Slashdot Log In
US Army "Scams" Service Members to Test Their Spam Gullibility
Posted by
Zonk
on Wed Apr 02, 2008 04:44 PM
from the i-think-they-call-that-trial-by-fire dept.
from the i-think-they-call-that-trial-by-fire dept.
9gezegen writes "An offer for free tickets to theme parks for service members turned out to be an email scam, a ploy that was in actuality a security exercise run by the Army. Involved servicemen and DoD civilians received an email, allegedly coming from the 'Army Family and Morale, Welfare and Recreation Command Office,' and directed them to a phishing site which asked for personal information. After rebuttal and warning by Army MWR, the website revealed that it was a security exercise after all. Army MWR later verified the exercise and announced they were not informed beforehand."
Related Stories
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Let me guess... (Score:5, Funny)
Why no stats on who fell for it? (Score:4, Interesting)
Re: (Score:2, Funny)
Not the answer you are looking for.... (Score:5, Funny)
Now, on to the answer you were looking for:
Unfortunately, in the process of transferring a few million dollars left by a distant relative in the State Bank of Nigeria, the soldier responsible for compiling the data allowed his system to be compromised, and all data was lost.
Parent
According to them, roughly 30% (Score:3, Informative)
Re: (Score:3, Interesting)
Typical (Score:5, Insightful)
Sounds like the test went off swimmingly. I can't count the number of times I've thought about doing the same sort of thing to people I work with. A few good solid scares will tighten up their security policy.
Re: (Score:3, Insightful)
Sounds like the test went off swimmingly. I can't count the number of times I've thought about doing the same sort of thing to people I work with. A few good solid scares will tighten up their security policy
*Sigh (not at you, just in general)* That's true, but how long will they remain scared and secure? People often fall into a false sense of security when there has been either a trend of "good times" or when someone keeps crying wolf. One scare will keep people safer in the short term, but not permanently.
Except for those of us who are always waiting for the other shoe to drop...
Re:Typical (Score:5, Funny)
As long as you leave up the signs that say "Threat Level: Orange", of course.
Parent
Re:Typical (Score:4, Funny)
Parent
Education? (Score:4, Interesting)
They will still need to conduct something like this once every year or two, though, you're right, because 1) yes, people will tend to become complacent, even if they now know better, and 2) Turnover (not apple or cherry) - old people leaving, new recruits joining, need to educate the new guys (and gals).
Plus, the information gathered in this exercise (not the data entered by the people on the phishing site, but the lessons learned by Command about the phishing attack and what made it succeed) could help them to review and re-write training material / procedures, and policies, to help them tighten up their security longer term. Although, we are talking about the military so who knows? (I kid, I kid. . . honestly, the military for the last 20 or so years has been doing, as far as I can tell, a pretty impressive job of re-inventing itself, and becoming much less bureaucratic than it used to have a reputation for being).
Parent
Re:Education? (Score:4, Insightful)
Parent
Re: (Score:3, Insightful)
Re:Typical (Score:5, Interesting)
The weakest link in any security system is the end user. I work with users that have the hardest time with computers. I have this guy call every week because he forgot his password and I have to take 10 min training him how to change his password. (why every week? he only works on Thursdays).
Now you will have to make a new password is has to have
now you have to put in your old password again. not that one, the one I just gave you is the old password. You have to click in the line. click the mouse. left click. you can't hover the mouse over it, you have to click in it.
You have to type it the same. no, I can see they don't match. the first one is longer, it has more dots.
You just cant explain to some people what fishing even is.
I had one guy call up freaking out that his computer told him he had porn on it. (its a fire on the spot if you have porn). It was a little pop up window trying to get him to instal a program to "remove" it. The good news is he was too scared to click the button and called me instead. Other users had to be rebuilt.
I know an attack like this would catch so many people and you have to train them. But you spend so much time just logging them in or working on the basic stuff. This is one detail that some people will have a hard time grasping.
I am in an interesting enviroment. I have college students looking to enter the workforce working with people that are about to or have retired. So I deal will the full range of users all the time.
Parent
Re:Typical (Score:5, Interesting)
We do it on a random sample of users with our web platform. All login requests get routed to a central domain ("shield.domain.com") which is non-SSL. That domain does a little basic load balancing to distribute requests to "https://foo.domain.com" or "https://bar.domain.com". We have a few extra domains set up, including "https://foo.domane.com" with a valid SSL certificate; "https://aa.domain.com" with an invalid certificate; and a non-SSL domain, "http://foodomain.com". All are nearly identical to our login page - one has a button out of alignment, throws some JavaScript errors, etc.
The pages alert the user to the deception on the first try. Second tries net a phone call. Third tries get a more detailed phone call with the office owner & account lockout.
It's been very effective, in fact, I've received several thank you notes so far from our users for teaching them about it. Not just dictating to them, but teaching them through first hand experience. They thank us because they can easily apply those same "does the address bar really match what it should?" technique to every other site out there.
And to get the same effect as phising, we send out periodic/random e-mails that read pretty official, but come from the wrong domain, or have a forged From: address, asking a user to visit a set up fraud website to enter personal information (not detailed, mostly just fishing for their user credentials).
The only thing I don't know yet is if users are learning because they are actually learning, or if it's a forced behavior just so they don't get a phone call from me. I'm not sure it matters why, just as long as it's happening.
Parent
Re:Typical (Score:5, Interesting)
Now you will have to make a new password is has to have
I consider myself fairly intelligent, but I had a heck of a time remembering the passwords and was embarrassed by needing regular password resets after long weekends.
