[HN Gopher] "Appointment" as professor at Harvard was an elabora...
___________________________________________________________________
"Appointment" as professor at Harvard was an elaborate phishing
attack
Author : LordAtlas
Score : 177 points
Date : 2021-01-16 13:53 UTC (9 hours ago)
(HTM) web link (www.ndtv.com)
(TXT) w3m dump (www.ndtv.com)
| wgriirwghawigi wrote:
| Is it possible she made this all up, for (temporary) media
| attention?
|
| Here she is hijacking an event for aspiring journalists to try
| and interview Barack Obama, who sees through this and publicly
| shames her:
|
| https://twitter.com/rose_k01/status/1350053978403291138
|
| There are multiple interviews of her talking about her upcoming
| appointment, her class structures, here (non-existent) syllabus.
|
| It seems like another possible interpretation of the events is
| that she made this all up, then blamed it all on a vague
| "phishing attack" to defuse any responsibility. In the months
| prior, her career received a boost from all the media attention.
| Now, she also has some level of additional fame, that while not
| exactly positive, could help her launch into the next phase of
| her aspirations
| LordAtlas wrote:
| Thread by a US-based tenured professor on how hiring works in
| academia:
| https://twitter.com/gauravsabnis/status/1350414118986121216
| screye wrote:
| I do not have much sympathy for her, given my low opinion of
| English-speaking Indian Media and their faux-elite mannerisms.
| Certainly some level of Schadenfreude. But, I won't go into that
| here.
|
| This seems more like a targeted public embarrassment operation
| than an attempt at identity theft. Objectively, Nidhi made a ton
| of elementary mistakes that would be inexcusable for a
| journalist. This includes non-technological mistakes such as not
| contacting the Dean or prospective collaborators who presumably
| voted to have her on the faculty. There is an immense amount of
| hubris on display as well. That being said, the scammers were
| incredibly sophisticated and committed to the ruse.
|
| Either ways, this sets a bad precedent. The internet allows for
| sophisticated scams like never seen before. A public
| embarrassment in the world of twitter can easily end careers.
|
| I hope she finds some quiet in the midst of this public show
| where she has been made an unwilling jester. She should have
| handled this in private. Now that it is out on Twitter, trolls
| will make sure she never forgets what I presume has been
| incredibly traumatic.
| alisonkisk wrote:
| She made it public because she had been doing PR telling people
| she was a Harvard professor.
|
| This "phishing" is suspected to be a cover up for her own fraud
| getting caught.
| randycupertino wrote:
| Is there a source on this?
| scarmig wrote:
| Definitely a targeted, very personal attack, as you can scam an
| order of magnitude more funds by focusing on the masses instead
| of making fake interviews, offer packets, etc.
|
| I'd love more details, because there's not much to learn here. I
| walk away from the article with no idea about novel defensive
| strategies people need to take and no idea what we as
| technologists can do to help prevent this in the future.
| MaxBarraclough wrote:
| It sounds like the scammers did a lot of work, succeeded in their
| deception, but still didn't end up turning a profit. What was
| their plan here?
| mlang23 wrote:
| The one thing the attacker definitely achieved was to reveal
| that a particular journalist is not very good at an essential
| part of their job, fact checking.
| mafuy wrote:
| You may be interested in this:
| https://www.youtube.com/watch?v=vJG698U2Mvo
| mlang23 wrote:
| How is this related to a job offer from a department that
| doesn't exist at all?
|
| And no, it wasn't particularily interesting since I am
| incapable of falling for optical illusions.
| lagolinguini wrote:
| Nidhi Razdan gets a lot of hate, particularly from the right in
| India.
| z3t4 wrote:
| I was probably a really bad joke by someone who did not like
| her. I can't see how you could get any financial gain from it.
| Scammers are usually slick, but very lazy.
| vinni2 wrote:
| I once got an email from our dean that he needed to see me
| urgently in his office. I first believed this was true but then
| this was very unusual to the dean who never communicated with me
| before to urgently needing me in his office. Once I double
| checked I realized it was a scam and many of my colleagues also
| got the same email.
|
| I immediately alerted the dean to warn everyone.
| MeinBlutIstBlau wrote:
| I figure if it's actually important, they'd personally meet me
| or call. You don't respond over email hoping an instant
| response. It's obvious from the start of the email.
| ghaff wrote:
| Maybe they have your email but not your mobile number? Or
| they want a written record of when and how they contacted
| you?
| MeinBlutIstBlau wrote:
| Depending on what rung you're on in the corporate ladder,
| if the head of the institution "needed me" immediately, I'm
| extraordinarily skeptical they do not have a means of
| contacting me directly. Especially if they have assistants
| and other immediate VP's. Hell a corporate directory to
| look up my number...
|
| If a CEO is gonna want me fired because I'm being skeptical
| of the veracity of an email, I wouldn't want to work at
| such a place.
| ghaff wrote:
| I guess it depends on the nature of the request. I got an
| email from our CEO a few weeks ago asking for my number
| to talk about something and I work for a 10K+ person
| company. (I also know him pretty well and I was pretty
| sure what this was in reference to.) A lot of execs don't
| have a problem with reaching out to people directly. Now,
| if he sent me an email asking me to go to some sketchy
| website or complete some financial transaction for him
| that would be something else.
| jccalhoun wrote:
| If this is legit, this is an insane amount of work to get
| someone's money. I add "if this is legit" because it does seem so
| unbelievable that someone would fake a 90 minute interview with
| someone. This leads me to believe it was personal because a
| scammer could have scammed a lot of other people in the amount of
| time and energy they put into scamming this one person.
| nullc wrote:
| People make prank phone calls that require a lot more work than
| a 90 minute phone interview.
| Cyclone_ wrote:
| It would be more helpful if she uploaded screenshots of the
| emails, including the sending address, and pictures of the
| letterhead. Assuming she's telling the truth about everything
| this would be by far the most elaborate phishing attack I've ever
| seen.
| patja wrote:
| She is remarkably circumspect about these details. Lots of
| references to people being allegedly from Harvard or appearing
| to be from Harvard. It does feel disingenuous to put that out
| there and not provide a single example.
| itg wrote:
| According the the founder of Nieman Lab at Harvard, Harvard has
| no school of journalism, no department of journalism, and no
| professors of journalism. See:
| https://twitter.com/jbenton/status/1350059632782356481
|
| I find it hard to believe a journalist with 21 years of
| experience wasn't aware of this. When someone reaches out to me
| regarding a new job opportunity, I always do some basic research.
| [deleted]
| aeoleonn wrote:
| I agree.
|
| I also wonder what degree of ego played into this.
|
| Who does Harvard contact out of the blue? If they contacted me
| out of the blue by email my first thought would be "Why would
| they contact me-- who am I? What have I accomplished that I
| would be on the radar that people are talking about me at
| Harvard to the point where I am invited to interview?"
|
| To me, that would be phishy-- Unless I was some award winning,
| well-published, and/or well-credentialed journalist.
|
| - Looking on Amazon, I see 1 book by this author: "Left, Right
| and Centre: The Idea of India". I also see a blank LinkedIn
| page, which mentions she lives in India.
|
| - On Wikipedia, I see she has " done documentaries from
| Pakistan-administered Kashmir, Tibet and the United Kingdom
| after the train bombings." and "has been the diplomatic
| correspondent of NDTV 24x7, which is an English language
| television channel that carries news and current affairs in
| India, owned by New Delhi Television Ltd network.":
| https://en.wikipedia.org/wiki/Nidhi_Razdan
|
| Those aren't trivial accomplishments. But I don't know that
| they represent the pinnacle of journalistic achievement to the
| degree that Harvard would reach out, out of the blue.
