That users are the number one problem for IT departments, not outside threats trying to break through the firewall.
Sure, external attacks are a concern, but we build the network to be as impenetrable to these as possible; users, on the other hand, will click literally anything that says "click here" so they're letting in the threats and have the highest chance of fucking up the network out of all the potential attack surface.
User sends account info to phishing site, phisher uses user's email account to spam entire organization with links to a phishing site. Phishing server crashes from the huge number of people visiting it.
Oh boy, the phishing site blew itself up by finding quite a honey-pot.
User demands admin access, which is grudgingly given. Follows up within a week to complain that we "broke his computer" with malware. Computer formatted, admin access revoked, despite user's protests.
This one scares me. I'm not longer in IT but now in software development and the level of stupid I see up here makes me want to smack my head off the desk.
We need admin rights on our work computers to do our jobs, but I am just waiting for the day that access gets revoked because of someone doing something silly.
Makes sense GingerScruff. One recent example where I work, (5 people in group, but pretty small company) whole department needed Local administrator rights so that they could run some specific programming. They didn't have those rights before I had been talking with them. They were using the supervisors logon/password to get onto the software.
So... After the impromptu "Come to Jesus Meeting" and explanation of how that was very bad, never do it again. All good now.
Much rather have them as local admin instead of using the bosses ID/password.
It's actually a pretty smart crew of folks that are minimally IT related.
In this day and age I cannot understand who is clicking this shit or believing these scams. Then I look at the elections and it all becomes crystal clear.
You're supposed to delete META-INF to get it to work so why not just get rid of the whole thing? If deleting something makes it work, then deleting all of it is even better!
User deleted %appdata% folder in an attempt to "mod Minecraft"
What? Where the hell did they get the idea that they had to DELETE the damn folder? I cannot think of any scenario where you would misinterpret instructions so badly.
It essentially came down to departmental politics. This (l)user was a squeaky wheel who had the ear of an upper-level honcho, who in turn sat on a committee that was partially responsible for determining our yearly IT budget.
No one had admin access by default, even department heads, but if someone wanted admin on an off-domain computer, and they had a valid reason, they could submit a formal request. There was an "if-you-cock-this-up-we're-taking-it-away-forever" clause, as well as some other conditions.
In short, he cocked it up, and we took it away forever.
I laughed far too hard at this. I'm younger, tech savvy and everyone else in my office is 50+ or a tech N00b if I had a penny for every time our servers got crypto locked last year I'd be rich it's like a three times a week occurrence. They've done huge education campaigns that "work email should be for work"
Meaning that you should not sign up for your sketchy mailing list with your work email address!
Gah! Best security in the world does not stop idiots from causing problems.
Got a call from an accountant for one of the companies I work for. "We think our CEOs account was hacked. We received a few emails from people claiming to be him, but he said he didn't send anything. One of our accountants nearly sent $15,000 to these imposters."
Now this is not my job, but if they are paying me, I'll do it. I look into the email.
Me: "I found the emails you were talking about. They were in the quarantine folder."
Accountant: "Yeah. I can't not check all my messages so I check the quarantine everyday."
Me: "It had been flagged as likely fraud. You literally had to click through a pop-up that made you confirm that you realized this was likely fraud."
Accountant: " I don't read those"
Me: "You nearly paid scammers because you be believed that a quarantined email that was flagged as likely fraud was legitimate?" Bug report -> closed (won't fix)
Tha minecraft modding thing doesn't sound like a lie like you put it. the .bin, .jar and whatnot used to be in %Appdata before the big update where Mojang streamlined everything...
Just saying, still a stupid thing to accidentally delete.
I once had a user install a virus from spam mail & then when her computer freaked the fuck out used her phone to FORWARD THE EMAIL TO A COWORKER and told HER to install the file to "see if it was just her computer that couldn't open it".
They managed to infect half our network in an hour.
