SDF Chatter
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
The Picard Maneuver@startrek.website to Comic Strips@lemmy.world · 2 years ago

Hacking skills

startrek.website

message-square
87
fedilink
1.61K

Hacking skills

startrek.website

The Picard Maneuver@startrek.website to Comic Strips@lemmy.world · 2 years ago
message-square
87
fedilink
alert-triangle
You must log in or register to comment.
  • 🇰 🌀 🇱 🇦 🇳 🇦 🇰 🇮 🏆@yiffit.net
    link
    fedilink
    English
    arrow-up
    132
    arrow-down
    2
    ·
    edit-2
    2 years ago

    A lot of hacking is actually social engineering. It’s not hard to get a tech-illiterate person to give up their password, and that’s the softest target for an attack.

    • yokonzo@lemmy.world
      link
      fedilink
      arrow-up
      57
      ·
      2 years ago

      I prefer the old “drop a usb in the parking lot”

      • The Picard Maneuver@startrek.websiteOP
        link
        fedilink
        arrow-up
        41
        ·
        2 years ago

        Be sure to put a label on it that says “secrets!”

        • teft@startrek.website
          link
          fedilink
          arrow-up
          39
          ·
          2 years ago

          Nowadays you’d probably be more likely to get a hit by putting an “Anime titties” label on the drive

          • Viking_Hippie@lemmy.world
            link
            fedilink
            arrow-up
            39
            ·
            2 years ago

            Why would you drop a drive full of world news?

          • DragonTypeWyvern@literature.cafe
            link
            fedilink
            arrow-up
            7
            ·
            2 years ago

            I’m interested.

        • Billiam@lemmy.world
          link
          fedilink
          arrow-up
          10
          arrow-down
          1
          ·
          2 years ago

          Pick Me Up.

        • Dandroid@dandroid.app
          link
          fedilink
          arrow-up
          8
          ·
          2 years ago

          I prefer a label that says, “Warning: USB stick contains scary virus. Do not plug into a computer”

          • The Picard Maneuver@startrek.websiteOP
            link
            fedilink
            arrow-up
            4
            ·
            2 years ago

            I bet someone still would

            • chatokun@lemmy.dbzer0.com
              link
              fedilink
              arrow-up
              3
              ·
              2 years ago

              It’s what sandboxes are for.

              • Martineski@lemmy.fmhy.net
                link
                fedilink
                English
                arrow-up
                4
                ·
                edit-2
                2 years ago

                There are usb sticks that can kill your pc by getting charged and then discharging all the electricity at once to your pc so no sandbox will save you in situations like those.

                • credit crazy@lemmy.world
                  link
                  fedilink
                  arrow-up
                  3
                  ·
                  2 years ago

                  Me: Plugs USB into throwaway computer. Computer: dies. Me: “well that’s a pretty boring virus!”

        • xantoxis@lemmy.world
          link
          fedilink
          arrow-up
          8
          ·
          2 years ago

          Just put the CEO’s name on it and a very recent date. They’ll be dying to know what secret information the CEO was carrying around.

        • cheery_coffee@lemmy.ca
          link
          fedilink
          arrow-up
          5
          ·
          edit-2
          2 years ago

          deleted by creator

    • igorlogius@lemmy.world
      link
      fedilink
      English
      arrow-up
      25
      arrow-down
      1
      ·
      edit-2
      2 years ago

      the softest target

      Managment making notes

      All employes must be buff.
      Fitness trainings for everyone are now mandatory!
      Problem solved.
      
      • uis@lemmy.world
        link
        fedilink
        arrow-up
        6
        ·
        2 years ago

        Managment taking notes:

    • UnculturedSwine@lemmy.world
      link
      fedilink
      arrow-up
      24
      arrow-down
      2
      ·
      2 years ago

      Or even jaded tech savvy people. I work in IT and there have been a number of times that I have witnessed or heard about people who know better causing an incident because they’re burnt out or irate.

      • Sharkwellington@lemmy.one
        link
        fedilink
        arrow-up
        36
        ·
        2 years ago

        “Wait a second…I don’t give a shit about this company.”