| kshacker wrote:
| Sometimes it is connectedness. See
|
| https://www.youtube.com/watch?v=SzCcVGbO9rw - Interview with
| Raghuram Rajan, who was the Governor of Reserve bank of
| India, was chief economist of IMF, and now a professor in US
|
| https://www.youtube.com/watch?v=p1qS4gdutso - Interview with
| a maverick political consultant, kinda like Frank Luntz of
| India
|
| https://www.youtube.com/watch?v=n6lolKKm2LU - Interview with
| Saudia Arabia foreign minister
|
| I am sure I can find more examples, but the point is that
| during a 21 year career, of which a few years as a prime time
| host, you build a lot of network, you get a lot of local
| awards, that when a US school comes fawning, it may be a
| small surprise, but you take it in the stride.
| e15ctr0n wrote:
| > _Raghuram Rajan, who was the Governor of Reserve bank of
| India, was chief economist of IMF, and now a professor in
| US_
|
| Raghuram Rajan has been a professor at the University of
| Chicago since 1997 except for a 3 year period from
| 2003-2006 when he served at the IMF. He was given a "public
| service" sabbatical from the University of Chicago to serve
| at the RBI.
|
| https://www.chicagobooth.edu/-/media/faculty/raghuram-
| rajan/...
| joshuaissac wrote:
| From the article:
|
| > Contrary to what many are tweeting, Harvard has a school
| called the Extension School offering a Journalism Degree
| Programme[1]. The actual programme is called the Master of
| Liberal Arts, Journalism degree.
|
| 1. https://www.extension.harvard.edu/academics/graduate-
| degrees...
| tinyhouse wrote:
| One suggestion to people is to not follow any links in emails and
| looking up things instead. For example, if you get an email to
| sign up for something, try to find that page yourself by googling
| it. If you get an email from someone at Harvard, try to find that
| person on the Harvard website to verify the email and everything
| else. But again, don't do it by following links in the email.
| Google/Bing/DDG is your friend.
| vinni2 wrote:
| Can't believe how confident must be. Harvard headhunted her
| without even applying for the job? She must be so cocky to fall
| for it.
| bob33212 wrote:
| Most phishing scams required the target to have an emotional
| reaction that clouds their judgement. For example, if you get
| an email saying that your credit card was charged in another
| state, if you are worried about your finances you may panic and
| click on the button to login and deny the charges.
| rm445 wrote:
| > I was invited to speak at an event (...) One of the apparent
| organisers of this event contacted me separately to say there
| was a vacancy for a teaching position and would I be interested
| (...) I submitted my CV (...) A few weeks later I was
| "interviewed"
|
| This sounds exactly like the kind of job opportunity that's
| meant to come about by networking, getting your name out there,
| public speaking and so on. We are often told that this is how
| the best jobs are found.
| ghaff wrote:
| Yes, up to that point it all seems very plausible whatever
| the victim-blamers on this thread think. Down the road,
| should alarm bells have started going off? Probably. But
| especially in the context of COVID-19, it's not hard to
| imagine those bells being suppressed in the excitement of a
| new opportunity etc.
| feral wrote:
| That is a bad sort of victim blaming.
|
| I hope you wouldn't apply that logic to victims of other non-
| online crimes.
|
| Anyway, separately, she addresses that in her article,
| convincingly I thought. Plus she's brave and helping others to
| write about this (which victim blaming doesn't encourage).
| vinni2 wrote:
| I would expect my aunt who thinks everything on WhatsApp is
| true to fall for it. She is a professional journalist with
| lots of experience as a fact checker. I am sorry she fell for
| it but someone with her education level and awareness I
| expected more.
| namanaggarwal wrote:
| My only point is that she is a journalist working for a
| reputable news agency for 21 years. Her job was to fact check
| everything. This means that a lot of things she told in the
| media before should be taken with a pinch of salt.
| minot wrote:
| Not just her. All of journalism.
|
| http://www.paulgraham.com/submarine.html
| cowpig wrote:
| What a strange reaction to this story.
| hfkldjsjfkdj wrote:
| Can't anyone say anything negative even if it makes sense?
| ryder9 wrote:
| ah yes the "my opinion is immune to criticism" response
| nip180 wrote:
| I had a similar thought: I would be more and more suspicious
| the longer I didn't get an email from an @harvard.edu email.
| FreakyT wrote:
| The article states that all the emails appeared to be from
| official Harvard email addresses.
|
| At some universities, it's possible to create email aliases
| at your .edu domain, so it's possible that the scammer had
| access to one or more convincing email addresses.
| nip180 wrote:
| That greatly increases the level of sophistication.
|
| The article doesn't say that the emails received were
| "@harvard.edu" only that they appeared to be valid Harvard
| ids. That means she made a judgement call that the email
| were legitimate, but it doesn't give very many technical
| details on what she judged that call on.
| InitialLastName wrote:
| This makes me assume that the bits she's most embarrassed
| about (a fact-checker should be able to find out what the
| valid Harvard email domains are) are the one she glossed
| over.
| nip180 wrote:
| I don't think this article was written for a technical
| audience so it's not surprising that it's light on
| technical details.
| namanaggarwal wrote:
| If this is all true, This was a very personal attack. This
| doesn't seem to be for financial gains but personal vendetta.
|
| Putting that aside, she should be equally blamed for falling for
| it despite being a fact checker for 21 years and also attending
| seminars, advisory meetings, talks and interviews as "Harvard
| Professor" without even going to a lecture hall once.
| alisonkisk wrote:
| No lecture halls in covid, but virtual lectures.
| Cyclone_ wrote:
| She mentioned she was interviewed online. Was it a video
| interview or someone IMing questions? A non video interview would
| have been a red flag to me.
| bawana wrote:
| so does mean that linked in is now a useful collection of
| targets?
| rileytg wrote:
| Unless harvard's email severs were breached, this seems like a
| case of user error... Harvard.edu has SPF headers which should be
| enough to detect fake emails right away. If i'm not mistaken
| you'd have a really tough time spoofing those emails.
| neya wrote:
| The last line - "(Nidhi Razdan is former Executive Editor,
| NDTV.)"
|
| That's their classic way of burning her for burning them.
|
| Having said that, I learnt the same lesson as well a few years
| ago. Never quit your current unless you're 101% sure your next
| job is waiting for you and all the due process is taken care of.
| aeoleonn wrote:
| TLDR: *It's not very useful to have an interpretation by a person
| who mis-interpreted a situation, without concrete real-world
| examples of what they actually interpreted: screenshots of
| conversations & email addresses/other contact info (at least
| domains such as @something.edu) , so I can at least say "Yeah,
| this was obviously phishing" or "wow, this phisher was really
| incognito".*
|
| I'm interested in seeing the email address domain of the person
| who phished this author. And other specific details about the
| conversation-- such as screenshots and other evidence.
|
| - "what appeared to be an official Harvard email ID" Did the
| phisher have a @harvard.edu sort of email address or not? I don't
| care about "what appeared to be" (i.e. insinuating the author
| interpreted the account to be official.) I want to know what the
| actual domain of the email address was -- not that in the
| author's opinion it seemed to not be fake.
