this post was submitted on 20 Sep 2026
45 points (95.9% liked)

Technology

88187 readers
3961 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
top 11 comments
sorted by: hot top controversial new old
[–] red_tomato@lemmy.world 38 points 3 days ago (4 children)

IT department: ”A clear telltale sign of phishing is the sense of urgency. Official IT department email will never panic you into clicking strange links”

Also IT department: ”YOUR PASSWORD IS EXPIRING IN 24 HOURS!!! CLICK THIS STRANGE LINK NOW TO RESET YOUR PASSWORD!!!”

[–] kn33@lemmy.world 8 points 2 days ago

We simply don't expire passwords regularly. We have Entra require a reset if it sees something suspicious. Other than that and manual "reset because suspicious", your password can last forever.

[–] 1995ToyotaCorolla@lemmy.world 5 points 2 days ago

We did 30 days, 15 days, one week, and 24 hours. And still, we'd have users get locked out for not changing their password or calling us in a panic because they only saw the 24hr notif. We switched over to only requiring changes when entra saw something fishy, which definitely lowered stress levels.

[–] wiccan2@thelemmy.club 9 points 3 days ago

24 hours, my IT department sends them out at 28 days!

It's so stupid, and they still write the email as if it's happening immediately.

[–] Cocodapuf@lemmy.world 3 points 3 days ago (1 children)

Exactly right. And the reasoning here is that the IT department is in no rush because they don't care if your password expires, so what.

At some point the password will fail to work and you'll be prompted to pick a new one. Either you'll update it and log in, or you won't, IT doesn't care.

[–] W98BSoD@lemmy.dbzer0.com 1 points 2 days ago

Wait, IT was supposed to care at some point?

[–] lemmydividebyzero@reddthat.com 26 points 3 days ago

My most relevant experience: A colleague sent me a paypal link that allows me to accept money. Nowadays, I know that it was legit. But instead of paypal.com, it was something like py.pl?code=abcdef or p.pl?code=abcdef or whatever...

Thanks, Paypal!!. Clicking the shortened hyperlink did not save me any time, but it wasted multiple minutes for me to research whether the domain was a scam or not.

[–] BlueOysterCultist@lemmy.zip 8 points 2 days ago (1 children)

People report official HRemails and emails from our cybersec department all the time. No links or attachments in them, clearly internal email because it’s missing the “external” banner, and it’s just general notifications.

Most people don’t understand what makes an email suspicious. They just report anything (or nothing) without actually thinking

[–] shrugs@piefed.social 5 points 2 days ago

Once a manager asked my, why the link in the mail from his wife doesn't work.

the mail was in english, he and his wife are from Germany.

"Do you usually speak english with your wife" I asked suspiciously. "No...why?" he said.

you can not relay on people using common sense... you can not fly with this superman costume

[–] MajinBlayze@lemmy.world 4 points 2 days ago

My favorite is urldefense, which replaces all links passing through exchange with links that look like phishing links

[–] deliriousdreams@fedia.io 4 points 3 days ago

Meanwhile my IT department set up protocols that are flagging emails I sent to myself as scams. Mostly photos that failed to upload to the sharepoint from my work phone that is already authenticated and verified. Nice work, guys.