
         | aeoleonn wrote:
         | I agree.
         | 
         | I also wonder what degree of ego played into this.
         | 
         | Who does Harvard contact out of the blue? If they contacted me
         | out of the blue by email my first thought would be "Why would
         | they contact me-- who am I? What have I accomplished that I
         | would be on the radar that people are talking about me at
         | Harvard to the point where I am invited to interview?"
         | 
         | To me, that would be phishy-- Unless I was some award winning,
         | well-published, and/or well-credentialed journalist.
         | 
         | - Looking on Amazon, I see 1 book by this author: "Left, Right
         | and Centre: The Idea of India". I also see a blank LinkedIn
         | page, which mentions she lives in India.
         | 
         | - On Wikipedia, I see she has " done documentaries from
         | Pakistan-administered Kashmir, Tibet and the United Kingdom
         | after the train bombings." and "has been the diplomatic
         | correspondent of NDTV 24x7, which is an English language
         | television channel that carries news and current affairs in
         | India, owned by New Delhi Television Ltd network.":
         | https://en.wikipedia.org/wiki/Nidhi_Razdan
         | 
         | Those aren't trivial accomplishments. But I don't know that
         | they represent the pinnacle of journalistic achievement to the
         | degree that Harvard would reach out, out of the blue.
        
           | kshacker wrote:
           | Sometimes it is connectedness. See
           | 
           | https://www.youtube.com/watch?v=SzCcVGbO9rw - Interview with
           | Raghuram Rajan, who was the Governor of Reserve bank of
           | India, was chief economist of IMF, and now a professor in US
           | 
           | https://www.youtube.com/watch?v=p1qS4gdutso - Interview with
           | a maverick political consultant, kinda like Frank Luntz of
           | India
           | 
           | https://www.youtube.com/watch?v=n6lolKKm2LU - Interview with
           | Saudia Arabia foreign minister
           | 
           | I am sure I can find more examples, but the point is that
           | during a 21 year career, of which a few years as a prime time
           | host, you build a lot of network, you get a lot of local
           | awards, that when a US school comes fawning, it may be a
           | small surprise, but you take it in the stride.
        
             | e15ctr0n wrote:
             | > _Raghuram Rajan, who was the Governor of Reserve bank of
             | India, was chief economist of IMF, and now a professor in
             | US_
             | 
             | Raghuram Rajan has been a professor at the University of
             | Chicago since 1997 except for a 3 year period from
             | 2003-2006 when he served at the IMF. He was given a "public
             | service" sabbatical from the University of Chicago to serve
             | at the RBI.
             | 
             | https://www.chicagobooth.edu/-/media/faculty/raghuram-
             | rajan/...
        
         | joshuaissac wrote:
         | From the article:
         | 
         | > Contrary to what many are tweeting, Harvard has a school
         | called the Extension School offering a Journalism Degree
         | Programme[1]. The actual programme is called the Master of
         | Liberal Arts, Journalism degree.
         | 
         | 1. https://www.extension.harvard.edu/academics/graduate-
         | degrees...
        
       | tinyhouse wrote:
       | One suggestion to people is to not follow any links in emails and
       | looking up things instead. For example, if you get an email to
       | sign up for something, try to find that page yourself by googling
       | it. If you get an email from someone at Harvard, try to find that
       | person on the Harvard website to verify the email and everything
       | else. But again, don't do it by following links in the email.
       | Google/Bing/DDG is your friend.
        
       | vinni2 wrote:
       | Can't believe how confident must be. Harvard headhunted her
       | without even applying for the job? She must be so cocky to fall
       | for it.
        
         | bob33212 wrote:
         | Most phishing scams required the target to have an emotional
         | reaction that clouds their judgement. For example, if you get
         | an email saying that your credit card was charged in another
         | state, if you are worried about your finances you may panic and
         | click on the button to login and deny the charges.
        
         | rm445 wrote:
         | > I was invited to speak at an event (...) One of the apparent
         | organisers of this event contacted me separately to say there
         | was a vacancy for a teaching position and would I be interested
         | (...) I submitted my CV (...) A few weeks later I was
         | "interviewed"
         | 
         | This sounds exactly like the kind of job opportunity that's
         | meant to come about by networking, getting your name out there,
         | public speaking and so on. We are often told that this is how
         | the best jobs are found.
        
           | ghaff wrote:
           | Yes, up to that point it all seems very plausible whatever
           | the victim-blamers on this thread think. Down the road,
           | should alarm bells have started going off? Probably. But
           | especially in the context of COVID-19, it's not hard to
           | imagine those bells being suppressed in the excitement of a
           | new opportunity etc.
        
         | feral wrote:
         | That is a bad sort of victim blaming.
         | 
         | I hope you wouldn't apply that logic to victims of other non-
         | online crimes.
         | 
         | Anyway, separately, she addresses that in her article,
         | convincingly I thought. Plus she's brave and helping others to
         | write about this (which victim blaming doesn't encourage).
        
           | vinni2 wrote:
           | I would expect my aunt who thinks everything on WhatsApp is
           | true to fall for it. She is a professional journalist with
           | lots of experience as a fact checker. I am sorry she fell for
           | it but someone with her education level and awareness I
           | expected more.
        
           | namanaggarwal wrote:
           | My only point is that she is a journalist working for a
           | reputable news agency for 21 years. Her job was to fact check
           | everything. This means that a lot of things she told in the
           | media before should be taken with a pinch of salt.
        
             | minot wrote:
             | Not just her. All of journalism.
             | 
             | http://www.paulgraham.com/submarine.html
        
         | cowpig wrote:
         | What a strange reaction to this story.
        
           | hfkldjsjfkdj wrote:
           | Can't anyone say anything negative even if it makes sense?
        
             | ryder9 wrote:
             | ah yes the "my opinion is immune to criticism" response
        
         | nip180 wrote:
         | I had a similar thought: I would be more and more suspicious
         | the longer I didn't get an email from an @harvard.edu email.
        
           | FreakyT wrote:
           | The article states that all the emails appeared to be from
           | official Harvard email addresses.
           | 
           | At some universities, it's possible to create email aliases
           | at your .edu domain, so it's possible that the scammer had
           | access to one or more convincing email addresses.
        
             | nip180 wrote:
             | That greatly increases the level of sophistication.
             | 
             | The article doesn't say that the emails received were
             | "@harvard.edu" only that they appeared to be valid Harvard
             | ids. That means she made a judgement call that the email
             | were legitimate, but it doesn't give very many technical
             | details on what she judged that call on.
        
               | InitialLastName wrote:
               | This makes me assume that the bits she's most embarrassed
               | about (a fact-checker should be able to find out what the
               | valid Harvard email domains are) are the one she glossed
               | over.
        
               | nip180 wrote:
               | I don't think this article was written for a technical
               | audience so it's not surprising that it's light on
               | technical details.
        
       | namanaggarwal wrote:
       | If this is all true, This was a very personal attack. This
       | doesn't seem to be for financial gains but personal vendetta.
       | 
       | Putting that aside, she should be equally blamed for falling for
       | it despite being a fact checker for 21 years and also attending
       | seminars, advisory meetings, talks and interviews as "Harvard
       | Professor" without even going to a lecture hall once.
        