|
| - I know some professors have their own websites & use their own
| custom domains-- still, I'd see this as phishy unless it
| specifically came from a @harvard.edu account. And even then, the
| phisher could still have somehow accessed an available account.
| But, then I'd simply try to find their faculty page. Also, I
| would expect other people or gorup-email-accounts in HR to be
| CCed on the emails, not just some individual contacting me.
|
| To be honest, I am surprised this author does not provide
| concrete details. She tells how things happened, and what steps
| she took. But provides no screenshots of her conversations, no
| specific details about the online personas of the phisher.
| JeremyNT wrote:
| There's something about this story that feels... incomplete to
| me.
|
| As the victim here - and as a journalist no less - it's in her
| own interest to present the attack as being incredibly
| sophisticated so as not to appear naive for being deceived. In
| reality, perhaps the attack was not as sophisticated as her
| narrative suggests.
|
| Like you, I'd appreciate some more details.
| lbblack wrote:
| Wholeheartedly agreed...
| Debug_Overload wrote:
| Also, the term "sophisticated" is almost meaningless here, and
| that's usually the case when talking about these kinds of
| issues. Pretty straightforward Nigerian prince style scam is
| now "sophisticated" phishing attack.
|
| We already had enough issues in infosec with companies claiming
| they're all attacked by "APT" and "state-sponsored actor". It
| just seems an easy way to dodge embarrassment and looking
| silly.
|
| Of course, there are real cases where the person/company may
| actually be a victim of a sophisticated phishing attack (or
| APT/state-sponsored attack, etc) but the terms lose their
| weight when they are being thrown around like this.
| spoonjim wrote:
| It's already an embarrassing situation to share. 99% of people
| would not share it. The screenshots might be even harder to
| share because the signs seem so obvious in retrospect. I agree
| that more would be valuable but understand why we may never get
| it.
| durovo wrote:
| I would expect a journalist to share this information. Many
| journalists don't shy away from sharing the details when they
| are reporting a story on someone else.
| aeoleonn wrote:
| I suspect that's exactly why they did not provide specific
| details. Which for me, negates the value of the article.
|
| In which case-- this article is more of a "Don't get phished.
| But I won't show you how not to get phished and what it looks
| like when you're getting phished."
| spoonjim wrote:
| The article has some value, which is to make people aware
| of the fact that this happens, and happens in highly
| bespoke ways to powerful/influential people. It's in all of
| society's interest that powerful people don't get phished
| (imagine this journalist getting phished, compromising
| photographs being stolen, and then blackmailed to say "talk
| positively about this political candidate and ensure they
| win or we will leak these photos." Not at all far fetched.
| poplan wrote:
| harvard.edu doesn't have a dmarc policy so it can be spoofed.
|
| edit: nevermind I've read the other replies and it's not that
| easy
| FlyingSnake wrote:
| > It's not very useful to have an interpretation by a person
| who mis-interpreted a situation, without concrete real-world
| examples of what they actually interpreted ...
|
| I second you. This being the Hacker news I'm really interested
| in how the phishing worked and the postmortem of the scam. This
| is a golden opportunity to learn about such high profile
| attempts, but no one's talking about it. It's sad to see that
| neither the author, nor her detractors are making any attempt
| to analyze the situation rationally.
| mensetmanusman wrote:
| A few weeks ago I was in the next room washing dishes overhearing
| my dad say he just got an alert of missing funds from his bank
| account.
|
| I asked him about it 10 minutes later and was shocked he had
| submitted all his account information from a text alert.
|
| "You do realize you just gave all your account information to a
| scammer in a phishing attack I hope."
|
| Thankfully he was able to change account information within
| minutes and no funds were lost.
|
| Moral: check in with your parents, people around the world are
| trying to scam them weekly.
| sulam wrote:
| This exact situation occurred a couple years ago to some people
| in the US. I don't know their names, and I didn't investigate the
| situation internally, so I don't know just how smart the phishers
| were vs their victims. What I do know is that I got a call from
| the front desk people at our Boston office that said someone is
| here for their first day of work and we have no record of them
| being hired. Did I know anything about this? I didn't. After some
| investigation it was revealed to be an identity theft scam, and
| within a week several other people were also found to be a victim
| of the same scam.
|
| Before you judge too harshly, keep in mind that often the people
| affected by this often aren't very technical, don't know what to
| look for when it comes to phishing, and are just doing what comes
| naturally in the situation. The scammers in this case are
| obviously at least somewhat technical and have a huge advantage
| in terms of being able to scattershot communicate with a very
| large group of people (potentially millions, although more likely
| 10's of thousands in the case I describe). Also, while I'm sure
| no one reading this has ever been phished ( _cough_ ), it has
| been _repeatedly_ found that phishing is effective, even for
| highly technical audiences. When it comes to recruiting, it is
| all too plausible that the person you're interacting with doesn't
| work for the company you're "interviewing" with, and many
| recruiters start a conversation not even revealing who they
| recruit for. In fact, there are recruiting agencies that may as
| well be phishing organizations, because they will claim to have a
| role simply to get your resume and then, once they have your
| information, will start shopping it to companies in an attempt to
| get paid.
|
| In short, I have a ton of sympathy for people affected by this,
| and think the assholes who do this kind of thing are pretty much
| evil.
| setum wrote:
| this was all over Twitter in India yesterday when she first
| tweeted about it. People where making fun of her and NDTV (her
| previous employer) which I thought was somewhat deserved
| considering they (she and her NDTV colleagues) pretend to be
| righteous, above all others, calling others with names like 'Fake
| Media', graduate of WhatsApp University, etc. They claim
| themselves to be true journalists and guardians of truth. This
| must be a reality check and sobering moment. (fun-fact: NDTV also
| runs a program named 'Reality Check')
|
| edit: grammatical
| lagolinguini wrote:
| They are certainly biased to the left. But they are definitely
| better than any of the alternatives in India... Have your seen
| what kind of garbage is reported by Indian news channels? There
| was the entire bullshit non issue about Rhea Chakroborty and
| the SSR suicide that was extremely disappointing to watch. And
| you can in no way defend the kind of nonsense that is spread on
| WhatsApp groups in India.
| setum wrote:
| You are all correct, It still doesn't justify self certifying
| as righteous. One's greatness is for others to evaluate, not
| they themselves.
| mav3rick wrote:
| You perceive them as righteous. They have never said it
| themselves.
| mav3rick wrote:
| I don't get it ? So they call out other media channels. So
| their journalists deserve shit ?
|
| Twitter is filled with BJP IT Cell bots and miscreants. I
| wouldn't expect less.
|
| Can you say with a straight face that Republic TV is not biased
| ? Or India TV ?
| LordAtlas wrote:
| Republic TV and Zee News are literally owned by BJP members
| of parliament.
| abhishekjha wrote:
| Surpringly similar to the story a senior Journalist at NYT got
| scammed by a guy pretending to be a terrorist :
|
| https://www.npr.org/2020/12/18/944594193/new-york-times-retr...
|
| What a roller coaster of emotion that Podcast was!
| LordAtlas wrote:
| While it's clear that this was a sophisticated and personally-
| targeted scam, I feel the blog post would have been more useful
| with information about which Harvard email addresses were used to
| communicate with her, and perhaps some screenshots. Were they
| actual harvard.edu email addresses, which means somebody had
| access to an official address for replying to mails from her?
| (That makes the scam deeper and involves US authorities.) Or was
| it something like harvardhr@gmail.com? Which means she should not
| have fallen for it.