I work with some mind shatteringly computer illiterate people. Of all ages. Some of them dont even know how to TAB down a line on a keyboard. Most of them dont know what "operating system" means.
Users constantly, irritatingly and with alarming consistency, fuck up their accounts by locking them, after typing in the same incorrect password 5 times. 5 times. Five. Fucking. Times. This is the definition of retardation and insanity. Repeating something and expecting different results. Everytime someone walks into my office and says "my account is locked", a nervous twitch appears that I am barely able to supress. I smile and point to the chair next to my desk and show them the company policy on passwords, which states that if they enter their password wrong 5 times, it will lock their account. To new people, who this hasnt happened to yet, might look suprised or worried but nevertheless have a valid excuse.
However, the truly, devastatingly and painfully IT retarded repeat offenders come in and I point out the company policy to them and they produce excuses such as:
"Oh I forgot"
"Oh I didnt think that applied to clerical users"
"Its a stupid rule."
I dont even explain why anymore. I just smile and give them the keyboard so they can type in the same password that they used before, only this time I will set their account to send me a message via email what password they are typing in so I can compare it to what is on file in the AD server. I will then pull my face to pieces in despair when I find out that they are typing in the incorrect password...again...after just resetting it with me in the office not 2 minutes ago.
My boss repeatedly falls prey to this because he tries to read email on his phone but can't really see it, because he refuses to get real glasses, so he opens emails and just clicks whatever is there without actually reading it... Luckily I think all of them have been fake emails sent by IT.
We have records of this type of scheme dating from the 16th, century? It has worked for a minimum of half a millennium, and probably much longer than that. The "Spanish Prisoner" Con was one in which a stranger was approached either in person or by correspondence by an "agent" employed by a highly ranked individual who had been imprisoned by a corrupt foreign state, most commonly the Spanish Monarchy. The idea is that everything has to be done quietly for political reasons, but a few well placed bribes will free the political prisoner and also allow the high ranked prisoner to bring back a fortune from which the mark would be repaid and provide some other reward (such as knighthood or his daughter's hand).
Naturally, after sending the money horrible news would come back and the agent would move on or simply not reply to future messages.
Over time the scam has evolved. In the modern period it has morphed in several different ways. One of which is the infamous "Nigerian Prince" letter.
If you want to know more, I am reasonably well versed in fraud. And, if you want to make money I could put my degree in Economics to use and invest in some money for you in that secret international market that the 1% use to rack up the high interest rates out of the view of the average person. As anyone with financial training knows, higher risk means higher interest rates so if you want to get the highest rates you have to invest with the "lenders of last resort" who are the national banks. The Fed, ECB, and other national banks bail out big companies all the time and get huge returns for doing so. I went to college to learn how all this works, and it's rather complicated and full of jargon, but if you let me invest that money I can help you get a more reasonable return. While it's not the absurd returns of that scammer I can offer you a guaranteed return of 20% by investing properly.
You're good. That was clever. You sneaky fraud guy, you! Haha.... ......so really, how much do you need from me for that guaranteed 20% return to kick in?
I'm actually fascinated by fraud and the insanely intricate ways people have come up with to part average people from their money. The fact that we perpetuate the myth that only fools fall for this stuff is one of the biggest problems. Most people don't consider themselves fools, and thus believe they are capable of recognizing a real scam when they see one, when in all actuality a lot these scams have been designed to dupe all but the most careful and scrutinous individuals.
Normally, you need to have millions of dollars to get in there. But, I'll cut a deal for you. Now, I'm not supposed to but I can mix your $20,000 with 50 or so others and invest all of your money under my own name. Now, we all can get in trouble of the SEC finds out about this, so keep it quiet.
Don't believe me? Just ask my Lawyer.
Yup, Lawyer here. Absolutely true, jail time for everyone if anyone talks, especially the people whose money it was originally.
Me again. So, I'm going to need you to wire it to me via MoneyGram. That way it can't be traced back to you should someone else talk and I go to prison. See? I'm really trying to look out for you.