         | alisonkisk wrote:
         | No lecture halls in covid, but virtual lectures.
        
       | Cyclone_ wrote:
       | She mentioned she was interviewed online. Was it a video
       | interview or someone IMing questions? A non video interview would
       | have been a red flag to me.
        
       | bawana wrote:
       | so does mean that linked in is now a useful collection of
       | targets?
        
       | rileytg wrote:
       | Unless harvard's email severs were breached, this seems like a
       | case of user error... Harvard.edu has SPF headers which should be
       | enough to detect fake emails right away. If i'm not mistaken
       | you'd have a really tough time spoofing those emails.
        
       | neya wrote:
       | The last line - "(Nidhi Razdan is former Executive Editor,
       | NDTV.)"
       | 
       | That's their classic way of burning her for burning them.
       | 
       | Having said that, I learnt the same lesson as well a few years
       | ago. Never quit your current unless you're 101% sure your next
       | job is waiting for you and all the due process is taken care of.
        
       | aeoleonn wrote:
       | TLDR: *It's not very useful to have an interpretation by a person
       | who mis-interpreted a situation, without concrete real-world
       | examples of what they actually interpreted: screenshots of
       | conversations & email addresses/other contact info (at least
       | domains such as @something.edu) , so I can at least say "Yeah,
       | this was obviously phishing" or "wow, this phisher was really
       | incognito".*
       | 
       | I'm interested in seeing the email address domain of the person
       | who phished this author. And other specific details about the
       | conversation-- such as screenshots and other evidence.
       | 
       | - "what appeared to be an official Harvard email ID" Did the
       | phisher have a @harvard.edu sort of email address or not? I don't
       | care about "what appeared to be" (i.e. insinuating the author
       | interpreted the account to be official.) I want to know what the
       | actual domain of the email address was -- not that in the
       | author's opinion it seemed to not be fake.
       | 
       | - I know some professors have their own websites & use their own
       | custom domains-- still, I'd see this as phishy unless it
       | specifically came from a @harvard.edu account. And even then, the
       | phisher could still have somehow accessed an available account.
       | But, then I'd simply try to find their faculty page. Also, I
       | would expect other people or gorup-email-accounts in HR to be
       | CCed on the emails, not just some individual contacting me.
       | 
       | To be honest, I am surprised this author does not provide
       | concrete details. She tells how things happened, and what steps
       | she took. But provides no screenshots of her conversations, no
       | specific details about the online personas of the phisher.
        
         | JeremyNT wrote:
         | There's something about this story that feels... incomplete to
         | me.
         | 
         | As the victim here - and as a journalist no less - it's in her
         | own interest to present the attack as being incredibly
         | sophisticated so as not to appear naive for being deceived. In
         | reality, perhaps the attack was not as sophisticated as her
         | narrative suggests.
         | 
         | Like you, I'd appreciate some more details.
        
           | lbblack wrote:
           | Wholeheartedly agreed...
        
         | Debug_Overload wrote:
         | Also, the term "sophisticated" is almost meaningless here, and
         | that's usually the case when talking about these kinds of
         | issues. Pretty straightforward Nigerian prince style scam is
         | now "sophisticated" phishing attack.
         | 
         | We already had enough issues in infosec with companies claiming
         | they're all attacked by "APT" and "state-sponsored actor". It
         | just seems an easy way to dodge embarrassment and looking
         | silly.
         | 
         | Of course, there are real cases where the person/company may
         | actually be a victim of a sophisticated phishing attack (or
         | APT/state-sponsored attack, etc) but the terms lose their
         | weight when they are being thrown around like this.
        
         | spoonjim wrote:
         | It's already an embarrassing situation to share. 99% of people
         | would not share it. The screenshots might be even harder to
         | share because the signs seem so obvious in retrospect. I agree
         | that more would be valuable but understand why we may never get
         | it.
        
           | durovo wrote:
           | I would expect a journalist to share this information. Many
           | journalists don't shy away from sharing the details when they
           | are reporting a story on someone else.
        
           | aeoleonn wrote:
           | I suspect that's exactly why they did not provide specific
           | details. Which for me, negates the value of the article.
           | 
           | In which case-- this article is more of a "Don't get phished.
           | But I won't show you how not to get phished and what it looks
           | like when you're getting phished."
        
             | spoonjim wrote:
             | The article has some value, which is to make people aware
             | of the fact that this happens, and happens in highly
             | bespoke ways to powerful/influential people. It's in all of
             | society's interest that powerful people don't get phished
             | (imagine this journalist getting phished, compromising
             | photographs being stolen, and then blackmailed to say "talk
             | positively about this political candidate and ensure they
             | win or we will leak these photos." Not at all far fetched.
        
         | poplan wrote:
         | harvard.edu doesn't have a dmarc policy so it can be spoofed.
         | 
         | edit: nevermind I've read the other replies and it's not that
         | easy
        
         | FlyingSnake wrote:
         | > It's not very useful to have an interpretation by a person
         | who mis-interpreted a situation, without concrete real-world
         | examples of what they actually interpreted ...
         | 
         | I second you. This being the Hacker news I'm really interested
         | in how the phishing worked and the postmortem of the scam. This
         | is a golden opportunity to learn about such high profile
         | attempts, but no one's talking about it. It's sad to see that
         | neither the author, nor her detractors are making any attempt
         | to analyze the situation rationally.
        
       | mensetmanusman wrote:
       | A few weeks ago I was in the next room washing dishes overhearing
       | my dad say he just got an alert of missing funds from his bank
       | account.
       | 
       | I asked him about it 10 minutes later and was shocked he had
       | submitted all his account information from a text alert.
       | 
       | "You do realize you just gave all your account information to a
       | scammer in a phishing attack I hope."
       | 
       | Thankfully he was able to change account information within
       | minutes and no funds were lost.
       | 
       | Moral: check in with your parents, people around the world are
       | trying to scam them weekly.
        
       | sulam wrote:
       | This exact situation occurred a couple years ago to some people
       | in the US. I don't know their names, and I didn't investigate the
       | situation internally, so I don't know just how smart the phishers
       | were vs their victims. What I do know is that I got a call from
       | the front desk people at our Boston office that said someone is
       | here for their first day of work and we have no record of them
       | being hired. Did I know anything about this? I didn't. After some
       | investigation it was revealed to be an identity theft scam, and
       | within a week several other people were also found to be a victim
       | of the same scam.
       | 
       | Before you judge too harshly, keep in mind that often the people
       | affected by this often aren't very technical, don't know what to
       | look for when it comes to phishing, and are just doing what comes
       | naturally in the situation. The scammers in this case are
       | obviously at least somewhat technical and have a huge advantage
       | in terms of being able to scattershot communicate with a very
       | large group of people (potentially millions, although more likely
       | 10's of thousands in the case I describe). Also, while I'm sure
       | no one reading this has ever been phished ( _cough_ ), it has
       | been _repeatedly_ found that phishing is effective, even for
       | highly technical audiences. When it comes to recruiting, it is
       | all too plausible that the person you're interacting with doesn't
       | work for the company you're "interviewing" with, and many
       | recruiters start a conversation not even revealing who they
       | recruit for. In fact, there are recruiting agencies that may as
       | well be phishing organizations, because they will claim to have a
       | role simply to get your resume and then, once they have your
       | information, will start shopping it to companies in an attempt to
       | get paid.
       | 
       | In short, I have a ton of sympathy for people affected by this,
       | and think the assholes who do this kind of thing are pretty much
       | evil.
        