        • illi@lemm.ee
          link
          fedilink
          English
          arrow-up
          17
          ·
          2 years ago

          This seems like there is an idea for a joke or a comic here somewhere…

      • hellishharlot@programming.dev
        link
        fedilink
        arrow-up
        9
        ·
        2 years ago

        Happy employees are less likely to be socially engineered? Wow shocker

      • cheery_coffee@lemmy.ca
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        2 years ago

        deleted by creator

    • CurlyMoustache@lemmy.world
      link
      fedilink
      arrow-up
      12
      ·
      2 years ago

      That’s a good point! I like the way you think! What is your password?

      • Frozengyro@lemmy.world
        link
        fedilink
        arrow-up
        19
        arrow-down
        1
        ·
        edit-2
        2 years ago

        It’s *******, what’s yours?

        Edit: that’s cool, Lemmy blocks it out!

        • rmuk@feddit.uk
          link
          fedilink
          English
          arrow-up
          10
          ·
          2 years ago

          Ah, cool, let me try:

          iWantToSuckFrozengyro’sToes69

        • credit crazy@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          2 years ago

          Oh so that’s why Lemmy sensors my f words

      • son_named_bort@lemmy.world
        link
        fedilink
        arrow-up
        16
        ·
        2 years ago

        hunter2

        • cheery_coffee@lemmy.ca
          link
          fedilink
          arrow-up
          3
          ·
          edit-2
          2 years ago

          deleted by creator

      • 🇰 🌀 🇱 🇦 🇳 🇦 🇰 🇮 🏆@yiffit.net
        link
        fedilink
        English
        arrow-up
        5
        ·
        2 years ago

        I am so sick of everyone asking me for my password with no spaces or capitals.

        • Sotuanduso@lemm.ee
          link
          fedilink
          English
          arrow-up
          6
          ·
          2 years ago

          W h A t I s Y o U r P a S s W o R d ?

      • BarelyOriginal@feddit.nl
        link
        fedilink
        arrow-up
        5
        ·
        2 years ago

        5

  • EmoDuck@sh.itjust.works
    link
    fedilink
    arrow-up
    95
    ·
    2 years ago

    Hacker voice: “I’m in”

    Looks at overly complicated industry software he’s never even heard of before

    “I’m out”

    • psycho_driver@lemmy.world
      link
      fedilink
      arrow-up
      43
      arrow-down
      1
      ·
      2 years ago

      “Looks like these guys have already been hit with ransomware.”

      • dubyakay@lemmy.ca
        link
        fedilink
        arrow-up
        30
        ·
        2 years ago

        So SAP.

    • SokathHisEyesOpen@lemmy.ml
      link
      fedilink
      English
      arrow-up
      13
      ·
      2 years ago

      Wait, I have an idea! Yes, just as I thought, I can overlay their proprietary operating system with this fancy looking graphical interface that resembles nothing and gain full control of their system. I’m back in!

      • Ignisnex@lemmy.world
        link
        fedilink
        English
        arrow-up
        12
        ·
        2 years ago

        That sounds like Grafana with extra steps.

        • SokathHisEyesOpen@lemmy.ml
          link
          fedilink
          English
          arrow-up
          9
          ·
          2 years ago

          I was thinking of the James Bond movies where they show hacking to be a guy wearing glasses looking for a glowing ball in a flashing GUI that he rotates around somehow by typing really fast.

          • MonkderZweite@feddit.ch
            link
            fedilink
            arrow-up
            2
            ·
            2 years ago

            So they have a fancy representation of … something with a hex table, that then transforms into a map of London given the right key?

  • twistedtxb@lemmy.ca
    link
    fedilink
    arrow-up
    75
    arrow-down
    1
    ·
    edit-2
    2 years ago

    We have these obligatory online seminars about web security /privacy at work.

    Turns out that for some reason, with Privacy Badger enabled, they appear as “passed” instantly. I never saw a single second of these endless seminars.

    I tried to tell the IT guy but he couldn’t care less and I suspect he didn’t even know what Privacy Badger actually is

    • DragonTypeWyvern@literature.cafe
      link
      fedilink
      arrow-up
      60
      ·
      2 years ago

      “Working as intended” - the dev who loves Privacy Badger.

