this post was submitted on 20 Sep 2026
389 points (98.0% liked)
Technology
88163 readers
2504 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
With how much effort is being put into phishing awareness and training, some people/companies still put zero effort into their communication.
Duting a lengthy process that involved an attorney, I got an email from a firstnamelastname(at)yahoo(dot)com, with no introduction, no mention of my name, a misspelled address, telling me about an appointment at another address that was... screenshotted from a website and pasted as image. Looks sketchy AF by any measure. Nope, that was a real email from a paralegal.
Filed a helpdesk ticket at work. Get a Teams message from " (external)", asking me my company machine ID in bad English. Responded with "you are helpdesk, do you not know this?". After a few repeated requests for the ID and not answering any of my questions, I just stopped responding.
The head of my IT department once asked me to send him an AWS root password over email because there was an issue with billing on the account.
Another manager told users to just bypass the certificate errors on a new web service.
Multiple times I've had people tell me over teams to do all kinds of weird things to work around security errors.
It's a weird thing where people in IT think the security rules are for everyone else and not for them. And it's just laziness. I wind up doing all of the work to set everything up so the user is going to subdomain.[my company's domain] and the cert is valid and if it's an internal service, use kerberos to validate the user so they don't even enter a password.
The goal should always be that the user sees zero red flags when using a service. But a lot of people are too lazy to implement what's needed so eliminate all of those red flags and instead just send out a message to tell people to ignore them.
Yeah, there were two IT techs at one company who routinely asked for user passwords, in part because some of the software we used require setup in the user account. I'd say no, but I was on a few reply all emails where others provided their password to everyone on the email.
I forwarded those emails after the IT manager after the company email server got blacklisted by a client for our emails being used as an attack vector to phish.