       | setum wrote:
       | this was all over Twitter in India yesterday when she first
       | tweeted about it. People where making fun of her and NDTV (her
       | previous employer) which I thought was somewhat deserved
       | considering they (she and her NDTV colleagues) pretend to be
       | righteous, above all others, calling others with names like 'Fake
       | Media', graduate of WhatsApp University, etc. They claim
       | themselves to be true journalists and guardians of truth. This
       | must be a reality check and sobering moment. (fun-fact: NDTV also
       | runs a program named 'Reality Check')
       | 
       | edit: grammatical
        
         | lagolinguini wrote:
         | They are certainly biased to the left. But they are definitely
         | better than any of the alternatives in India... Have your seen
         | what kind of garbage is reported by Indian news channels? There
         | was the entire bullshit non issue about Rhea Chakroborty and
         | the SSR suicide that was extremely disappointing to watch. And
         | you can in no way defend the kind of nonsense that is spread on
         | WhatsApp groups in India.
        
           | setum wrote:
           | You are all correct, It still doesn't justify self certifying
           | as righteous. One's greatness is for others to evaluate, not
           | they themselves.
        
             | mav3rick wrote:
             | You perceive them as righteous. They have never said it
             | themselves.
        
         | mav3rick wrote:
         | I don't get it ? So they call out other media channels. So
         | their journalists deserve shit ?
         | 
         | Twitter is filled with BJP IT Cell bots and miscreants. I
         | wouldn't expect less.
         | 
         | Can you say with a straight face that Republic TV is not biased
         | ? Or India TV ?
        
           | LordAtlas wrote:
           | Republic TV and Zee News are literally owned by BJP members
           | of parliament.
        
       | abhishekjha wrote:
       | Surpringly similar to the story a senior Journalist at NYT got
       | scammed by a guy pretending to be a terrorist :
       | 
       | https://www.npr.org/2020/12/18/944594193/new-york-times-retr...
       | 
       | What a roller coaster of emotion that Podcast was!
        
       | LordAtlas wrote:
       | While it's clear that this was a sophisticated and personally-
       | targeted scam, I feel the blog post would have been more useful
       | with information about which Harvard email addresses were used to
       | communicate with her, and perhaps some screenshots. Were they
       | actual harvard.edu email addresses, which means somebody had
       | access to an official address for replying to mails from her?
       | (That makes the scam deeper and involves US authorities.) Or was
       | it something like harvardhr@gmail.com? Which means she should not
       | have fallen for it.
       | 
       | I just saw this tweet from someone senior at her former employer
       | about how she uploaded a reference letter to an official-looking
       | site but again, no screenshot or URL referenced.
       | 
       | https://twitter.com/soniandtv/status/1350415332599480324
        
         | quesera wrote:
         | She writes: "what appeared to be an official Harvard email ID".
         | No further description is given.
         | 
         | This could be something as simple as "someone@harvard-
         | faculty.org".
         | 
         | For the recipient, this is effectively indistinguishable from a
         | legit address. Not just because people are unsophisticated, but
         | because many orgs really do use this sort of ancillary domain
         | for conducting real business.
         | 
         | I've seen Fortune 50 corps, hospitals, and banks make this
         | mistake.
         | 
         | Even if Harvard does not, has not, and will not ever make this
         | mistake, an outsider would not be surprised to see it.
        
           | psychometry wrote:
           | No, anyone at Harvard uses a @*.harvard.edu address.
        
             | quesera wrote:
             | Yes, of course.
             | 
             | But the senders were not _at_ Harvard, so it 's very likely
             | that they did not do so. And they would not need to do so,
             | for their purpose.
        
             | notahacker wrote:
             | Sure, but you wouldn't expect the average person who
             | doesn't have a deep interest in tech and lives in a country
             | where the .edu suffix isn't even a thing to know this. I
             | doubt even most hackers here validate the ownership of the
             | URLs every time a recruiter reaches out with a plausible-
             | sounding personally-targeted opportunity (as opposed to a
             | 'dear customer please sign in here' mass-mailing)
        
         | [deleted]
        
         | orange_tee wrote:
         | Email addresses can be spoofed.
         | 
         | https://en.wikipedia.org/wiki/Email_spoofing
        
           | noname120 wrote:
           | No. [1][2][3]
           | 
           | [1] https://en.wikipedia.org/wiki/Sender_Policy_Framework
           | 
           | [2] https://en.wikipedia.org/wiki/DMARC
           | 
           | [3] https://en.wikipedia.org/wiki/DomainKeys_Identified_Mail
        
             | lkurtz wrote:
             | Only if they're used. There are no DMARC records in place
             | for harvard.edu or subdomains, which is kinda shocking.
        
               | oefrha wrote:
               | The lack of DMARC records, even if it could facilitate
               | spoofing, won't magically make reply emails addressed at
               | a valid @harvard.edu address land in a spoofer's inbox. A
               | different Reply-To address is possible but then you can't
               | claim a lack of warning signal. There's something else
               | going on.
        
           | willmeyers wrote:
           | I'm guessing the scammers did something like
           | person@hr.harvard.edu.obscuredomain.tld
           | 
           | They've gotten pretty good at crafting domains this way.
        
             | foolmeonce wrote:
             | No idea on harvard, but alumni are often allowed to keep
             | their addresses and for every alum that still takes full
             | advantage of that, ten may not notice anything. Similarly,
             | old group addresses may mostly go into the void.
             | 
             | I suspect it is quite easy to make it look like many people
             | from an institution are in a thread and a passive
             | participant is an email address from a 3rd party job
             | portal.
        
               | oefrha wrote:
               | I don't know a single reputable U.S. institution that
               | doesn't replace your @university.edu address with
               | @alum[ni].university.edu after you leave. I've been
               | affiliated with two and have friends all over the place,
               | including Harvard.
        
               | UncleMeat wrote:
               | My alma mater (one of the highest ranked state schools)
               | grants your email for live and does not update it.
        
               | gnicholas wrote:
               | For decades, Harvard issued alumni email addresses of
               | *@post.harvard.edu. [1] Given that "post" could either
               | refer to "after" or "postal", I would imagine someone who
               | didn't know many people at Harvard might think that a
               | post.harvard.edu email address is a normal thing for
               | current employees.
               | 
               | 1: https://alumni.harvard.edu/help/email-forwarding
        
               | foolmeonce wrote:
               | MIT is right next to Harvard..
               | 
               | *Might your own cultural expectations open you to attacks
               | from a place with MIT's (recent if not current) network
               | culture?
        