|
| I just saw this tweet from someone senior at her former employer
| about how she uploaded a reference letter to an official-looking
| site but again, no screenshot or URL referenced.
|
| https://twitter.com/soniandtv/status/1350415332599480324
| quesera wrote:
| She writes: "what appeared to be an official Harvard email ID".
| No further description is given.
|
| This could be something as simple as "someone@harvard-
| faculty.org".
|
| For the recipient, this is effectively indistinguishable from a
| legit address. Not just because people are unsophisticated, but
| because many orgs really do use this sort of ancillary domain
| for conducting real business.
|
| I've seen Fortune 50 corps, hospitals, and banks make this
| mistake.
|
| Even if Harvard does not, has not, and will not ever make this
| mistake, an outsider would not be surprised to see it.
| psychometry wrote:
| No, anyone at Harvard uses a @*.harvard.edu address.
| quesera wrote:
| Yes, of course.
|
| But the senders were not _at_ Harvard, so it 's very likely
| that they did not do so. And they would not need to do so,
| for their purpose.
| notahacker wrote:
| Sure, but you wouldn't expect the average person who
| doesn't have a deep interest in tech and lives in a country
| where the .edu suffix isn't even a thing to know this. I
| doubt even most hackers here validate the ownership of the
| URLs every time a recruiter reaches out with a plausible-
| sounding personally-targeted opportunity (as opposed to a
| 'dear customer please sign in here' mass-mailing)
| [deleted]
| orange_tee wrote:
| Email addresses can be spoofed.
|
| https://en.wikipedia.org/wiki/Email_spoofing
| noname120 wrote:
| No. [1][2][3]
|
| [1] https://en.wikipedia.org/wiki/Sender_Policy_Framework
|
| [2] https://en.wikipedia.org/wiki/DMARC
|
| [3] https://en.wikipedia.org/wiki/DomainKeys_Identified_Mail
| lkurtz wrote:
| Only if they're used. There are no DMARC records in place
| for harvard.edu or subdomains, which is kinda shocking.
| oefrha wrote:
| The lack of DMARC records, even if it could facilitate
| spoofing, won't magically make reply emails addressed at
| a valid @harvard.edu address land in a spoofer's inbox. A
| different Reply-To address is possible but then you can't
| claim a lack of warning signal. There's something else
| going on.
| willmeyers wrote:
| I'm guessing the scammers did something like
| person@hr.harvard.edu.obscuredomain.tld
|
| They've gotten pretty good at crafting domains this way.
| foolmeonce wrote:
| No idea on harvard, but alumni are often allowed to keep
| their addresses and for every alum that still takes full
| advantage of that, ten may not notice anything. Similarly,
| old group addresses may mostly go into the void.
|
| I suspect it is quite easy to make it look like many people
| from an institution are in a thread and a passive
| participant is an email address from a 3rd party job
| portal.
| oefrha wrote:
| I don't know a single reputable U.S. institution that
| doesn't replace your @university.edu address with
| @alum[ni].university.edu after you leave. I've been
| affiliated with two and have friends all over the place,
| including Harvard.
| UncleMeat wrote:
| My alma mater (one of the highest ranked state schools)
| grants your email for live and does not update it.
| gnicholas wrote:
| For decades, Harvard issued alumni email addresses of
| *@post.harvard.edu. [1] Given that "post" could either
| refer to "after" or "postal", I would imagine someone who
| didn't know many people at Harvard might think that a
| post.harvard.edu email address is a normal thing for
| current employees.
|
| 1: https://alumni.harvard.edu/help/email-forwarding
| foolmeonce wrote:
| MIT is right next to Harvard..
|
| *Might your own cultural expectations open you to attacks
| from a place with MIT's (recent if not current) network
| culture?
| oefrha wrote:
| MIT uses @alum.mit.edu. I don't think I know former
| employees there but at least former students I know lose
| mit.edu addresses, a fact also easily confirmed with a
| Google search. So, your point being?
|
| Edit: You added
|
| > *Might your own cultural expectations open you to
| attacks from a place with MIT's (recent if not current)
| network culture?
|
| after my reply. I'm not sure how it is relevant to your
| claim that "alumni are often allowed to keep their
| addresses". In fact the question doesn't make any sense
| to me; I'm not gonna accept an MIT job offer from an
| alum.mit.edu address (or more relevant to me,
| alumni.stanford.edu/alumni.princeton.edu), regardless of
| network culture.
|
| Edit 2: Reread your question and realized you were
| implying that MIT "recently" allowed alumni to keep
| @mit.edu addresses. Well, you'll need to show some proof.
| foolmeonce wrote:
| Your expectations are very specific to what you know
| about US schools right now. MIT would let a machine
| receive email, many institutions would forward email to a
| users alum address, etc.
|
| This approach to identifying phishing is ultimately
| insufficient.
| LordAtlas wrote:
| Well, of course, SMTP headers are trivial to spoof, but for
| this scam to work, the scammer would need actual POP/IMAP
| access to the harvard.edu account to receive her replies and
| respond to those, which is not as trivial.
| tinyhouse wrote:
| Exactly. No concrete details and examples so safe to assume the
| emails were not actual @harvard.edu ones. But I blame it on
| organizations and esp universities. Each school/lab get their
| own prefix which makes it harder for people to spot a fake
| address.
| nullc wrote:
| > to assume the emails were not actual @harvard.edu ones
|
| If that is so... so what? Plenty of organizations use
| different domains. Fidelity staff uses "frm.com"-- as an
| example-- while most customers know them as fidelity.com.
| mensetmanusman wrote:
| Imagine a future where an army of GTP-4 agents await mere mortals
| in cyberspace.
|
| If they are all programmed to extract funds through conversation,
| how will we prevent this?
| cowpig wrote:
| This scam sounds frighteningly sophisticated. I really feel bad
| for people who get caught up in things like this.
|
| To get strung along for over a year, throwing away that much time
| and energy, must feel devastating.
| runawaybottle wrote:
| It's not sophisticated, it preys on very vulnerable and
| sheltered people.
|
| Like, you have to know Harvard is not going to just call you up
| one day and decide to fly you over to America lol. Really a
| problem with delusions amongst many of us.
| ceejayoz wrote:
| You really should consider reading the article.
| runawaybottle wrote:
| I did.
| wtmt wrote:
| Regardless of which side of the political spectrum one is or what
| qualifications one has or what terrible deeds one has done (or
| alleged to have done), the fact is that phishing attacks aren't
| very easy to avoid (you'd be fooling yourself if you believe
| you'd never fall for one). You can ace all the phishing email
| tests your company routinely sends you and still fall for a more
| sophisticated attack or fall for something that in retrospect
| seems stupid because you were preoccupied or stressed or had
| other serious things going on in life.
|
| Victim blaming and questioning how she could believe that she's
| qualified for some position is the wrong thing to talk about, and
| is also disgusting in certain ways.
|
| What would be better, at least in a tech focused community, is to
| find out more details on how this happened and where the gaps
| (that are obvious in hindsight) are. I wish someone like Brian
| Krebs (of Krebs on Security) could get more information on this
| and do a detailed write up. That would be more insightful and
| useful to everyone than rants about the victim.
| gumby wrote:
| A clever element of this is the cross-cultural nature: the
| Harvard name internationally known, yet someone not in that
| milieu would not be able to detect a number of "red flag"
| anomalies. In fact if the author was phished by someone in
| India (a likely case) then the perpetrator could make a
| cultural error that would be undetectable by the victim as they
| might share the same set of assumptions.