    • emergencyfood@sh.itjust.works
      link
      fedilink
      arrow-up
      31
      ·
      2 years ago

      Or maybe he feels that these seminars are for people who don’t use things like privacy badger.

    • supercriticalcheese@feddit.it
      link
      fedilink
      arrow-up
      15
      arrow-down
      1
      ·
      2 years ago

      It seems like you don’t need Training then (:

    • pwalker@discuss.tchncs.de
      link
      fedilink
      arrow-up
      4
      ·
      2 years ago

      now I want to know what privacy badger is amd I’m too lazy to google it…

      • cheery_coffee@lemmy.ca
        link
        fedilink
        arrow-up
        4
        ·
        edit-2
        2 years ago

        deleted by creator

  • joel_feila@lemmy.world
    link
    fedilink
    arrow-up
    53
    ·
    2 years ago

    Its like the only accurate part of hackers

    • Naia@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      6
      ·
      2 years ago

      And sadly, hackers is like the most accurate hacking in any movie.

    • Zapp@sh.itjust.works
      link
      fedilink
      arrow-up
      5
      ·
      2 years ago

      Untrue, we also have a functioning Gibson screensaver.

    • teft@startrek.website
      link
      fedilink
      arrow-up
      5
      ·
      2 years ago

      The books that Cereal Killer pulls out are all legit also. The titles at least are all real books.

  • ArbitraryValue@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    47
    arrow-down
    2
    ·
    2 years ago

    We get fake phishing emails that are actually from IT and if we don’t recognize and report them, we get a talking-to. It’s a good way of keeping employees vigilant.

    • cynar@lemmy.world
      link
      fedilink
      arrow-up
      38
      arrow-down
      2
      ·
      2 years ago

      A friend (who actually works in IT) apparently has a good system at his company. It actually automates turning real phishing attempts into internal tests. It effectively replaces links etc and sends it onwards. If the user actually clicks through, their account is immediately locked. It requires them to contact IT to unlock it again, often accompanied by additional training.

      • zalgotext@sh.itjust.works
        link
        fedilink
        arrow-up
        4
        arrow-down
        2
        ·
        2 years ago

        Wait. So your friend’s company has the ability to reliably detect phishing attacks, but instead of just blocking them outright, it replaces the malicious phishing links with their own phishing links, sends those on to employees, and prevents them from doing their jobs of they fall for it?

        Sounds like your friend’s company’s IT people are kind of dickheads

        • lazyshit@sh.itjust.works
          link
          fedilink
          arrow-up
          10
          ·
          2 years ago

          I work at a company that does something similar; it can be annoying to deal with these fake phishing emails from our own IT, but a 10-15 minute training session if you fail is a lot less disruptive than what can happen if you clicked the real link instead.

          I consider myself a bit more tech-savvy than average, but I’ve almost fallen for a couple of these fake phishing emails. It helps me to keep up with what the latest versions of these attacks look like (and keeps me on my toes too…)

        • rbits@lemm.ee
          link
          fedilink
          arrow-up
          2
          ·
          2 years ago

          Well the company probably can’t detect them reliably, so wih the ones it does detect it trains them to avoid the ones that they can’t detect.

        • cheery_coffee@lemmy.ca
          link
          fedilink
          arrow-up
          2
          ·
          edit-2
          2 years ago

          deleted by creator

        • cynar@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          2 years ago

          It’s not every phishing email. I think it’s technically those that get through the initial filters, and get reported, but don’t quote me on that. Apparently it’s quite effective. They also don’t need to report every one. It’s only if they do something that could have compromised the company that causes a lock down. It’s designed to be disruptive and embarrassing, but only if they actively screw up.

    • grysbok
      link
      fedilink
      English
      arrow-up
      32
      ·
      2 years ago

      My last company did this. They’d also send out surveys and training from addresses I didn’t recognize, so I’d report those, too, only to be told they were legit 😂

      • hemko@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        3
        ·
        2 years ago

        Yeah this is a running joke at our workplace too. Only to be asked by some manager to do those week or few later

        • cheery_coffee@lemmy.ca
          link
          fedilink
          arrow-up
          1
          ·
          edit-2
          2 years ago

          deleted by creator

          • hemko@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 years ago

            For me (us) it’s simply because the security training emails are sent from some 3rd party service with sender email like fuckme-security@asshole.ml

    • SMITHandWESSON@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      ·
      edit-2
      2 years ago

      I send supervisor emails about stuff I’m not gonna do to my spam folder as well…

      “Did you get the email?”