               | oefrha wrote:
               | MIT uses @alum.mit.edu. I don't think I know former
               | employees there but at least former students I know lose
               | mit.edu addresses, a fact also easily confirmed with a
               | Google search. So, your point being?
               | 
               | Edit: You added
               | 
               | > *Might your own cultural expectations open you to
               | attacks from a place with MIT's (recent if not current)
               | network culture?
               | 
               | after my reply. I'm not sure how it is relevant to your
               | claim that "alumni are often allowed to keep their
               | addresses". In fact the question doesn't make any sense
               | to me; I'm not gonna accept an MIT job offer from an
               | alum.mit.edu address (or more relevant to me,
               | alumni.stanford.edu/alumni.princeton.edu), regardless of
               | network culture.
               | 
               | Edit 2: Reread your question and realized you were
               | implying that MIT "recently" allowed alumni to keep
               | @mit.edu addresses. Well, you'll need to show some proof.
        
               | foolmeonce wrote:
               | Your expectations are very specific to what you know
               | about US schools right now. MIT would let a machine
               | receive email, many institutions would forward email to a
               | users alum address, etc.
               | 
               | This approach to identifying phishing is ultimately
               | insufficient.
        
           | LordAtlas wrote:
           | Well, of course, SMTP headers are trivial to spoof, but for
           | this scam to work, the scammer would need actual POP/IMAP
           | access to the harvard.edu account to receive her replies and
           | respond to those, which is not as trivial.
        
         | tinyhouse wrote:
         | Exactly. No concrete details and examples so safe to assume the
         | emails were not actual @harvard.edu ones. But I blame it on
         | organizations and esp universities. Each school/lab get their
         | own prefix which makes it harder for people to spot a fake
         | address.
        
           | nullc wrote:
           | > to assume the emails were not actual @harvard.edu ones
           | 
           | If that is so... so what? Plenty of organizations use
           | different domains. Fidelity staff uses "frm.com"-- as an
           | example-- while most customers know them as fidelity.com.
        
       | mensetmanusman wrote:
       | Imagine a future where an army of GTP-4 agents await mere mortals
       | in cyberspace.
       | 
       | If they are all programmed to extract funds through conversation,
       | how will we prevent this?
        
       | cowpig wrote:
       | This scam sounds frighteningly sophisticated. I really feel bad
       | for people who get caught up in things like this.
       | 
       | To get strung along for over a year, throwing away that much time
       | and energy, must feel devastating.
        
         | runawaybottle wrote:
         | It's not sophisticated, it preys on very vulnerable and
         | sheltered people.
         | 
         | Like, you have to know Harvard is not going to just call you up
         | one day and decide to fly you over to America lol. Really a
         | problem with delusions amongst many of us.
        
           | ceejayoz wrote:
           | You really should consider reading the article.
        
             | runawaybottle wrote:
             | I did.
        
       | wtmt wrote:
       | Regardless of which side of the political spectrum one is or what
       | qualifications one has or what terrible deeds one has done (or
       | alleged to have done), the fact is that phishing attacks aren't
       | very easy to avoid (you'd be fooling yourself if you believe
       | you'd never fall for one). You can ace all the phishing email
       | tests your company routinely sends you and still fall for a more
       | sophisticated attack or fall for something that in retrospect
       | seems stupid because you were preoccupied or stressed or had
       | other serious things going on in life.
       | 
       | Victim blaming and questioning how she could believe that she's
       | qualified for some position is the wrong thing to talk about, and
       | is also disgusting in certain ways.
       | 
       | What would be better, at least in a tech focused community, is to
       | find out more details on how this happened and where the gaps
       | (that are obvious in hindsight) are. I wish someone like Brian
       | Krebs (of Krebs on Security) could get more information on this
       | and do a detailed write up. That would be more insightful and
       | useful to everyone than rants about the victim.
        
         | gumby wrote:
         | A clever element of this is the cross-cultural nature: the
         | Harvard name internationally known, yet someone not in that
         | milieu would not be able to detect a number of "red flag"
         | anomalies. In fact if the author was phished by someone in
         | India (a likely case) then the perpetrator could make a
         | cultural error that would be undetectable by the victim as they
         | might share the same set of assumptions.
         | 
         | I say "cross cultural" but by that I also mean "cross domain"
         | which is how financial scams can entrap victims who aren't
         | familiar with the details of financial jargon.
         | 
         | It's also why people can believe conspiracy theories which are
         | absurd to someone familiar with the domain.
        
         | ghaff wrote:
         | Thank you for posting that. There are obviously way too many
         | people here (and elsewhere) who think _they 're_ way too smart
         | to fall for phishing and other forms of scams unlike "stupid"
         | grandmas, journalists, etc.
         | 
         | The reality is that we all do things when we're distracted and
         | not really paying attention. Or we get caught up in the
         | excitement of something and we don't stand back and ask
         | ourselves whether it really makes sense. And anyone who thinks
         | otherwise is just arrogant and misguided.
        
           | networkimprov wrote:
           | This. And the effectiveness of targeted phishing is why we
           | must replace SMTP-based email, and eventually _block SMTP on
           | public networks_. It isn 't suited to the 21st Century
           | Internet.
           | 
           | Hence, the mnm project[1] (open source client & server) and
           | TMTP[2][3].
           | 
           | [1] https://mnmnotmail.org
           | 
           | [2]
           | https://github.com/networkimprov/mnm/blob/master/Protocol.md
           | 
           | [3] https://mnmnotmail.org/rationale.html
        
           | dissidents wrote:
           | It may well be true that phishing scams can be easy to fall
           | for, but it is not relevant to this story. Razdan tweeted
           | that she was joining the Harvard's Faculty of Arts & Sciences
           | as an Associate Professor. Regardless of how convincing the
           | phishing attempt was, this is incredibly naive; Razdan does
           | not have a PhD or any publications and Harvard's FAS does not
           | have any professors in journalism.
           | 
           | Edit: https://twitter.com/ruchirsharma_1/status/1350067266289
           | 85651...
           | 
           | It seems that this may not even have been a phishing attempt.
        
             | [deleted]
        
             | pmiller2 wrote:
             | Not to mention that universities typically don't hire
             | people at the associate professor level. The first rank is
             | called "assistant professor," followed by "associate
             | professor," and then "full professor." Associate and full
             | are tenured ranks, which is why there isn't much hiring at
             | that level.
             | 
             | Also, one would expect any open position at a US university
             | to be advertised, most likely in _The Chronicle of Higher
             | Education_. This is something perhaps only someone who 's
             | got a little familiarity with the academic job market may
             | know, so, I suppose one could be forgiven for not knowing
             | it, but I would assume that one would at least google for
             | open positions at Harvard to find out if it really exists.
             | 
             | That said, naive or not, I also don't think victim blaming
             | is a productive thing to do here. All it does is discourage
             | people from speaking out about their experiences, which
             | means we can't learn from them. It may also discourage
             | people from seeking help when they think they might be
             | getting phished.
        
               | LordAtlas wrote:
               | This thread says people from industry are sometimes hired
               | without needing Ph.Ds - https://twitter.com/gauravsabnis/
               | status/1350414118986121216
        
               | pmiller2 wrote:
               | Ok? I never said anything about PhDs. What I said was
               | that people typically aren't hired in at the associate
               | level. Those that are would typically be professors who
               | have tenure at another institution, meaning that they're
               | _already at_ the associate level or higher. People who
               | are denied tenure at their current institution and want
               | to continue in academia would apply to an assistant
               | professor job and negotiate a shortened tenure clock,
               | meaning that they would be assessed for tenure in fewer
               | than the standard 6 years that a brand new, never held a
               | professorship of any type assistant professor would have.
               | 
               | Again, this is a lot of esoterica about the academic job
               | market that not many people outside of those circles is
               | going to know, so I don't blame anyone for not knowing
               | it.
        