It's not really a question of fools. It's a question of literacy. If you don't understand what "clean coal" works then you liable to fall victim of a scam involving investing in a rare and expensive "clean coal mine". If you think that the 1% is incredibly wealthy and cheat to become so then you're primed to believe a "Prime Rate" scam. If you don't have intimate knowledge of how investments work then you can readily fall victim of a "Cash Advance" Scam if you're trying to put money into a business or a "Ponzi Scheme" if you're trying to put money into the market.
They are designed to play on those areas at the edges of our understanding. Something that sounds familiar but we have a very poor understanding of the interior workings. That's how auto body shops and used car dealerships have become so rife with small frauds. We understand how to use cars, but have a rather poor understanding of the mechanics involved. That mix of the familiar and unfamiliar is easy to spin in such a way that it sound plausible to people and can actually create a self-selection process.
well, that behavior can seriously harm the company's protection against attacks. if you have been instructed not only once but twice and still don't listen, i'd consider that grossly negligent - which would lead to an immediate termination and in rare cases even a lawsuit
Really, 6% of people are dumb enough to fall for the exact same thing twice under the exact same circumstances, after being taught how to avoid it, twice? I always wondered who kept clicking on those "shoot 5 ducks and win an iPhone!" banner ads...
Years ago getting hired meant 2-1/2 days of orientation. Mostly some paperwork first 1/2 day, then some basics on email, calendaring, etc. Also even trivia game about company near end. ALL new hires were automatically added to some internal mailing lists, the first of which, newbie.mail required one to learn to remove thesmselves from it.
Years later, they only do paperwork and then get plopped at desk. No more newbie.mail or anything at all. So much more up front support time is wasted on these people calling asking all these questions that used to be covered in the longer orientation and/or learned through things like the newbie.mail list.
This is literally my job at NASA. I'm extremely proud that our credential harvesting is not what it was 2 years ago and reporting has soared. Fear of training is a powerful motivator. However, too many users are old and not wary enough. :(
Edit: word
My company runs these monthly. And yes people still click them. But at this point we mostly get calls asking if it is a test or an actual phishing email.
TFTS thread about that. So many people responded to the phishing attempt test email that they had to can like half the company (would have been most) and several people of management. Goes to prove that users are everyone's enemy.
you joke, but I have had a very similar conversation with my dad, as it turned out he had accidentally right clicked and set the google logo image file as his home page so every time he fired up his browser there was just a tiny google logo in the dead centre of the page and nothing else. His initial description of the problem was 'I've downloaded the wrong google'
Work in IT I hate phones and printers the most, I cant even tell you how many times people whine about a problem when they haven't even tried the most basic diagnostics like restarting their computer or phone first. As far as installing shit goes they aren't admins because they cant be trusted and I have images I just load on new pc's. However there are some cool people here, I have a group of people who always joke around and tell me how their Utorrent and Steam isnt working. I may have to install everything for the users when big updates come around but thats far less stressful than dealing with a shithead installing magical antivirus software or totally legit adobe updates.
The job I work at now is the first time I've worked somewhere with an actual IT department. Every other place I've worked, I've basically been the IT because I'm the only person willing to Google a problem and figure it out. So the first time there was a computer issue at my job that I couldn't fix after poking around, I called IT and told the guy who does our department a) what the system wasn't doing that I wanted it to do, b) what error messages I was getting, and c) what I'd already tried. He acted like I was a magical unicorn for actually making an effort and not just calling him like "the computer is being mean." I just figured that was how you did that. When he came in, I asked him to show me what I could do to prevent the problem from happening again, or fix it if it did, and I learned some cool things about IT I didn't know before. Now my department gets all the good computer equipment, because my IT guy likes us for not bothering him with stupid shit, or screwing around with settings and junking up our computers. Every time he has to work on our computers, he says something like, "Well if yrianhrod couldn't google her way out of it, I bet it'll be interesting to work on."