      “Nope, sorry, it looked a little suspicious so I didn’t open and sent it to spam…”

      • average_internet_enjoyer@lemmy.world
        link
        fedilink
        arrow-up
        2
        ·
        2 years ago

        Basically you created a echo chamber at work where you can only hear what you want to hear

        • SMITHandWESSON@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 years ago

          😃👍🏾

          • average_internet_enjoyer@lemmy.world
            link
            fedilink
            arrow-up
            2
            ·
            2 years ago

            I just realised how you control reality at work and how much enjoyment you get… Until you are enjoying too much and get fired

            • SMITHandWESSON@lemmy.world
              link
              fedilink
              English
              arrow-up
              2
              ·
              2 years ago

              …but until then😈

    • HeyJoe@lemmy.world
      link
      fedilink
      arrow-up
      6
      ·
      2 years ago

      We do as well, except we only concern ourselves with the people who click them.

    • son_named_bort@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      2 years ago

      My workplace does this too. I can usually tell when the email isn’t a legit phishing email but an IT test though. Not sure how helpful that is.

    • Samsy@lemmy.ml
      link
      fedilink
      arrow-up
      4
      ·
      edit-2
      2 years ago

      That’s neat, will steal this.

    • GBU_28@lemm.ee
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 years ago

      Lol I don’t click shit.

    • frickineh@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      2 years ago

      We get those, but the sender email shows up as blahblah@employersname.kn0wbe4.compromisedblog.org or whatever. Literally the most obvious possible address. I’m always tempted to forward one to IT and ask if they’re serious with that shit.

      • ArbitraryValue@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 years ago

        Ours are the opposite: the sender’s email shows up as a normal name@company.com email. Gmail is supposed to warn when a return address is being spoofed like that, but I guess my company turned that warning off for these fake phishing emails. There’s still no SPF but I don’t check the SPF unless an email looks suspicious so I hope that that warning will work for real, sophisticated phishing.

    • xantoxis@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      2 years ago

      deleted by creator

    • XaeroDegreaz@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      2 years ago

      Same. Users who click on links get signed up for remedial training courses lol

    • fidodo@lemm.ee
      link
      fedilink
      arrow-up
      2
      arrow-down
      1
      ·
      2 years ago

      But if they’re recognized it means they aren’t doing a good enough job faking them

      • shastaxc@lemm.ee
        link
        fedilink
        arrow-up
        2
        ·
        2 years ago

        Oh well, time to get better IT guys

    • ikapoz@sh.itjust.works
      link
      fedilink
      arrow-up
      1
      ·
      2 years ago

      We do too, so I just tell my team to flag everything as spam

    • ScreamingFirehawk@feddit.uk
      link
      fedilink
      arrow-up
      1
      ·
      2 years ago

      I always just ignore anything that looks dodgy, I can’t be bothered to spend the time reporting emails when I get so damn many that are either spam or phishing

  • saltnotsugar@lemm.ee
    link
    fedilink
    arrow-up
    45
    ·
    2 years ago

    (Opens DOS, frantically types)
    “Heh. I was able to SSH right into their jpg with nothing but an Ethernet cable and router grease.”

    • yokonzo@lemmy.world
      link
      fedilink
      arrow-up
      29
      ·
      edit-2
      2 years ago

      router grease

      I don’t think that’s what you think it is sir carefully hides tissues

  • Perfide@reddthat.com
    link
    fedilink
    arrow-up
    40
    arrow-down
    5
    ·
    2 years ago

    Nah, this isn’t cool. Fuck the company, but this will fuck over the users more than anyone.