               | dissidents wrote:
               | As others have pointed out on Twitter, I am not sure who
               | is the victim here; Nidhi Razdan apparently had multiple
               | speaking engagements where she was introduced as Harvard
               | faculty:
               | 
               | Example: https://pbs.twimg.com/media/ErxnAc5XEAEkro3?form
               | at=jpg&name=...
        
               | CyberRabbi wrote:
               | What you are suggesting here makes this already
               | interesting story even more interesting. Perhaps there
               | are holes in her story but if she really knowingly faked
               | the whole thing, why would she resign from her job?
        
               | ghaff wrote:
               | Because she was maybe resigned?
               | 
               | It's possible there's an innocent explanation but Occam's
               | Razor does suggest she just made up her Associate
               | Professor at Harvard title and, when called out for it,
               | concocted a story about it really being Harvard Extension
               | School and phishing. Which was vaguely plausible so long
               | as you don't think too deeply about it and ignore that,
               | if this were the case, the initial Twitter post was
               | deceptive.
        
               | CyberRabbi wrote:
               | By "resigned" I am assuming you mean she was fired. If
               | she were fired why would her previous employer allow her
               | to use their website to publish this story?
        
               | ghaff wrote:
               | Who knows? Maybe the Occam's Razor conclusion isn't in
               | fact the right one. Maybe the publication thinks it saves
               | them face as well as her. (Journalists who lie look bad
               | for news publications even if they're fired.)
        
               | pmiller2 wrote:
               | I don't understand. Are you saying people are claiming
               | she made the whole thing up and was just going around
               | saying she was an associate professor at Harvard?
        
               | alisonkisk wrote:
               | Yes. That's what the Twitter thread shows.
        
             | ghaff wrote:
             | As I responded elsewhere, that's not what she wrote in the
             | post that people are responding to. I would agree that if
             | it were the case that she was offered a full faculty
             | position after a 90 minute remote interview, that wouldn't
             | pass the sniff test. But that's not what she claims in this
             | post. It's very plausible that a working journalist would
             | teach at Harvard Extension School. Though it's at least a
             | bit of a stretch that Harvard would relocate someone from
             | India to do so. And it does seem that her story is
             | changing.
             | 
             | ADDED: And, yes, there seem to be different claims on
             | twitter than what is stated in this post.
        
               | dissidents wrote:
               | "But that's not what she claims in her post."
               | 
               | I am not sure how much more clear I can be with you.
               | Nidhi Razdan claimed on Twitter that she was joining the
               | Harvard Faculty of Arts and Sciences as an Associate
               | Professor. The Harvard Extension School has absolutely
               | nothing to do with any of this. Here is the original
               | tweet:
               | 
               | https://twitter.com/Nidhi/status/1271705895437651968
        
               | boomboomsubban wrote:
               | The Harvard Extension School is a program of the Harvard
               | Division of Continuing Education, which is part of the
               | Harvard Faculty of Arts and Sciences.
        
               | dissidents wrote:
               | Again, this is irrelevant. I find it hard to believe how
               | often I have to repeat this. The Harvard Extension School
               | does not hire tenured professors. You do not become a
               | tenured faculty, let alone an associate professor, at
               | Harvard's FAS if you have no research background. The
               | story should fail a minimal scrutiny test from a
               | layperson, let alone a journalist with more than 20 years
               | of experience. This just doesn't add up.
        
               | boomboomsubban wrote:
               | Why do you repeatedly say "I can't believe I have to
               | repeat this" and then say something you haven't mentioned
               | in this thread?
               | 
               | What an "associate professor" is isn't common knowledge,
               | even for a journalist. It both means something different
               | in Commonwealth countries and the definition of
               | "associate" is "entry level" which doesn't fit either
               | version of an associate professor.
        
               | Aeolun wrote:
               | > You do not become a tenured faculty, let alone an
               | associate professor, at Harvard's FAS if you have no
               | research background.
               | 
               | This is _not_ something someone without a research
               | background would know.
        
               | ghaff wrote:
               | I'd absolutely expect an experienced American journalist
               | to have a pretty good idea of how academia operates in
               | the US. I do and I don't have a research background. I
               | have no idea though how things operate in India.
        
               | ghaff wrote:
               | The title is still fishy though even if she (as a
               | journalist!) took some liberties in implying she was a
               | professor at Harvard University (and what that implies)
               | even though she wasn't. Just as if I said I graduated
               | from Harvard when I got a degree of some sort from HES,
               | that's clearly misleading. If you look through the
               | faculty directory of HES, it doesn't look as if HES
               | generally gives titles; most of the titles given are the
               | faculty's positions at other institutions where
               | applicable. (There are a few Lecturers in Extension.)
        
               | localhost wrote:
               | Which would have made her an adjunct professor, certainly
               | not an _associate_ professor.
        
           | pwillia7 wrote:
           | This reminds me of how if you ask almost anyone if marketing
           | works on them, they'll say no or not the deceptive parts.
           | Yet, logically, marketing must work on most people or Coke
           | wouldn't spend 4 billion dollars a year on it. Feels hubris-y
           | to me. We forget we all have the same equipment.
           | 
           | https://www.investopedia.com/articles/markets/081315/look-
           | co...
        
             | sjs7007 wrote:
             | Idk, it could still be wrong or not as useful as thought
             | of.
             | 
             | https://www.forbes.com/sites/augustinefou/2021/01/02/when-
             | bi... :When Big Brands Stopped Spending On Digital Ads,
             | Nothing Happened. Why?
        
               | pwillia7 wrote:
               | Interesting article. I know the big CPGs have been
               | challenged by digitally native brands like harrys and the
               | shave companies. It's also clearly not true if you're not
               | a globally known brand with a lot of monopolies. I wonder
               | if it holds true in all markets for the big brands. I
               | also wonder if it would open them to more competition
               | from smaller brands over time. Like the other commenter
               | said, hard to name too many non coke/pepsi carbonated
               | beverages.
        
             | CyberRabbi wrote:
             | People always say marketing doesn't work on them until you
             | ask them to name non-Coke carbonated beverages...
        
               | eitland wrote:
               | I'm not sure if I understand you correctly, but at least
               | around here thers RC Crown Cola, Solo, Farris, Pepsi,
               | Pepsi Max, Eplerose, Oscar Sylte Paerebrus, Monster
               | energy, Red Bull, 7-up etc and I don't think I am special
               | at all for knowing them.
               | 
               | In case it matters, a number of these don't advertise, at
               | least not in the same league as coke (multiple national
               | campaigns a year).
        
               | CyberRabbi wrote:
               | > I don't think I am special at all for knowing them.
               | 
               | I would guess that at least 80% of people off the street
               | would only be able to name advertised carbonated
               | beverages. In that case, yes I think you are special.
        