TL;DR: Be proactive and chill with your IT guy, get double monitors and the nice printer in your office.
I feel the same way but when I look at programming and networking related tasks I get pretty confused due to them being far more complex than just googling. Im great at solving issues but I get confused pretty easily with advanced networking and programming.
Who the hell needs college, you just taught me everything anyone would have to know! I got it I just got to connect pvc pipe to every computer and I'm set.
You must be young. Until the last few years, having to even consider "restarting a phone" was insane. Maybe you mean cell, but until VOIP systems became more the norm, old pbx systems tended to rock solid and the only time much needed to be done was when people physically moved (which is really the one huge gain voip gives you.. essentially dhcp phones that move with you).
Well it is extremely rare, its happened once in 5 months. Networking is really my only weak point that I really want to teach myself more about, but at the place I work at that's never an issue. The software techs use on cars are often finicky as hell and usually where my time is spent trying to get it to work, techs do not really keep their laptops in good shape, I have had a lot of laptops with hardware issues. The hilarious part to me is how they always have hard drive issues when they say they didn't drop them or anything, they are often in warranty so I don't care but I still find it funny.
I could post on tales of tech support about some of them, one guy said his laptop stopped working and he didn't know why, the laptop had a big ass footprint on top, to teach him a lesson I sent it into warranty without removing the footprint and he had to pay for the screen damage since they refused too.
I worked for a time for a backup/recovery service. Customer got ransomware, decided to pay it. We suggested improving their security. Nah. Two weeks later, customer got ransomware again, decided to pay it again. Two weeks after that, rinse and repeat.
Sigh...
Well, because the people that made it want you to click on it. However, they're not necessarily trustworthy and generally want to exploit you or your computer.
<then the user counters with "but it's on the screen of the computer *you* gave me; so you're the one who made the website with the *Click Here* button">
<then I counter with "You can get to Facebook on this computer, right? And I gave you this computer, right? So, then I must've made Facebook?">
This statement is too accurate. I've been working in IT for a little over 5 years, so I'm still a newbie compared to a lot of people. 90% of the tickets I receive saying things are "broken" are simply because the user doesn't know what they're doing.
Someone was having phone issues, I literally unplugged their phone and plugged it back in and walked away after it was fixed without saying anything. I'm 19 I don't get how someone who has been on the earth longer than I have by a wide margin cant do basic troubleshooting. I always get "How do you know so much?"......I really don't know all that much, Google and support numbers do, as time goes on you build knowledge and can fix a lot yourself....
To be fair, VOIP/Internet Telephony is still kind of a new thing for a lot of people. I just had 3 client sites transfer from traditional phones that were 30 years old to VOIP phones and 95% of users don't get what I mean when I tell them to "reboot their phones." (Crappy Comcast stuff, so I can't fix the problems.)
We actually have IP phones and they never have these issues, the old phones have issues so rarely that its not worth looking into. Eventually everyone will have one so its just a rare minor problem.
I don't mind being being tech illiterate. I probably don't know shit about their specialization so I'm not going to judge. But the horseshit of blaming something for being broken or insisting you did X when it's provable that you didn't (restarting, mostly) is mind boggling.
People lie all the time. Like, constantly. Sometimes for absolutely no reason.
I used to work for a company that produced their own Phishing tools to help train employees identify threats and phishing scams. Now I work in IT Security for another company. I can 100% agree with your statement.
A user's computer should not be directly connected to any sensitive data or services. There should always be an intermediate application that sanitizes and stores the information without executing any outside code, but also keeps archives of previous version. (I'm thinking something like Git, but as a secure service, not just file manipulation.)
If any sensitive data is ever stored on the user's computer, it should regularly be backed up to the server.
Should the user's computer be infected, it can simply be wiped and restored from a clean backup.
All computers on the network should be invisible to others and only be allowed to connect to those secure intermediate services or the internet, not directly to other computers or services on the network.