|
| I say "cross cultural" but by that I also mean "cross domain"
| which is how financial scams can entrap victims who aren't
| familiar with the details of financial jargon.
|
| It's also why people can believe conspiracy theories which are
| absurd to someone familiar with the domain.
| ghaff wrote:
| Thank you for posting that. There are obviously way too many
| people here (and elsewhere) who think _they 're_ way too smart
| to fall for phishing and other forms of scams unlike "stupid"
| grandmas, journalists, etc.
|
| The reality is that we all do things when we're distracted and
| not really paying attention. Or we get caught up in the
| excitement of something and we don't stand back and ask
| ourselves whether it really makes sense. And anyone who thinks
| otherwise is just arrogant and misguided.
| networkimprov wrote:
| This. And the effectiveness of targeted phishing is why we
| must replace SMTP-based email, and eventually _block SMTP on
| public networks_. It isn 't suited to the 21st Century
| Internet.
|
| Hence, the mnm project[1] (open source client & server) and
| TMTP[2][3].
|
| [1] https://mnmnotmail.org
|
| [2]
| https://github.com/networkimprov/mnm/blob/master/Protocol.md
|
| [3] https://mnmnotmail.org/rationale.html
| dissidents wrote:
| It may well be true that phishing scams can be easy to fall
| for, but it is not relevant to this story. Razdan tweeted
| that she was joining the Harvard's Faculty of Arts & Sciences
| as an Associate Professor. Regardless of how convincing the
| phishing attempt was, this is incredibly naive; Razdan does
| not have a PhD or any publications and Harvard's FAS does not
| have any professors in journalism.
|
| Edit: https://twitter.com/ruchirsharma_1/status/1350067266289
| 85651...
|
| It seems that this may not even have been a phishing attempt.
| [deleted]
| pmiller2 wrote:
| Not to mention that universities typically don't hire
| people at the associate professor level. The first rank is
| called "assistant professor," followed by "associate
| professor," and then "full professor." Associate and full
| are tenured ranks, which is why there isn't much hiring at
| that level.
|
| Also, one would expect any open position at a US university
| to be advertised, most likely in _The Chronicle of Higher
| Education_. This is something perhaps only someone who 's
| got a little familiarity with the academic job market may
| know, so, I suppose one could be forgiven for not knowing
| it, but I would assume that one would at least google for
| open positions at Harvard to find out if it really exists.
|
| That said, naive or not, I also don't think victim blaming
| is a productive thing to do here. All it does is discourage
| people from speaking out about their experiences, which
| means we can't learn from them. It may also discourage
| people from seeking help when they think they might be
| getting phished.
| LordAtlas wrote:
| This thread says people from industry are sometimes hired
| without needing Ph.Ds - https://twitter.com/gauravsabnis/
| status/1350414118986121216
| pmiller2 wrote:
| Ok? I never said anything about PhDs. What I said was
| that people typically aren't hired in at the associate
| level. Those that are would typically be professors who
| have tenure at another institution, meaning that they're
| _already at_ the associate level or higher. People who
| are denied tenure at their current institution and want
| to continue in academia would apply to an assistant
| professor job and negotiate a shortened tenure clock,
| meaning that they would be assessed for tenure in fewer
| than the standard 6 years that a brand new, never held a
| professorship of any type assistant professor would have.
|
| Again, this is a lot of esoterica about the academic job
| market that not many people outside of those circles is
| going to know, so I don't blame anyone for not knowing
| it.
| dissidents wrote:
| As others have pointed out on Twitter, I am not sure who
| is the victim here; Nidhi Razdan apparently had multiple
| speaking engagements where she was introduced as Harvard
| faculty:
|
| Example: https://pbs.twimg.com/media/ErxnAc5XEAEkro3?form
| at=jpg&name=...
| CyberRabbi wrote:
| What you are suggesting here makes this already
| interesting story even more interesting. Perhaps there
| are holes in her story but if she really knowingly faked
| the whole thing, why would she resign from her job?
| ghaff wrote:
| Because she was maybe resigned?
|
| It's possible there's an innocent explanation but Occam's
| Razor does suggest she just made up her Associate
| Professor at Harvard title and, when called out for it,
| concocted a story about it really being Harvard Extension
| School and phishing. Which was vaguely plausible so long
| as you don't think too deeply about it and ignore that,
| if this were the case, the initial Twitter post was
| deceptive.
| CyberRabbi wrote:
| By "resigned" I am assuming you mean she was fired. If
| she were fired why would her previous employer allow her
| to use their website to publish this story?
| ghaff wrote:
| Who knows? Maybe the Occam's Razor conclusion isn't in
| fact the right one. Maybe the publication thinks it saves
| them face as well as her. (Journalists who lie look bad
| for news publications even if they're fired.)
| pmiller2 wrote:
| I don't understand. Are you saying people are claiming
| she made the whole thing up and was just going around
| saying she was an associate professor at Harvard?
| alisonkisk wrote:
| Yes. That's what the Twitter thread shows.
| ghaff wrote:
| As I responded elsewhere, that's not what she wrote in the
| post that people are responding to. I would agree that if
| it were the case that she was offered a full faculty
| position after a 90 minute remote interview, that wouldn't
| pass the sniff test. But that's not what she claims in this
| post. It's very plausible that a working journalist would
| teach at Harvard Extension School. Though it's at least a
| bit of a stretch that Harvard would relocate someone from
| India to do so. And it does seem that her story is
| changing.
|
| ADDED: And, yes, there seem to be different claims on
| twitter than what is stated in this post.
| dissidents wrote:
| "But that's not what she claims in her post."
|
| I am not sure how much more clear I can be with you.
| Nidhi Razdan claimed on Twitter that she was joining the
| Harvard Faculty of Arts and Sciences as an Associate
| Professor. The Harvard Extension School has absolutely
| nothing to do with any of this. Here is the original
| tweet:
|
| https://twitter.com/Nidhi/status/1271705895437651968
| boomboomsubban wrote:
| The Harvard Extension School is a program of the Harvard
| Division of Continuing Education, which is part of the
| Harvard Faculty of Arts and Sciences.
| dissidents wrote:
| Again, this is irrelevant. I find it hard to believe how
| often I have to repeat this. The Harvard Extension School
| does not hire tenured professors. You do not become a
| tenured faculty, let alone an associate professor, at
| Harvard's FAS if you have no research background. The
| story should fail a minimal scrutiny test from a
| layperson, let alone a journalist with more than 20 years
| of experience. This just doesn't add up.
| boomboomsubban wrote:
| Why do you repeatedly say "I can't believe I have to
| repeat this" and then say something you haven't mentioned
| in this thread?
|
| What an "associate professor" is isn't common knowledge,
| even for a journalist. It both means something different
| in Commonwealth countries and the definition of
| "associate" is "entry level" which doesn't fit either
| version of an associate professor.
| Aeolun wrote:
| > You do not become a tenured faculty, let alone an
| associate professor, at Harvard's FAS if you have no
| research background.
|
| This is _not_ something someone without a research
| background would know.
| ghaff wrote:
| I'd absolutely expect an experienced American journalist
| to have a pretty good idea of how academia operates in
| the US. I do and I don't have a research background. I
| have no idea though how things operate in India.