         | mlang23 wrote:
         | I have yet to see a scam which would fool me. And I have seen
         | many already.
         | 
         | All the scam and phishing mails I saw in my whole internet
         | career were somewhere between totally obvious and embarrasingly
         | blunt.
         | 
         | I can't agree with your assessment. If someone is naive, they
         | are at risk. Same applies for overconfidence. These are
         | personality traits which are easily exploited. In real life as
         | well as on the Internet. We cant protect everyone from
         | everything. Neither in healthcare nor in VR.
        
           | quesera wrote:
           | > I have yet to see a scam which would fool me. And I have
           | seen many already.
           | 
           | That's because you have never been targeted. It's that
           | simple.
           | 
           | There is a small segment of society who are: a) savvy, and b)
           | not actively engaged in
           | commerce/business/community/career/friends/family, so _any_
           | solicitation over email is likely suspicious.
           | 
           | Everyone else is at some level of risk. And sometimes it only
           | takes one failure.
        
             | aidenn0 wrote:
             | Even untargeted scams can fool a savvy person by
             | coincidence. I followed my accountant when he switched
             | accounting firms. Within two weeks of that, I got a generic
             | accounting email SharePoint document share. It linked to
             | the actual ms domain and used some redirection trickery to
             | end up on a pixel perfect copy of the office 365 login
             | screen. I only didn't get scammed because my password
             | manager refused to auto fill.
             | 
             | Had the email come after I had learned the name of the new
             | accounting firm, I never would have even clicked on the
             | link.
        
               | ghaff wrote:
               | >Even untargeted scams can fool a savvy person by
               | coincidence.
               | 
               | And you can pick them up 99 times out of 100. But that
               | 100th time, you're tired, rushing to get out the door,
               | etc. and they get you.
               | 
               | I'm definitely more cautious than I was when phishing was
               | just starting to be a big thing. Back then I don't think
               | I ever fell for anything but there was once or twice when
               | I wasn't really thinking and started down the path of
               | providing information.
        
             | mlang23 wrote:
             | Interesting. How do you know that I have never been
             | targeted. Did you ask your crystal ball? Or is it that you
             | just know everything? I am amazed and bow to your skills,
             | great magician.
             | 
             | Also, implying that I am not actively engaged with anything
             | is a pretty personal attack. Reserve your patronising
             | behaviour for your children please.
        
           | fortran77 wrote:
           | I admire her for doing the right thing, and risking
           | embarrassment and shame, by telling the story to make the
           | rest of us hyper-aware.
        
           | notahacker wrote:
           | > I have yet to see a scam which would fool me
           | 
           | If it fooled you well enough you might not have noticed you
           | were scammed.
           | 
           | Scams run from laughably blunt like the Nigerian prince to
           | remarkably close to the real thing, like the callcentre that
           | rang me pretending to sell phone contract upgrades that used
           | exactly the same crap phone sales techniques my actual
           | network used when they (coincidentally) called me a week
           | later, and had a 1-letter different email address with the
           | URL redirecting to the same website
        
           | reddog wrote:
           | > I have yet to see a scam which would fool me
           | 
           | Maybe not but you will. If you live long enough you _will_
           | suffer inevitable cognitive decline until one day you _will_
           | be vulnerable to such a scam. We all will. No amount of good
           | diet, meditation, fish oil and exercise will keep that from
           | happening.
        
             | alisonkisk wrote:
             | mlang23 has commented about being blind, which is a pretty
             | huge filter against Internet scams, which aren't designed
             | for screen readers.
        
               | mlang23 wrote:
               | You pretty much nailed it. I am filtering a lot of stuff
               | because I refuse to use certain modern flashy
               | technologies. Office 365, yeah, go away. Firefox? Only on
               | a dedicated machine if I really need it.
               | 
               | Emacs, SSH, tmux, old fashioned email (text only) and a
               | linux virtual console is all I need to be productive,
               | _fast_ and especially happy.
               | 
               | A big part of what makes these attacks work is the tech
               | stack in use on the recipients side. I recently heard
               | about a Emotet attack, and was told "Well, you know, the
               | problem is that Outlook only shows the name but not the
               | address by default". Oh well, what can you say about
               | that?
        
               | Frondo wrote:
               | If any sizeable portion of internet users were also
               | visually impaired, and on a stack similar to yours, you'd
               | certainly see scams targeted at you.
               | 
               | Good for you for being so far off the map, though, that
               | is a good protective measure.
        
             | mlang23 wrote:
             | We're all gonna die. Some earlier, some later.
        
           | 11thEarlOfMar wrote:
           | One that was successful at my company recently was an e-mail
           | sent to an electrical engineer from the CEO saying that the
           | CEO needed a gift card from Target for an employee birthday,
           | and had forgotten to pick it up. The EE went to Target and
           | bought the card. The instructions including to reply to the
           | e-mail with the card # so the CEO could include the number in
           | the birthday card and not need the actual plastic.
           | 
           | The spoof was believable at first glance. It used the CEOs
           | actual first name and obscured the actual source e-mail
           | address with his company e-mail as the name. What should have
           | given the engineer pause (among other things) was the
           | context. There was no reason that the CEO would ask an
           | engineer to do this task at my company. Nonetheless, the
           | engineer was perhaps overly deferential to the chain of
           | command and the suspicion didn't emerge until he had
           | embarrassed himself.
        
             | Aeolun wrote:
             | Hah, I almost fell for the same thing, but when they asked
             | for 4! $1000 codes! over email! I got a bit suspicious.
             | 
             | Could have probably gotten 4 times $50 out of me though.
        
             | mlang23 wrote:
             | Simple. Either call or reply asking him why he didn't send
             | this mail to the secretary.
             | 
             | If you can't be so direct with your boss, find another job.
        
               | 11thEarlOfMar wrote:
               | In this case, it was his boss's boss's boss (I am his
               | boss's boss). This particular engineer is highly valued
               | at the company, including by me personally. It was at the
               | same time surprising, but paining to see his
               | consternation, and I certainly do hope he doesn't leave
               | us. I'll gladly endure a $100 mistake to have his talents
               | and attitude as an engineer.
        
             | pwillia7 wrote:
             | That's rough. I got a phishing email from my CEO asking
             | about something similar with money and had a brief 'oh
             | shit' chain of command moment before my incredulousness
             | kicked in. I get it.
        
           | spoonjim wrote:
           | No offense, but you're likely a "nobody." So you've only come
           | across the generic scams. This is a famous person. The
           | phishing attempt was designed specifically for her. You don't
           | know if you'd fall for it because 1) nobody would invest that
           | much effort into phishing you, and 2) "we'd like you to come
           | teach at our university" is a plausible thing for her to hear
           | but not you or I.
        
       | unanswered wrote:
       | Whenever I'm changing jobs, I spend at least half my time worried
       | sick that I'm being scammed somehow. Until now, the "rational"
       | part of my mind thought this was very silly, but I think this
       | goes to show that it's a legitimate concern.
       | 
       | The fact of the matter is that when joining a new institution one
       | lacks the contacts and the context to discern normal
       | institutional behavior because it so often deviates from
       | (seemingly) ordinary, sane human behavior even when nothing is
       | wrong. Having autism, no part of my mind is naturally attempting
       | to cover up this discrepancy: it remains jarring until I manage
       | to "manually" reset expectations.
        