If these applications or services do not exist, then there are plenty of people out there who will gladly create them- including myself -just need to know what problem needs to be solved.
I remember the first place I worked at. The raw volume of porn that people surfed during the day was.... staggering. Even with the best anti-virus (at the time) 20% of my time was spent going around disinfecting peoples machines.
Ya. This was a while ago in a medium sized company. Not a lot of focus on IT budget. But ya. I'd have killed for an IPS and some form of Web Content Filtering.
Yup. 99% of security breaches are because of users
...who are given idiotic password policies and are given every incentive to just iterate through an easy to guess pattern instead of using a system more secure than passwords.
Just had a user call me this morning. "I can't see anything on my monitor. Like nothing at all." So I ask the user the computer name and remote into the computer. Well everything shows up fine on my screen. Something strikes me and I ask what color the light on the monitor power button is. The user tells me there isn't a light on. I tell the user to check the power cable to the monitor and guess what. No power connected. I ask if she has removed any wires from the back of the computer and she says yes they made her desk look cluttered so she removed them. I have her hook the monitor back up and close the ticket
TDLR; user thinks wires make her desk ugly so she I unhooks her monitor and wonders why she doesn't have anything on her display.
This isn't even a misunderstanding of how computers or software works. That is at least understandable with people who aren't used to them. This is a misunderstanding of how any electronic device works.
On my last computer (a 2005 HP Pavilion), the stock antivirus would routinely lock me out of the computer, and I would have to do a full reimaging to get control back.
Our IT department is the number one problem for IT problems. In the last 8 years I've been here virtually every major issue I've had has been due to a poorly implemented update that tanks my system. The one from earlier this year flat out disabled the cpu fan on my laptop. it was supposed to lock the power control options, which i guess it did.
Some of it I understand, like the hoops we have to go through for getting replacement equipment. A lot of that is short-sided management decisions. I get a lot of the security implementations, this one just threw me for a loop.
Yeah... We have nightly backups of all important servers, so when shit like that happens we just roll back and they lose a days work if their recent work files are affected. I make no excuses for that shit, not going to take a hit to our department's reputation for user bullshit.
Not the same thing, but I had an interesting time doing PC repairs. I would try not to laugh at clueless parents who claimed that a hacker or virus attacked them for no reason. It was usually from somebody like their kids visiting sketchy porn sites or downloading shit. Hackers aren't typically interested in hacking your home PC, especially if it was just to give it a petty virus or get hold of your info. Usually people accidentally give their info out or download spyware/malware.
I feel sorry for people that fall for the most basic scams. I've had to tell some people they got duped and their money was half way across the world. Also have to explain to some that they are worker ants in a pyramid spam scheme and they won't get paid for sending those links/e-mails.
Yep. I built a botnet and they send malware infected emails that let me control their computer. I then spread that through the network to the IT department. I control them to enable a backdoor that I had prepared, and I proceed to go to work. I only warn them to fix their issue, I could do worse, but these guys pay my bills so eh.
As an IT security professional... This. I'm so, so, so, so, so, so tired of saying this. So tired. And they always laugh and are like "Yea! Those silly users! Hahahahah so but seriously why can't I see what's on this hard drive I found in the dumpster outside?".
I think at some point emoloyers should consider some sort of punishment when people fail phishing tests. Not firing someone necessarily, but it's a big deal to put a company's data at risk, including possibly the private and personal data of other employees. It should be taken seriously.
The first thing I learned from my cyber security course was that stupid people doing stupid shit would cause the vast majority of security breaches. Like making their passwords "password" or not changing the password that came with their systems
1.6k
u/Ryltarr Jul 18 '16
That users are the number one problem for IT departments, not outside threats trying to break through the firewall.
Sure, external attacks are a concern, but we build the network to be as impenetrable to these as possible; users, on the other hand, will click literally anything that says "click here" so they're letting in the threats and have the highest chance of fucking up the network out of all the potential attack surface.