[HN Gopher] Spear phishing with Slackbot for fun and profit
___________________________________________________________________
Spear phishing with Slackbot for fun and profit
Author : roosgit
Score : 10 points
Date : 2021-10-27 08:26 UTC (14 hours ago)
(HTM) web link (ericwbailey.design)
(TXT) w3m dump (ericwbailey.design)
| chitowneats wrote:
| Stopped reading at the suggestion that "white, male" users are
| somehow more technically illiterate than other individuals.
|
| With any luck, this style of insufferable faux self-deprecation
| will not be fashionable with the next generation.
| srinivgp wrote:
| > we'll need to identify important people with both a high
| degree of importance but with a low degree of tech literacy,
| i.e. your average white, male C-level executive
|
| From this, you think the author is suggesting that white male
| users are more technically illiterate than other individuals?
| Your detectors are tuned for too much recall.
| paxys wrote:
| The problem is real, but all the presented solutions are useless.
| Every user name, description and profile picture check can be
| bypassed to create a close enough approximation that average
| users wont dig further into. And the kind of people who would
| enter passwords in Slack when prompted by "Slackbot" would just
| as easily fall for "IT Security Bot" or someone pretending to be
| their manager.
|
| The real problem can be condensed into - how do you prevent your
| employees from getting phished? And well, if you had a solution
| to that you would be worth many billions of dollars.
| user3939382 wrote:
| > how do you prevent your employees from getting phished?
|
| Security Awareness Training. Preferably with automated tools
| and continuous. KnowBe4 is the platform I've used but there are
| others.
| r00fus wrote:
| You can't eliminate the problem but you can put up defenses.
| One way is a constant internal advertisement campaign that
| highlights these dangers and possible solutions. Another is
| essentially constantly pen-testing your workforce. Finally,
| make it fun to have an IT security mindset by hosting fun
| activities like a capture-the-flag game.
|
| All of these solutions require process and manpower, and are
| not automated solutions.
___________________________________________________________________
(page generated 2021-10-27 23:01 UTC)