| ghaff wrote:
| The title is still fishy though even if she (as a
| journalist!) took some liberties in implying she was a
| professor at Harvard University (and what that implies)
| even though she wasn't. Just as if I said I graduated
| from Harvard when I got a degree of some sort from HES,
| that's clearly misleading. If you look through the
| faculty directory of HES, it doesn't look as if HES
| generally gives titles; most of the titles given are the
| faculty's positions at other institutions where
| applicable. (There are a few Lecturers in Extension.)
| localhost wrote:
| Which would have made her an adjunct professor, certainly
| not an _associate_ professor.
| pwillia7 wrote:
| This reminds me of how if you ask almost anyone if marketing
| works on them, they'll say no or not the deceptive parts.
| Yet, logically, marketing must work on most people or Coke
| wouldn't spend 4 billion dollars a year on it. Feels hubris-y
| to me. We forget we all have the same equipment.
|
| https://www.investopedia.com/articles/markets/081315/look-
| co...
| sjs7007 wrote:
| Idk, it could still be wrong or not as useful as thought
| of.
|
| https://www.forbes.com/sites/augustinefou/2021/01/02/when-
| bi... :When Big Brands Stopped Spending On Digital Ads,
| Nothing Happened. Why?
| pwillia7 wrote:
| Interesting article. I know the big CPGs have been
| challenged by digitally native brands like harrys and the
| shave companies. It's also clearly not true if you're not
| a globally known brand with a lot of monopolies. I wonder
| if it holds true in all markets for the big brands. I
| also wonder if it would open them to more competition
| from smaller brands over time. Like the other commenter
| said, hard to name too many non coke/pepsi carbonated
| beverages.
| CyberRabbi wrote:
| People always say marketing doesn't work on them until you
| ask them to name non-Coke carbonated beverages...
| eitland wrote:
| I'm not sure if I understand you correctly, but at least
| around here thers RC Crown Cola, Solo, Farris, Pepsi,
| Pepsi Max, Eplerose, Oscar Sylte Paerebrus, Monster
| energy, Red Bull, 7-up etc and I don't think I am special
| at all for knowing them.
|
| In case it matters, a number of these don't advertise, at
| least not in the same league as coke (multiple national
| campaigns a year).
| CyberRabbi wrote:
| > I don't think I am special at all for knowing them.
|
| I would guess that at least 80% of people off the street
| would only be able to name advertised carbonated
| beverages. In that case, yes I think you are special.
| mlang23 wrote:
| I have yet to see a scam which would fool me. And I have seen
| many already.
|
| All the scam and phishing mails I saw in my whole internet
| career were somewhere between totally obvious and embarrasingly
| blunt.
|
| I can't agree with your assessment. If someone is naive, they
| are at risk. Same applies for overconfidence. These are
| personality traits which are easily exploited. In real life as
| well as on the Internet. We cant protect everyone from
| everything. Neither in healthcare nor in VR.
| quesera wrote:
| > I have yet to see a scam which would fool me. And I have
| seen many already.
|
| That's because you have never been targeted. It's that
| simple.
|
| There is a small segment of society who are: a) savvy, and b)
| not actively engaged in
| commerce/business/community/career/friends/family, so _any_
| solicitation over email is likely suspicious.
|
| Everyone else is at some level of risk. And sometimes it only
| takes one failure.
| aidenn0 wrote:
| Even untargeted scams can fool a savvy person by
| coincidence. I followed my accountant when he switched
| accounting firms. Within two weeks of that, I got a generic
| accounting email SharePoint document share. It linked to
| the actual ms domain and used some redirection trickery to
| end up on a pixel perfect copy of the office 365 login
| screen. I only didn't get scammed because my password
| manager refused to auto fill.
|
| Had the email come after I had learned the name of the new
| accounting firm, I never would have even clicked on the
| link.
| ghaff wrote:
| >Even untargeted scams can fool a savvy person by
| coincidence.
|
| And you can pick them up 99 times out of 100. But that
| 100th time, you're tired, rushing to get out the door,
| etc. and they get you.
|
| I'm definitely more cautious than I was when phishing was
| just starting to be a big thing. Back then I don't think
| I ever fell for anything but there was once or twice when
| I wasn't really thinking and started down the path of
| providing information.
| mlang23 wrote:
| Interesting. How do you know that I have never been
| targeted. Did you ask your crystal ball? Or is it that you
| just know everything? I am amazed and bow to your skills,
| great magician.
|
| Also, implying that I am not actively engaged with anything
| is a pretty personal attack. Reserve your patronising
| behaviour for your children please.
| fortran77 wrote:
| I admire her for doing the right thing, and risking
| embarrassment and shame, by telling the story to make the
| rest of us hyper-aware.
| notahacker wrote:
| > I have yet to see a scam which would fool me
|
| If it fooled you well enough you might not have noticed you
| were scammed.
|
| Scams run from laughably blunt like the Nigerian prince to
| remarkably close to the real thing, like the callcentre that
| rang me pretending to sell phone contract upgrades that used
| exactly the same crap phone sales techniques my actual
| network used when they (coincidentally) called me a week
| later, and had a 1-letter different email address with the
| URL redirecting to the same website
| reddog wrote:
| > I have yet to see a scam which would fool me
|
| Maybe not but you will. If you live long enough you _will_
| suffer inevitable cognitive decline until one day you _will_
| be vulnerable to such a scam. We all will. No amount of good
| diet, meditation, fish oil and exercise will keep that from
| happening.
| alisonkisk wrote:
| mlang23 has commented about being blind, which is a pretty
| huge filter against Internet scams, which aren't designed
| for screen readers.
| mlang23 wrote:
| You pretty much nailed it. I am filtering a lot of stuff
| because I refuse to use certain modern flashy
| technologies. Office 365, yeah, go away. Firefox? Only on
| a dedicated machine if I really need it.
|
| Emacs, SSH, tmux, old fashioned email (text only) and a
| linux virtual console is all I need to be productive,
| _fast_ and especially happy.
|
| A big part of what makes these attacks work is the tech
| stack in use on the recipients side. I recently heard
| about a Emotet attack, and was told "Well, you know, the
| problem is that Outlook only shows the name but not the
| address by default". Oh well, what can you say about
| that?
| Frondo wrote:
| If any sizeable portion of internet users were also
| visually impaired, and on a stack similar to yours, you'd
| certainly see scams targeted at you.
|
| Good for you for being so far off the map, though, that
| is a good protective measure.
| mlang23 wrote:
| We're all gonna die. Some earlier, some later.
| 11thEarlOfMar wrote:
| One that was successful at my company recently was an e-mail
| sent to an electrical engineer from the CEO saying that the
| CEO needed a gift card from Target for an employee birthday,
| and had forgotten to pick it up. The EE went to Target and
| bought the card. The instructions including to reply to the
| e-mail with the card # so the CEO could include the number in
| the birthday card and not need the actual plastic.
|
| The spoof was believable at first glance. It used the CEOs
| actual first name and obscured the actual source e-mail
| address with his company e-mail as the name. What should have
| given the engineer pause (among other things) was the
| context. There was no reason that the CEO would ask an
| engineer to do this task at my company. Nonetheless, the
| engineer was perhaps overly deferential to the chain of
| command and the suspicion didn't emerge until he had
| embarrassed himself.
| Aeolun wrote:
| Hah, I almost fell for the same thing, but when they asked
| for 4! $1000 codes! over email! I got a bit suspicious.
|
| Could have probably gotten 4 times $50 out of me though.
| mlang23 wrote:
| Simple. Either call or reply asking him why he didn't send
| this mail to the secretary.
