From 2024, but funny to read…

What makes this situation so ridiculous is that while we’re all watching for scammers attempting to imitate legitimate organisations, FedEx is out there imitating scammers!

  • SpaceCowboy@lemmy.ca
    link
    fedilink
    English
    arrow-up
    69
    arrow-down
    1
    ·
    1 day ago

    The mentality around online security now is to push the responsibility onto someone else instead of investing any real effort into it. So you need to be aware of phishing scams, but the company isn’t going to make any kind of effort towards it. That’s on you, not on us!

    Microsoft is really terrible about this. They have at least 20 different domains and many of them ask you to enter your credentials into them. Usually you’re redirected to something like login.microsoft-online.com or something like that and enter in your credentials into that. Always seems like a phishing thing… why wouldn’t it just be login.microsoft.com? I’m guessing within Microsoft, it’s probably was a pain in the ass to get whatever department in MS that controls the microsoft.com domain to set up a subdomain. So instead ever department registers a domain that they can control. The end result is you’re dumping your credentials into random looking domains, then downloading and installing software from other random domains.

    They just don’t really care as long as there’s no legal liability. You’re data gets compromised because you didn’t notice that you put your credentials into online.microsoft-login.com instead of login.microsoft-online.com, that’s your mistake and no one can sue microsoft for it. As long their negligence doesn’t meet the legal definition of negligence, they’re not going to put an any kind of effort.

    Anti-phishing training could be so much better… “don’t put your credentials into anything other that *.microsoft.com”. But since these companies won’t make any effort, anti-phishing training amounts to “Just be careful or whatever LOL!”

    • billwashere@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      10 hours ago

      I’m guessing within Microsoft, it’s probably was a pain in the ass to get whatever department in MS that controls the microsoft.com domain to set up a subdomain.

      I’ve had to deal with shit like this personally so I guarantee that was at least one reason. The departments that control the domain treat it like some sort of power trip and make it hard to do the smart thing.

    • Evotech@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      10 hours ago

      Microsoft is just a web of legacy software mixed with modern shit. Its a web of stuff that one human just cannot comprehend. Sp yeah

    • 🌞 Alexander Daychilde 🌞@lemmy.world
      link
      fedilink
      English
      arrow-up
      19
      ·
      1 day ago

      You’re data

      Bad grammar is the hallmark of a scam. THIS COMMENT IN A SCAM, PEOPLE!!! DO NOT READ!!!

      ;-)

      I think you’re spot-on regarding those domains. People trying to make things work and fighting (and losing) against internal pressures, making the situation ten times worse.

      For years, anti-phishing training sucked most places - I suspect it still does most places - but my previous employer actually got a better one in the last couple of years before I left. Most phishing training just says “Don’t click links from sources you don’t trust” and doesn’t teach you what to look for.

      To me, understanding how URLs work is essential. Being able to identify the actual domain is critical, but also at least being able to identify when the parameters start is also critical. But that fails when companies register weird domains or use third-party shorteners and things like that.

      The linked article is a fantastic example of the worst legit comms I’ve seen. Absolutely looks scammy all the way through.