         | djrogers wrote:
         | > The fact of the matter is that when joining a new institution
         | one lacks the contacts and the context to discern normal
         | institutional behavior
         | 
         | That was the case for me at a couple of very early jobs in my
         | career, but hasn't been the case for the last couple of
         | decades. New jobs come by way of old colleagues, friends, etc.
         | in such a way that I'm basically never walking in to a
         | completely unknown situation.
         | 
         | If you're not great at relationship maintenance, use something
         | like LinkedIn. Reach out to former coworkers who you worked
         | well with or got along with, and ask about jobs. Odds are very
         | high that they'd like to work with you again, and will get a
         | referral bonus if it happens!
        
           | ghaff wrote:
           | I've gotten out of the blue recruitment calls, but after my
           | first job via on campus recruitment out of grad school, every
           | job (just a few of them) have been directly through people I
           | knew. Except for essentially pro-forma reasons, I've probably
           | never really needed a resume.
        
         | MeinBlutIstBlau wrote:
         | I 100% agree. All the hoops you have to jump through and things
         | you need to enter regarding personal information always makes
         | them feel like a honeypot. Not one moment in initial onboarding
         | process do I feel like I'm legitimitely giving my info to HR
         | but some scammer in god knows where.
        
         | lagolinguini wrote:
         | It's been particularly hard interviewing during the pandemic.
         | In usual times, at least you would visit the office and meet
         | some real people in person. Not saying you can't get scammed in
         | person, but it's definitely harder to impersonate reasonably
         | large organisations like that.
        
           | ghaff wrote:
           | Unless maybe it was somewhere I knew people well, I'd be very
           | hesitant to switch jobs in a situation where I only had
           | communicated virtually--unless I had no choice in the matter.
        
           | xhkkffbf wrote:
           | SPOILER: If you want to see an example of scamming people by
           | sneaking into an office and pretending to work in it, watch
           | "Charade" with Cary Grant and Audrey Hepburn.
        
       | lkurtz wrote:
       | Wow, very surprised to see no DMARC records in place for
       | harvard.edu or their various subdomains. It may be possible that
       | a single DNS record could have prevented this whole madness.
        
       | crowf wrote:
       | > In January 2020, I got an email from an alleged Harvard Human
       | Resources person from what appeared to be an official Harvard
       | email ID,
       | 
       | it would have been interesting if she would have shared exactly
       | what that email address was. Was it hr@harvard.com or maybe
       | hr@harverd.com? I doubt that it was hr@<something>.edu since it
       | is hard to register .edu domains. But if someone did, that would
       | be news to me.
        
         | notahacker wrote:
         | A url containing 'harvard' and redirecting to an actual faculty
         | website is going to convince most people if the communications
         | are plausible. Many large organizations use multiple url forms
         | for emails, especially for quasi-separate divisions like
         | business schools or extension programmes.
         | 
         | A particularly sneaky scammer without access to Harvard
         | mailboxes might register a plausible-sounding domain with an
         | .ac TLD (which resembles the .ac reserved for universities in
         | many national domain systems including the author's, but is
         | actually a freely purchasable domain supposedly associated with
         | Ascension Island)
        
         | alisonkisk wrote:
         | A clever person could hijack an alumni email account
         | username@post.harvard.edu
         | 
         | Note the bad pun Harvard uses: "post"
         | 
         | Or you could get an address (deceptively or via hijack) on an
         | subdomain run by a student group.
        
           | pge wrote:
           | You can't send from a post.harvard.edu email address - it is
           | just a forwarding address for receiving mail.
        
           | ghaff wrote:
           | Yeah. The alumni emails probably follow a pattern. Get a list
           | of alumni and find one who hadn't set up an email forwarding
           | address previously and set up an account.
        
         | netsharc wrote:
         | Maybe something like @harvard-school-of-journalism.com,
         | although that's too wordy. The article mentions "Harvard
         | Extension School", so, it could be some variation of that.
         | 
         | Edit: I tried harvard-extension.school in the browser, it
         | redirected me to http:harvard-education.edu (not https!), which
         | seems to be a clone of extension.harvard.edu . The WHOIS
         | records of harvard-extension.school/.education are pretty new
         | (registered last year), and they're registered on GoDaddy and
         | 1API GmbH respectively. A Germany-based registrar? Would
         | Harvard use them?
        
       | oefrha wrote:
       | This episode makes me wonder: how many times an anonymous source
       | "verified" by a journalist is just someone pretending to use an
       | organization's official email address.
        
         | boomboomsubban wrote:
         | This is why journalists generally try to confirm information
         | before publishing. I wouldn't say it never happens, but there
         | is supposed to be some amount of verifying that wouldn't have
         | been done on a personal job offer.
        
       | nip180 wrote:
       | How do we establish trust in a virtual world? There are a lot of
       | cues in an meatspace social interaction that can trigger a "gut
       | reaction" one way or another on trust. In digital interactions
       | it's significantly easier to be social engineered.
        
         | lagolinguini wrote:
         | Everybody gets a public key certificate, possibly since birth.
         | There needs to be some way of establishing that which keys
         | belong to which person, perhaps via some government registry,
         | and a way to invalidate old/compromised keys. Overkill?
        
           | Aerroon wrote:
           | Kind of like ID cards in Estonia? You have a chip on the card
           | that holds your private key and the government has a list of
           | people and their public keys. Services and other people can
           | check that. You can even sign and encrypt documents with it.
        
             | netsharc wrote:
             | China's ID cards also have chips, and they have to scan
             | them to enter train stations or airports (or the center of
             | the old town in Tibet)...
        
       | JackFr wrote:
       | You get the feeling that this was not phishing scam with the
       | ultimate goal of financial crime. This (to me) smells more like a
       | specific, personal attack on this woman with the intent to
       | humiliate and embarrass her professionally.
        
         | lagolinguini wrote:
         | > personal attack on this woman with the intent to humiliate
         | and embarrass her professionally.
         | 
         | This is exactly what it feels like to me.
        
         | netsharc wrote:
         | Yeah, who would spend the 90 minutes doing a fake interview for
         | a random phishing victim. Even one with questions that are
         | convincing enough to her.
         | 
         | Assuming the scammers are Indian, and the victim would be
         | expecting some Americans interviewing her, I wonder how they
         | scammers got some Americans to join in the scam. Hire some
         | American actors and tell them it's for a prank TV show maybe?
        
         | kshacker wrote:
         | I did not want to speculate, but when I think of someone
         | wanting to humiliate and embarrass, the first name that came to
         | mind was "IT cell". But one of my friends said, the "IT cell"
         | usually sends rape threats, they are not so sophisticated.
         | 
         | You either know about the "IT cell" or please google it ... all
         | the links on it are non-authoritative.
        
         | jerome-jh wrote:
         | Definitely. Looks like the goal was to make her leave her
         | position at NDTV.
        
       | nullc wrote:
       | What the heck is going on with the victim blaming -- both here
       | and by Harvard staff on twitter? It's gross.
       | 
       | I'm sure this was an opportunity of a life time-- not enough of
       | one to come off as totally implausible, but enough to paper over
       | some of the red flags. Most scams are obvious in hindsight and
       | from an external view.
       | 
       | Believing that you couldn't fall for a scam is probably one of
       | the best ways to increase your vulnerability.
        
