Dull Men's Club
An unofficial chapter of the popular Dull Men's Club.
1. Relevant commentary on your own dull life. Posts should be about your own dull, lived experience. This is our most important rule. Direct questions, random thoughts, comment baiting, advice seeking, many uses of "discuss" rarely comply with this rule.
2. Original, Fresh, Meaningful Content.
3. Avoid repetitive topics.
4. This is not a search engine
Use a search engine, a tradesperson, Reddit, friends, a specialist Facebook group, apps, Wikipedia, an AI chat, a reverse image search etc. to answer simple questions or identify objects. Also see rule 1, “comment baiting”.
There are a number of content specific communities with subject matter experts who can help you.
Some other communities to consider before posting:
5. Keep it dull. If it puts us to sleep, it’s on the right track. Examples of likely not dull: jokes, gross stuff (including toes), politics, religion, royalty, illness or injury, killing things for fun, or promotional content. Feel free to post these elsewhere.
6. No hate speech, sexism, or bullying No sexism, hate speech, degrading or excessively foul language, or other harmful language. No othering or dehumanizing of anyone or negativity towards any gender identity.
7. Proofread before posting. Use good grammar and punctuation. Avoid useless phrases. Some examples: - starting a post with "So" - starting a post with pointless phrases, like "I hope this is allowed" or “this is my first post” Only share good quality, cropped images. Do not share screenshots of images; share the original image.
.
view the rest of the comments
Never heard of drive-by malware attacks? Malicious ads? Zero-click attacks? That link is Schrödinger’s zero-day ransomware attack, which may or may not exist. And there’s no way for you to know which it is, until after you’ve already clicked it. Sandboxing your browser is fine, but they weren’t testing to see if your browser would allow an attack to happen. They were testing to see if you would allow an attack to happen.
The actual method of attack (and any protections you have set up for your browser) is irrelevant, because they’re not testing to see if your browser is hardened. If they were going to do a software audit to see if browsers were vulnerable, you probably wouldn’t ever even hear about it. Because IT would handle it directly, via the access they already have to your company computer.
Tricking you into disclosing sensitive info is only one specific type of attack. The phishing link isn’t checking to see if you’d give info away. If they were testing that, they could do it in other ways, like a fake email from your manager asking for the info. No need to click a link to fail that test. But with the phishing link, you fail the test when you click it because it ultimately doesn’t matter what loads after you click the link. That link exists in a quantum state where every single piece of malware that ever did/will exist can load as soon as you click it.
To consider an employee clicking on a potentially malicious link as "allowing an attack to happen" takes a special kind of incompetence on the part of the IT (security) team.
If simply clicking a link compromises a system, that's on corporate IT, not on the user. As you say, "they weren't testing to see if your browser would allow an attack to happen". Because - in a corporate setting - if it would, they done fucked up. And if it wouldn't, then clicking a link alone is no problem.
I dislike that you incite me to respond to that because I don't want to insult you personally, but I have very strong feelings about this attitude. This particular, take from a corporate IT department, is moronic. If clicking a link to check where it leads compromises IT security, that is 100% the fault of corporate IT. That is what they must fix with firewalls and filter policies.
As an IT security responsible, if you push responsibility for single keypress actions to the user, you are an idiot, and a liability to your company's IT security, and you should not be allowed anywhere near a sensitive system or policy.
The role of IT security is not to set legal frameworks in which when a fuckup happens, a responsible person that is not them can be found. The role of IT security is to protect the intranet and users from external attacks, be it hacking or phishing or malware - and to protect the same intranet from internal attacks in the best way feasible. That includes a user intentionally clicking a link if that is sufficient to compromise intranet systems.
About the only thing you can make users responsible for is to not disclose information through phishing or social engineering attacks, and to not intentionally sabotage anything.
The point is to have multiple layers of protection. With users who are vigilant it's less likely for something to get through even if IT fails to filter out an attack.
Think of it like gun safety. Even though a gun is unloaded you don't aim it at someone.
No argument there - training cybersecurity awareness is fine, but singling users for clicking on a link alone is moronic. Most security fuckups in my experience result from stupid IT policies and rarely do the responsible admins / managers ever get flak for their fuckups.
In my experience (I'm not in IT), the IT folks only get recognized for fuckups. When they do things right nobody notices and thinks they're a waste of money, resulting in the company cutting back on their budget then freaking out when they're not equipped to do their job and something goes wrong.
Ok let me rephrase: IT management never gets the flak they often deserve.
But also there's a distinction to be made between competent IT and IT service contracts where the contract officers are corrupt and/or incompetent and then the service is awful as a whole.