[HN Gopher] Spear phishing with Slackbot for fun and profit
       ___________________________________________________________________
        
       Spear phishing with Slackbot for fun and profit
        
       Author : roosgit
       Score  : 10 points
       Date   : 2021-10-27 08:26 UTC (14 hours ago)
        
 (HTM) web link (ericwbailey.design)
 (TXT) w3m dump (ericwbailey.design)
        
       | chitowneats wrote:
       | Stopped reading at the suggestion that "white, male" users are
       | somehow more technically illiterate than other individuals.
       | 
       | With any luck, this style of insufferable faux self-deprecation
       | will not be fashionable with the next generation.
        
         | srinivgp wrote:
         | > we'll need to identify important people with both a high
         | degree of importance but with a low degree of tech literacy,
         | i.e. your average white, male C-level executive
         | 
         | From this, you think the author is suggesting that white male
         | users are more technically illiterate than other individuals?
         | Your detectors are tuned for too much recall.
        
       | paxys wrote:
       | The problem is real, but all the presented solutions are useless.
       | Every user name, description and profile picture check can be
       | bypassed to create a close enough approximation that average
       | users wont dig further into. And the kind of people who would
       | enter passwords in Slack when prompted by "Slackbot" would just
       | as easily fall for "IT Security Bot" or someone pretending to be
       | their manager.
       | 
       | The real problem can be condensed into - how do you prevent your
       | employees from getting phished? And well, if you had a solution
       | to that you would be worth many billions of dollars.
        
         | user3939382 wrote:
         | > how do you prevent your employees from getting phished?
         | 
         | Security Awareness Training. Preferably with automated tools
         | and continuous. KnowBe4 is the platform I've used but there are
         | others.
        
         | r00fus wrote:
         | You can't eliminate the problem but you can put up defenses.
         | One way is a constant internal advertisement campaign that
         | highlights these dangers and possible solutions. Another is
         | essentially constantly pen-testing your workforce. Finally,
         | make it fun to have an IT security mindset by hosting fun
         | activities like a capture-the-flag game.
         | 
         | All of these solutions require process and manpower, and are
         | not automated solutions.
        
       ___________________________________________________________________
       (page generated 2021-10-27 23:01 UTC)