         | ghaff wrote:
         | I agree. There are good reasons to be skeptical of the story at
         | this point. But if, for purposes of argument, one ignores other
         | claims and goes by the original post only, it falls into the
         | category of vaguely plausible. Vaguely to be sure. But not
         | quite so vaguely that I'm going to say that no experienced
         | journalist could ever fall for it. (Although, the more I think
         | about it, the harder it is for me to believe that she wouldn't
         | have made one phone call or sent one email to the dean or
         | whoever to ask "Hey, I seem to be being given the runaround"
         | before quitting her job. Journalists aren't known for being shy
         | about picking up the phone.)
        
         | lern_too_spel wrote:
         | Indian journalists are notoriously gullible. Stories about them
         | being tricked are a dime a dozen.
         | 
         | http://www.gelfmagazine.com/archives/nasas_prodigy_takes_ind...
        
       | dissidents wrote:
       | This is ridiculous. This journalist doesn't even have a PhD or
       | any publications.
       | 
       | To those who are downvoting this because of the misleading
       | comment below, note that she claimed on Twitter to be joining the
       | Harvard Faculty of Arts and Sciences, not the Harvard Extension
       | School. Nobody becomes an Associate Professor at the Harvard FAS
       | without a PhD.
       | 
       | Source: https://twitter.com/Nidhi/status/1271705895437651968
        
         | ghaff wrote:
         | This was Harvard Extension School. You're not talking a tenured
         | Harvard professor position. One of my mentors undergrad was a
         | former Newsweek editor who lectured a couple days a week and
         | also didn't have a PhD or academic publications. (He had
         | written books.)
        
           | LordAtlas wrote:
           | Though she did originally say she was joining "Harvard
           | University's Faculty of Arts and Sciences" -
           | https://twitter.com/Nidhi/status/1271705895437651968
        
           | pge wrote:
           | For those not familiar with Harvard's Extension School, it
           | provides classes to the general public (you have to register
           | and pay but they are open to anyone)
           | 
           | https://www.extension.harvard.edu/registration-admissions
        
           | dissidents wrote:
           | This is just misleading. Razdan claimed on Twitter that she
           | was joining the Harvard Faculty of Arts, not the Harvard
           | Extension School. Harvard FAS does not have any journalism
           | professors or offer degrees in journalism, and if it did, you
           | would certainly need a PhD.
        
             | ghaff wrote:
             | All I know is what she wrote in the post: "Contrary to what
             | many are tweeting, Harvard has a school called the
             | Extension School offering a Journalism Degree Programme.
             | The actual programme is called the Master of Liberal Arts,
             | Journalism degree. The Extension School lists 500 faculty
             | of whom 17 are categorised as journalism faculty. A number
             | of these people are working journalists. I believed I fit
             | this profile."
             | 
             | ADDED: It certainly seems as if the story has changed from
             | something implausible to something vaguely understandable.
        
               | LordAtlas wrote:
               | I believe GP is referring to her original announcement
               | here:
               | https://twitter.com/Nidhi/status/1271705895437651968
        
               | dissidents wrote:
               | I know, and it is irrelevant and misleading. This is what
               | she tweeted in the first place:
               | 
               | "After 21 years at NDTV, I am changing direction and
               | moving on. Later this year, I start as an Associate
               | Professor teaching journalism as part of Harvard
               | University's Faculty of Arts and Sciences."
               | 
               | Nobody is joining Harvard's FAS as as an Associate
               | Professor without a PhD.
        
         | evanelias wrote:
         | I realize this is uselessly pedantic, but Harvard's Division of
         | Continuing Education (Extension School + Summer School) is
         | technically under the FAS umbrella, alongside Harvard College
         | (undergrad) and GSAS (graduate arts + sciences). ~15 years ago
         | I worked for FAS as a web developer, and the software my org
         | developed was used by all 3 of these schools. Wikipedia
         | confirms FAS is still organized in this way:
         | https://en.wikipedia.org/wiki/Harvard_Faculty_of_Arts_and_Sc...
         | 
         | That said, yes it's extremely misleading for a DCE instructor
         | to call themselves an FAS professor. This sort of thing does
         | happen at all top tier schools' extension programs, though far
         | more often it's done by students rather than instructors.
        
       | pomian wrote:
       | That's an intense level of con. Timed with the pandemic, it could
       | have been hard not to fall for. I hope there is a follow up on
       | who pulled it off. Did the perpetrators know the victim, did they
       | send more of these "letters"? The con seemed pretty specific for
       | a certain target. A lot of work to pull off. Also wonder if, and
       | hope, Nidhi got her old job back. With a great story.
        
         | scotty79 wrote:
         | It seems more specific to Harvard. I wonder if the documents
         | she was given by scammers were just believable or accurate. If
         | they mirrored actual Harvard recruitment process then it's
         | possible that whoever did this wokred or applied there.
         | 
         | Or maybe it wasn't about the money? Maybe she was targetted
         | specifically for her previous roles and knowledge?
         | 
         | Attack was very sophisticated.
        
           | alisonkisk wrote:
           | There is no "Harvard recruitment process" for adjunct
           | lecturers at the Extension school. People beat down Harvard's
           | door for jobs.
           | 
           | Story is very fishy.
        
             | foolmeonce wrote:
             | I wouldn't find it suspicious if some professors preferably
             | refer people who speak on the campus over the database of
             | spontaneous CVs, and there is a process regardless of how
             | it initiates.
             | 
             | I think it is equally easy to imagine that she made it up
             | (and pressured co-workers to lie?) to falsely claim harvard
             | credentials with a good out as it is to imagine that a
             | political organization wanted to discredit a journalist and
             | get her to resign, probably expecting her to go quietly.
             | 
             | Since politicians are being given special access to
             | advanced phishing, I think it is prudent to treat the story
             | as real. How can this not raise demand for similar attacks
             | using software from the US/Israeli/Italian/etc firms that
             | specialize in state sponsored crime?
        
         | ghaff wrote:
         | >Timed with the pandemic, it could have been hard not to fall
         | for.
         | 
         | It didn't start there though. The offer letter supposedly came
         | in January 2020 when things were perfectly normal in the vast
         | majority of the world; I was traveling around Europe without a
         | thought of pandemics at that time.
         | 
         | It seems a _little_ weird that there would be a job offer after
         | just a 90 minute phone interview. And moving halfway around the
         | world seems a pretty big deal and one would think someone in
         | that situation would be looking for a bit more motion on the
         | logistics. On the other hand, we 're talking Harvard _Extension
         | School_ and she 's in India so maybe not a complete red flag
         | especially given she had some apparent prior contact with the
         | school. But certainly the pandemic allowed them to string
         | things out for whatever reason.
         | 
         | It does seem as if there are different stories floating around
         | though.
        
       | 3327 wrote:
       | TLDR: i was a suckered into quoting my job and as a journalist
       | failed at the one job i am supposed to be good at- Getting the
       | truth in a story. I quit my job, look like an idiot so I write
       | this click bait piece to grab attention.
        
       ___________________________________________________________________
       (page generated 2021-01-16 23:01 UTC)