Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

An email from Google with a bit.ly link? Hell no, I hope I won't fell from it in whatever situation.

I agree that any defense is far from being perfect, but IT professionals shouldn't fell for an unsofiscated attack like this even if you are no working in security. I am not even talking about a web developer.



And you would be wrong about that. They do. All the time. Spear phishing is still the most effective way for foreign nationals to breach US companies.

Now, there are two ways to deal with the situation. Demonize, or accept. The demonize/blame approach doesn't work.


> An email from Google with a bit.ly link?

The article clearly explains that "the bitly link was not directly visible in the phishing email, as it was an HTML-email."


Disabling HTML e-mails does not sound particularly unreasonable. There’s little additional benefit from them but a whole host of possible issues, least of all that suddenly your e-mail client has to deal with properly parsing HTML and you have to decide whether or not to load remote images and potentially execute JavaScript.


I've never read my email in HTML, mostly for security reasons such as this incident. For the rare occasion where an email doesn't render correctly, Thunderbird's "Show HTML" button works a charm.

Have I been able to convince a single customer (I run a computer services business) or friend to follow my lead? Nope, not a single one.


I have no idea why your post was downvoted. Your post is clearly correct.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: