The issue is that people’s egos get bruised when they fall for it, and they’ll very quickly get management on their side that certain ones are unfair, as if phishers give a shit about fair.
What I really love is how my workplace uses some man in the middle crap to replace every link in every email with a new one redirected through our cyber security link scanning product, so now there’s no way to check the actual link before you click it since they’re all just like garbagesec.com/4a12c89e7f now.
But real phishing emails will have the same treatment as normal emails making them harder to detect. Sounds like a really bad system that probably doesn’t offer any advantages over a pihole.
At work, we use Safe Links in Microsoft Defender so examining the URL of a link in an email was always a pain, but Microsoft actually made a useful change recently. Now when I over over the link in Outlook, it displays the Original URL without all of the Safe Links gibberish. The link itself still goes through Safe Links, but the hover shows me the destination URL. I was pleasantly surprised when I noticed this.
We were doing that, until our infosec team needed to justify themselves, and decided an easy win would be to pay another vendor even more for the link protection that was already included in our Microsoft licensing.
The issue is that people’s egos get bruised when they fall for it, and they’ll very quickly get management on their side that certain ones are unfair, as if phishers give a shit about fair.
What I really love is how my workplace uses some man in the middle crap to replace every link in every email with a new one redirected through our cyber security link scanning product, so now there’s no way to check the actual link before you click it since they’re all just like
garbagesec.com/4a12c89e7fnow.Our IT solution to that was to MITM all the links except for the phishing tests. So anyone savvy enough to realize that always passes.
Ours is exactly the same as this lol. The joke is we are an IT firm so everyone except from sales and hr easily detetct it.
But real phishing emails will have the same treatment as normal emails making them harder to detect. Sounds like a really bad system that probably doesn’t offer any advantages over a pihole.
Ours seems to set a header like X-Phishing-Test on the email so it’s trivially easy to get them right every time
In my experience, its usually upper management that fails the phishing attempts.
At work, we use Safe Links in Microsoft Defender so examining the URL of a link in an email was always a pain, but Microsoft actually made a useful change recently. Now when I over over the link in Outlook, it displays the Original URL without all of the Safe Links gibberish. The link itself still goes through Safe Links, but the hover shows me the destination URL. I was pleasantly surprised when I noticed this.
We were doing that, until our infosec team needed to justify themselves, and decided an easy win would be to pay another vendor even more for the link protection that was already included in our Microsoft licensing.
Yours too? I hate it. I can’t scan the URL and it drives me crazy. You just took away a way to identify a scam attempt.