|
| If you can't be so direct with your boss, find another job.
| 11thEarlOfMar wrote:
| In this case, it was his boss's boss's boss (I am his
| boss's boss). This particular engineer is highly valued
| at the company, including by me personally. It was at the
| same time surprising, but paining to see his
| consternation, and I certainly do hope he doesn't leave
| us. I'll gladly endure a $100 mistake to have his talents
| and attitude as an engineer.
| pwillia7 wrote:
| That's rough. I got a phishing email from my CEO asking
| about something similar with money and had a brief 'oh
| shit' chain of command moment before my incredulousness
| kicked in. I get it.
| spoonjim wrote:
| No offense, but you're likely a "nobody." So you've only come
| across the generic scams. This is a famous person. The
| phishing attempt was designed specifically for her. You don't
| know if you'd fall for it because 1) nobody would invest that
| much effort into phishing you, and 2) "we'd like you to come
| teach at our university" is a plausible thing for her to hear
| but not you or I.
| unanswered wrote:
| Whenever I'm changing jobs, I spend at least half my time worried
| sick that I'm being scammed somehow. Until now, the "rational"
| part of my mind thought this was very silly, but I think this
| goes to show that it's a legitimate concern.
|
| The fact of the matter is that when joining a new institution one
| lacks the contacts and the context to discern normal
| institutional behavior because it so often deviates from
| (seemingly) ordinary, sane human behavior even when nothing is
| wrong. Having autism, no part of my mind is naturally attempting
| to cover up this discrepancy: it remains jarring until I manage
| to "manually" reset expectations.
| djrogers wrote:
| > The fact of the matter is that when joining a new institution
| one lacks the contacts and the context to discern normal
| institutional behavior
|
| That was the case for me at a couple of very early jobs in my
| career, but hasn't been the case for the last couple of
| decades. New jobs come by way of old colleagues, friends, etc.
| in such a way that I'm basically never walking in to a
| completely unknown situation.
|
| If you're not great at relationship maintenance, use something
| like LinkedIn. Reach out to former coworkers who you worked
| well with or got along with, and ask about jobs. Odds are very
| high that they'd like to work with you again, and will get a
| referral bonus if it happens!
| ghaff wrote:
| I've gotten out of the blue recruitment calls, but after my
| first job via on campus recruitment out of grad school, every
| job (just a few of them) have been directly through people I
| knew. Except for essentially pro-forma reasons, I've probably
| never really needed a resume.
| MeinBlutIstBlau wrote:
| I 100% agree. All the hoops you have to jump through and things
| you need to enter regarding personal information always makes
| them feel like a honeypot. Not one moment in initial onboarding
| process do I feel like I'm legitimitely giving my info to HR
| but some scammer in god knows where.
| lagolinguini wrote:
| It's been particularly hard interviewing during the pandemic.
| In usual times, at least you would visit the office and meet
| some real people in person. Not saying you can't get scammed in
| person, but it's definitely harder to impersonate reasonably
| large organisations like that.
| ghaff wrote:
| Unless maybe it was somewhere I knew people well, I'd be very
| hesitant to switch jobs in a situation where I only had
| communicated virtually--unless I had no choice in the matter.
| xhkkffbf wrote:
| SPOILER: If you want to see an example of scamming people by
| sneaking into an office and pretending to work in it, watch
| "Charade" with Cary Grant and Audrey Hepburn.
| lkurtz wrote:
| Wow, very surprised to see no DMARC records in place for
| harvard.edu or their various subdomains. It may be possible that
| a single DNS record could have prevented this whole madness.
| crowf wrote:
| > In January 2020, I got an email from an alleged Harvard Human
| Resources person from what appeared to be an official Harvard
| email ID,
|
| it would have been interesting if she would have shared exactly
| what that email address was. Was it hr@harvard.com or maybe
| hr@harverd.com? I doubt that it was hr@<something>.edu since it
| is hard to register .edu domains. But if someone did, that would
| be news to me.
| notahacker wrote:
| A url containing 'harvard' and redirecting to an actual faculty
| website is going to convince most people if the communications
| are plausible. Many large organizations use multiple url forms
| for emails, especially for quasi-separate divisions like
| business schools or extension programmes.
|
| A particularly sneaky scammer without access to Harvard
| mailboxes might register a plausible-sounding domain with an
| .ac TLD (which resembles the .ac reserved for universities in
| many national domain systems including the author's, but is
| actually a freely purchasable domain supposedly associated with
| Ascension Island)
| alisonkisk wrote:
| A clever person could hijack an alumni email account
| username@post.harvard.edu
|
| Note the bad pun Harvard uses: "post"
|
| Or you could get an address (deceptively or via hijack) on an
| subdomain run by a student group.
| pge wrote:
| You can't send from a post.harvard.edu email address - it is
| just a forwarding address for receiving mail.
| ghaff wrote:
| Yeah. The alumni emails probably follow a pattern. Get a list
| of alumni and find one who hadn't set up an email forwarding
| address previously and set up an account.
| netsharc wrote:
| Maybe something like @harvard-school-of-journalism.com,
| although that's too wordy. The article mentions "Harvard
| Extension School", so, it could be some variation of that.
|
| Edit: I tried harvard-extension.school in the browser, it
| redirected me to http:harvard-education.edu (not https!), which
| seems to be a clone of extension.harvard.edu . The WHOIS
| records of harvard-extension.school/.education are pretty new
| (registered last year), and they're registered on GoDaddy and
| 1API GmbH respectively. A Germany-based registrar? Would
| Harvard use them?
| oefrha wrote:
| This episode makes me wonder: how many times an anonymous source
| "verified" by a journalist is just someone pretending to use an
| organization's official email address.
| boomboomsubban wrote:
| This is why journalists generally try to confirm information
| before publishing. I wouldn't say it never happens, but there
| is supposed to be some amount of verifying that wouldn't have
| been done on a personal job offer.
| nip180 wrote:
| How do we establish trust in a virtual world? There are a lot of
| cues in an meatspace social interaction that can trigger a "gut
| reaction" one way or another on trust. In digital interactions
| it's significantly easier to be social engineered.
| lagolinguini wrote:
| Everybody gets a public key certificate, possibly since birth.
| There needs to be some way of establishing that which keys
| belong to which person, perhaps via some government registry,
| and a way to invalidate old/compromised keys. Overkill?
| Aerroon wrote:
| Kind of like ID cards in Estonia? You have a chip on the card
| that holds your private key and the government has a list of
| people and their public keys. Services and other people can
| check that. You can even sign and encrypt documents with it.
| netsharc wrote:
| China's ID cards also have chips, and they have to scan
| them to enter train stations or airports (or the center of
| the old town in Tibet)...
| JackFr wrote:
| You get the feeling that this was not phishing scam with the
| ultimate goal of financial crime. This (to me) smells more like a
| specific, personal attack on this woman with the intent to
| humiliate and embarrass her professionally.
| lagolinguini wrote:
| > personal attack on this woman with the intent to humiliate
| and embarrass her professionally.
|
| This is exactly what it feels like to me.
| netsharc wrote:
| Yeah, who would spend the 90 minutes doing a fake interview for
| a random phishing victim. Even one with questions that are
| convincing enough to her.
|
| Assuming the scammers are Indian, and the victim would be
| expecting some Americans interviewing her, I wonder how they
| scammers got some Americans to join in the scam. Hire some
| American actors and tell them it's for a prank TV show maybe?