    • WereCat@lemmy.world
      link
      fedilink
      arrow-up
      43
      arrow-down
      6
      ·
      2 years ago

      If company does not give a crap about employee then they don’t about customer

      • nogrub@lemmy.world
        link
        fedilink
        arrow-up
        9
        arrow-down
        2
        ·
        2 years ago

        companies care about money everything else is means for the purpes

  • kamen@lemmy.world
    link
    fedilink
    English
    arrow-up
    26
    ·
    2 years ago

    "I wonder why they’d need my 2FA too, but oh, well… "

    • AssPennies@lemmy.world
      link
      fedilink
      arrow-up
      9
      ·
      2 years ago

      You get a duo push! And you get a duo push! …

      • Sigh_Bafanada@lemmy.world
        link
        fedilink
        arrow-up
        2
        ·
        2 years ago

        Duo push more like duo push you off a cliff because you forgot to do your Spanish lessom

  • aviationeast@lemmy.world
    link
    fedilink
    arrow-up
    26
    arrow-down
    3
    ·
    2 years ago

    I might care if they paid me a living wage.

    • hoodatninja@kbin.social
      link
      fedilink
      arrow-up
      36
      arrow-down
      3
      ·
      2 years ago

      I’m all for acting your wage, but I don’t want to make victims of anyone who is interacting with my company simply because I was feeling spiteful. The company will be fine, the tons of people who just had their information leaked are the ones who are truly inconvenienced and may face financial repercussions later on when their information is distributed. Just something to consider

    • raptor102888@lemmy.world
      link
      fedilink
      arrow-up
      4
      arrow-down
      1
      ·
      2 years ago

      I have to care about mine. If I cause a security breach, I can be sent to prison.

  • teft@startrek.website
    link
    fedilink
    arrow-up
    16
    ·
    2 years ago

    A good portion of the movie Hackers was social engineering. That’s how Mitnick got into a lot of systems as well. Why search for vulnerabilities in apps when people are much easier to manipulate.

    • joel_feila@lemmy.world
      link
      fedilink
      arrow-up
      9
      ·
      2 years ago

      HACK THE PLANET

    • FlaminGoku@reddthat.com
      link
      fedilink
      arrow-up
      5
      ·
      2 years ago

      Loved that movie. That has been a fallback movie for so long now.

  • azerial@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    13
    arrow-down
    1
    ·
    2 years ago

    I wonder if that’s how my old job had 780 gb of source stolen though social engineering.

    • xantoxis@lemmy.world
      link
      fedilink
      arrow-up
      11
      ·
      2 years ago

      780 gb of source code? Sounds a bit overengineered, I bet that was hard to audit for security flaws

      • zalgotext@sh.itjust.works
        link
        fedilink
        arrow-up
        7
        ·
        2 years ago

        If there’s 780 gb of source code, I doubt anyone there has the wherewithall to do security audits

  • CADmonkey@lemmy.world
    link
    fedilink
    arrow-up
    9
    arrow-down
    2
    ·
    2 years ago

    Pay people enough and this is less likely to happen.

    • noUsernamesLef7@infosec.pub
      link
      fedilink
      arrow-up
      4
      ·
      2 years ago

      As somone in IT who has to deal with executives I can assure you that high compensation has no correlation with good security practices :(

Comic Strips@lemmy.world

comicstrips@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !comicstrips@lemmy.world

Comic Strips is a community for those who love comic stories.

The rules are simple:

  • The post can be a single image, an image gallery, or a link to a specific comic hosted on another site (the author’s website, for instance).
  • The comic must be a complete story.
  • If it is an external link, it must be to a specific story, not to the root of the site.
  • You may post comics from others or your own.
  • If you are posting a comic of your own, a maximum of one per week is allowed (I know, your comics are great, but this rule helps avoid spam).
  • The comic can be in any language, but if it’s not in English, OP must include an English translation in the post’s ‘body’ field (note: you don’t need to select a specific language when posting a comic).
  • Politeness.
  • Adult content is not allowed. This community aims to be fun for people of all ages.

Web of links

  • !linuxmemes@lemmy.world: “I use Arch btw”
  • !memes@lemmy.world: memes (you don’t say!)
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1.98K users / day
  • 5.81K users / week
  • 11.2K users / month
  • 24.7K users / 6 months
  • 146 local subscribers
  • 16.7K subscribers
  • 4.71K Posts
  • 93.4K Comments
  • Modlog
  • mods:
  • lawrence@lemmy.world
  • BE: 0.19.8
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org