Re: Phishing

Sep 05, 2024 Last reply: 1 year ago 13 Replies


I'm checking my "deflected" incoming mail to see if anything that


>*should* have been allowed through was mistakenly diverted
>(false positive).
>
>I see a fair number of phishing attempts on my "public" accounts.
>But, all are trivially identified as such.
>
>So, how is it that folks (organizations) are so often deceived
>by these things? Are users just lazy? Would it be more helpful
>to have mail clients make it HARDER to activate an embedded
>URL or "potentially compromised" attachment?
>
>Or, will the stupidity of users adapt, accordingly?

Outlook will apparently send anything through, even obvious phishing ploys.

More likely the ingenuity of scammers will adapt accordingly.

I got a "Your amazon account has been charged" call today. Caller ID gave a local number, just different last four digits.

I don't bother filtering email except at the server level where some countries can't connect inbound at all.

>

Making it harder to do things will likely mean that nothing gets done.

While most people who read this group can do that, most people cannot. Also have you tried doing that with a phone?

I usually answer local calls and calls from known numbers. Others may be answered if they start leaving a message, depending on the message.

Actually that's not quite true because at the server level I also have

formatting link
which works well.

I can't remember when I last got a message containing a dodgy URL or dodgy attachment. Unexpected attachments are always discarded. Sometimes I'll have a look at where a dodgy URL goes but most often it goes nowhere due to my outbound filtering.

I never allow an MTA to do anything with an exe other than discard it. If I have a need to send an exe it goes in a zip which is made downloadable.

It's a mail application, not an anti-virus filter.

Mail servers of paid ISPs are getting less responsible in that regard, also, no longer filtering spam 'for free'.

You're probably your own best mail filter.

RL

It has a tab for reporting phishing which says it helps them keep user' information safe. They seem to ignore the reports.

There are lots of things that don't work in Outlook.

Yes, I've had to set up my own filters, but I don't have access to the tools that Microsoft presumably has.

It's a mild chore, to review and delete the 60 or so spams and phishings per day. But what's granny down the block to do?

I am generally stunned how naive people can be. "But it came from a PG&E address and had a PG&E link in there!" ... "There is a customer service number on your paper statements. Did you call them about that past due accusation?" ... "Ahm, well, no".

When it comes to politics and elections it's even worse. "But he had such a nice smile!". Don't get me started ...

I've noticed that I get very little spam or phishing on Saturday or Sunday. Do bots get the weekend off?

no, that is when they concentrate on compromising servers.

Mine was a phone call. Heavy Indian accent, "This is the Windows company. We would like to help you solve a problem we have detected with your Windows"... me "Oh yeah, you are right, there are at least nine windows here that really need cleaning. Do you use Windex for that?"

I don't either but I could not resist to pull that prank.

I never give them anything.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required