| kshacker wrote:
| I did not want to speculate, but when I think of someone
| wanting to humiliate and embarrass, the first name that came to
| mind was "IT cell". But one of my friends said, the "IT cell"
| usually sends rape threats, they are not so sophisticated.
|
| You either know about the "IT cell" or please google it ... all
| the links on it are non-authoritative.
| jerome-jh wrote:
| Definitely. Looks like the goal was to make her leave her
| position at NDTV.
| nullc wrote:
| What the heck is going on with the victim blaming -- both here
| and by Harvard staff on twitter? It's gross.
|
| I'm sure this was an opportunity of a life time-- not enough of
| one to come off as totally implausible, but enough to paper over
| some of the red flags. Most scams are obvious in hindsight and
| from an external view.
|
| Believing that you couldn't fall for a scam is probably one of
| the best ways to increase your vulnerability.
| ghaff wrote:
| I agree. There are good reasons to be skeptical of the story at
| this point. But if, for purposes of argument, one ignores other
| claims and goes by the original post only, it falls into the
| category of vaguely plausible. Vaguely to be sure. But not
| quite so vaguely that I'm going to say that no experienced
| journalist could ever fall for it. (Although, the more I think
| about it, the harder it is for me to believe that she wouldn't
| have made one phone call or sent one email to the dean or
| whoever to ask "Hey, I seem to be being given the runaround"
| before quitting her job. Journalists aren't known for being shy
| about picking up the phone.)
| lern_too_spel wrote:
| Indian journalists are notoriously gullible. Stories about them
| being tricked are a dime a dozen.
|
| http://www.gelfmagazine.com/archives/nasas_prodigy_takes_ind...
| dissidents wrote:
| This is ridiculous. This journalist doesn't even have a PhD or
| any publications.
|
| To those who are downvoting this because of the misleading
| comment below, note that she claimed on Twitter to be joining the
| Harvard Faculty of Arts and Sciences, not the Harvard Extension
| School. Nobody becomes an Associate Professor at the Harvard FAS
| without a PhD.
|
| Source: https://twitter.com/Nidhi/status/1271705895437651968
| ghaff wrote:
| This was Harvard Extension School. You're not talking a tenured
| Harvard professor position. One of my mentors undergrad was a
| former Newsweek editor who lectured a couple days a week and
| also didn't have a PhD or academic publications. (He had
| written books.)
| LordAtlas wrote:
| Though she did originally say she was joining "Harvard
| University's Faculty of Arts and Sciences" -
| https://twitter.com/Nidhi/status/1271705895437651968
| pge wrote:
| For those not familiar with Harvard's Extension School, it
| provides classes to the general public (you have to register
| and pay but they are open to anyone)
|
| https://www.extension.harvard.edu/registration-admissions
| dissidents wrote:
| This is just misleading. Razdan claimed on Twitter that she
| was joining the Harvard Faculty of Arts, not the Harvard
| Extension School. Harvard FAS does not have any journalism
| professors or offer degrees in journalism, and if it did, you
| would certainly need a PhD.
| ghaff wrote:
| All I know is what she wrote in the post: "Contrary to what
| many are tweeting, Harvard has a school called the
| Extension School offering a Journalism Degree Programme.
| The actual programme is called the Master of Liberal Arts,
| Journalism degree. The Extension School lists 500 faculty
| of whom 17 are categorised as journalism faculty. A number
| of these people are working journalists. I believed I fit
| this profile."
|
| ADDED: It certainly seems as if the story has changed from
| something implausible to something vaguely understandable.
| LordAtlas wrote:
| I believe GP is referring to her original announcement
| here:
| https://twitter.com/Nidhi/status/1271705895437651968
| dissidents wrote:
| I know, and it is irrelevant and misleading. This is what
| she tweeted in the first place:
|
| "After 21 years at NDTV, I am changing direction and
| moving on. Later this year, I start as an Associate
| Professor teaching journalism as part of Harvard
| University's Faculty of Arts and Sciences."
|
| Nobody is joining Harvard's FAS as as an Associate
| Professor without a PhD.
| evanelias wrote:
| I realize this is uselessly pedantic, but Harvard's Division of
| Continuing Education (Extension School + Summer School) is
| technically under the FAS umbrella, alongside Harvard College
| (undergrad) and GSAS (graduate arts + sciences). ~15 years ago
| I worked for FAS as a web developer, and the software my org
| developed was used by all 3 of these schools. Wikipedia
| confirms FAS is still organized in this way:
| https://en.wikipedia.org/wiki/Harvard_Faculty_of_Arts_and_Sc...
|
| That said, yes it's extremely misleading for a DCE instructor
| to call themselves an FAS professor. This sort of thing does
| happen at all top tier schools' extension programs, though far
| more often it's done by students rather than instructors.
| pomian wrote:
| That's an intense level of con. Timed with the pandemic, it could
| have been hard not to fall for. I hope there is a follow up on
| who pulled it off. Did the perpetrators know the victim, did they
| send more of these "letters"? The con seemed pretty specific for
| a certain target. A lot of work to pull off. Also wonder if, and
| hope, Nidhi got her old job back. With a great story.
| scotty79 wrote:
| It seems more specific to Harvard. I wonder if the documents
| she was given by scammers were just believable or accurate. If
| they mirrored actual Harvard recruitment process then it's
| possible that whoever did this wokred or applied there.
|
| Or maybe it wasn't about the money? Maybe she was targetted
| specifically for her previous roles and knowledge?
|
| Attack was very sophisticated.
| alisonkisk wrote:
| There is no "Harvard recruitment process" for adjunct
| lecturers at the Extension school. People beat down Harvard's
| door for jobs.
|
| Story is very fishy.
| foolmeonce wrote:
| I wouldn't find it suspicious if some professors preferably
| refer people who speak on the campus over the database of
| spontaneous CVs, and there is a process regardless of how
| it initiates.
|
| I think it is equally easy to imagine that she made it up
| (and pressured co-workers to lie?) to falsely claim harvard
| credentials with a good out as it is to imagine that a
| political organization wanted to discredit a journalist and
| get her to resign, probably expecting her to go quietly.
|
| Since politicians are being given special access to
| advanced phishing, I think it is prudent to treat the story
| as real. How can this not raise demand for similar attacks
| using software from the US/Israeli/Italian/etc firms that
| specialize in state sponsored crime?
| ghaff wrote:
| >Timed with the pandemic, it could have been hard not to fall
| for.
|
| It didn't start there though. The offer letter supposedly came
| in January 2020 when things were perfectly normal in the vast
| majority of the world; I was traveling around Europe without a
| thought of pandemics at that time.
|
| It seems a _little_ weird that there would be a job offer after
| just a 90 minute phone interview. And moving halfway around the
| world seems a pretty big deal and one would think someone in
| that situation would be looking for a bit more motion on the
| logistics. On the other hand, we 're talking Harvard _Extension
| School_ and she 's in India so maybe not a complete red flag
| especially given she had some apparent prior contact with the
| school. But certainly the pandemic allowed them to string
| things out for whatever reason.
|
| It does seem as if there are different stories floating around
| though.
| 3327 wrote:
| TLDR: i was a suckered into quoting my job and as a journalist
| failed at the one job i am supposed to be good at- Getting the
| truth in a story. I quit my job, look like an idiot so I write
| this click bait piece to grab attention.
___________________________________________________________________
(page generated 2021-01-16 23:01 UTC)