LOL
@nixCraft lmfao
everywhere else:
sent: give me your api key
received: no way, scammer
meanwhile at your prev enterprise
sent: dont share your keys
replied: okay, here is my key
If I've learned anything from IT its that there is a wild difference in tech literacy and security literacy.
I just got done spending two weeks learning enough JavaScript to be able to read our developers code because the security guy found out they were trying to set prices on the client side.
It tooK two weeks of explaining to the Devs, the B2B team, and the CIO and CMO why this is ACTUALLY REALLY BAD to let CUSTOMERS set PRICES.
@nixCraft a virus ran wild in a company inspite of email filtering.
Turned out, the filter did indeed work.
But the admin had opened the flagged attachment to see what‘s inside.
@nixCraft
I once got an obviously phishy email from work, and I was hovering over a link to see which phish trap site they were using.
And I accidentally tapped on my trackpad.
Damn it.
@nixCraft yeah, sounds about right. HR clicked on our last phishing test and provided credentials. All of them.
Time before that, all of our privacy officers did.
Endusers who are the least tech savvy called or mailed us with questions if it was legit.
Classic 😅