2024 LC Thread

Head over to Flatbush and go to Kings Plaza if you want a mall in NYC

That’s a 1.5 hour subway and bus ride from my neighborhood. I might as well go to Paramus. (I actually did take the bus to a mall in Paramus with one of my friends as part of a trip to the city I made during grad school. He was a little weird like that.)

Do you trust Nigerian princes more or less than you trust the management at your work? Do you want your employees thinking of you the same as you think of Nigerian princes?

Tweet blacks out the most important part. If this came from a corporate email account, employees should regard the chances of this being phishing as basically zero, unless they are also getting emails from IT that the whole company has been pwned. If corporate sent this from a deliberately shady, non-corporate account, they at least have a leg to stand on.

1 Like

Promising a bonus and then yanking it away was the big screwup here. Testing employees with a fake phishing scam doesn’t seem too unreasonable, I routinely get extremely sophisticated, targeted phishing emails.

1 Like

From addresses can be spoofed.

Stop checking your emails. The one weird trick to passing phishing tests.

8 Likes

there’s pretty good evidence that phishing training does have a pretty significant positive impact, but I seriously doubt this particular test has a better performance outcome than other stuff.

FWIW that particular test happened like 4 years ago.

Everyone should get the bonus…but the employees who failed the test should be given mandatory training and/or be placed in a PIP.

2 Likes

How big of a bonus before you’re justified in channeling your inner Luigi Mangione?

We have to watch monthly cybersecurity videos from Knowbe4 (usually only 5-10 mins and you can play them at faster speeds) and occasionally get suspect emails sent out to us that we’re supposed to report.

They’ve got to be at least slightly helpful, a lot of people are awful about security/falling for scams etc.

Getting a like from CaffeineNeeded and microbet on the same post? Straight to my personal “best of”

7 Likes

3 Likes

I am so strict about my work emails lol. I only look at my emails while I’m getting paid to work. People think that’s a reasonable policy, until they realize I don’t work typical 9-5 hours and it might be 6 days until I look at the email and respond at 2am. I also rarely get an important work email so I don’t check it much

https://x.com/CraigDMauger/status/1866464741520036123?t=E4m75QS6MZrS1KxjrelzyA&s=19

Carpetbagging mf stay in indiana. Dems gonna ratfuck a great candiate in mike duggan

Any e-mail coming from outside the organization can be marked as such and this can’t be spoofed. Still shocked at the amount of companies that don’t do this. Also phishing training is effective and can easily be shown to be effective as the amount of people falling for better and better designed attempts is clearly dropping in our company. In certain roles falling for them repeatedly will cost you your job.

You can train people to not fall for phishing emails without crushing their souls, that’s just a bonus…

Yes, but it seems like best practices these days is to have your email system say “THIS IS AN EXTERNAL MESSAGE” for mail that doesn’t come from inside the company.

Can’t blame him. He doesn’t want to Beto himself.

His permanent residence is in Traverse City, MI, which is his husband’s hometown.