To make matters worse, password management programs like KeePass were not allowed on the network and any unauthorized software could get you in trouble. Because of this I ended up having to do things like writing half my password on a post-it and the other half on a card in my wallet. I devised all sorts of incredibly insecure systems to store the myriad complex passwords I was required to maintain.
Parent
Re: (Score:3, Funny)
But, can you teach them to fish?
Teach a man to phish and you won't get jack squat out of it, ever.
Re:Typical (Score:5, Interesting)
Parent
Re: (Score:3, Insightful)
These are called 'exercises', are planned extensively, and there is definitely installation coordination. The local DOIM (directorate of information management) is notified of the exercise, usually by their theatre command well ahead of time.
Of all the phishing iv seen during various exercises, iv never seen one more complicated than simply counting how many users on what installation clicked the link. no information gathering besides IP, which is helpful fo
This is good. (Score:5, Insightful)
Re: (Score:2)
Hell your email provider should send you a 419 scam every month or so, and attach "sexy" photos to them.
Seriously would help.
Re: (Score:2)
Re: (Score:3, Interesting)
It's a way for "businesses" who can't even muster enough confidence from a bank to get an account with them, to still be able to "accept" credit cards.
But although you can do something that's very much like banking, with paypal, they are not, themselves, a bank. So they can get away with outrageous fees and also avoid any of the liability the CC banks have.
This is very much in line with Ebay's business practices: a classified-ad web site server which charges based on how much mone
Re:This is good. (Score:5, Funny)
They already do. Haven't you ever received a "Pre-Approved" credit card application?
Parent
In before.... (Score:4, Insightful)
Re:In before.... (Score:5, Insightful)
I'm not pretending the army is full of Einsteins, but they all graduated high school or earned a GED (vast vast majority graduated high school), and all of them are required to learn math skills involving chemical attack detection, navigation, operating a frequency hopping radio, etc.
Compare that to kids in the average US city, where 50% do not graduate high school.
The Army is certainly a lot smarter than the general population. They may be more willing to rely on titles (like MWR)... I don't know about that, but I'd like to know who is buying the Carter era propaganda that the army is a bunch of idiots.
Parent
Re:In before.... (Score:4, Informative)
http://www.bellum.nu/armoury/FFVAT4.html [bellum.nu]
Parent
Re: (Score:3, Insightful)
Re:In before.... (Score:5, Funny)
"AIM AWAY FROM FACE." ???
Parent
Re: (Score:3, Insightful)
Simple instructions are the fail-over mechanism.
Re: (Score:3)
I mean, my toaster as a "do not use in bathtub" picture on the bottom of it". My Playstation 2 comes with a similar warning. Same with my Thinkpad.
It's not fair to point to a rocket launcher, something capable of destroying nearly any vehicle and killing nearly anyone
Good Idea (Score:2)
Addendum (Score:5, Funny)
2. Don't tell.
3. Don't opt-in.
Re:Addendum (Score:5, Funny)
2. Don't tell.
3. Don't opt-in.
This is an e-mail from the Army Family and Morale, Welfare and Recreation Command Office informing you that you've been signed up for the "STDs and You" mailing list. To Opt-Out, please visit the following link: hxxp://maliciouslink.com where you will be asked for some basic information to verify your identity.
Parent
.mil??? (Score:5, Insightful)
Re: (Score:3, Informative)
There is nothing wrong with the military's affiliates using
Re: (Score:2)
http://www.ftc.gov/opa/2005/08/consumerinfo.shtm [ftc.gov]
Re: (Score:2)
Re: (Score:3, Interesting)
Seems fitting (Score:2)
Challenges = Good Security (Score:3, Insightful)
At work, I will always do something to an unlocked computer. Sometimes it's just to open Notepad and write, "This machine has been hacked!" and crank the font size up to 96. Sometimes I'll send an "I Love You" e-mail from the person to the person sitting next to them. (Who I always bring in on the prank, and I have never had a problem getting cooperation).
Last week, my boss (VP of IT) went into a meeting and left his machine unlocked. I sent *his* boss an "I Quit!" message.
Now, unlocked computers are so very rare around here. I'm glad for the increased security, but sad that I can no longer prank my co-workers.
I like it (Score:5, Insightful)
What I think the Army will find most surprising(or not!) is the apparent lack of use of the AKO Webmail system, it sucks, hard.
Good (Score:3, Interesting)
Dear Seargent or Lewtenant (Score:4, Funny)
Dear sir (Score:4, Funny)
Re:And what was the point? (Score:5, Insightful)
If my company trusted my co-workers with information that could get me killed, I'd want them to test susceptibility to social engineering. If I do a bad job, my company loses money. When people in the military do a bad job, people can die (OK, when they do a good job people still die - but they're other people, those trying to kill them). They need to worry more about security.
Parent
Re:And what was the point? (Score:4, Interesting)
I think that the military should try more such exercises to keep their people aware of such security issues. If they do it enough, the standard response to such emails will be to verify the source and report it as required.
Even with that somewhat computer literate USAF folks I served with, these "exercises" would have been very helpful.
Parent
Re: (Score:3, Insightful)
I would prefer that my company be active in testing security in this exact fashion. Rather than imposing increasingly opressive restrictions because of what some people "might" do.
it would be better to get teh e-mail "Since 12% of you BONEHEADS didn't recognize a clear security threat, and feature XYZ was essentially opened to be compromized, it will be locked untill you boneheads demonstrate yo
Re: (Score:2)
Re:The army has been scamming people for years. (Score:4, Insightful)
They cannot pull you out of class. The only time they can pull you out of class is during a natural disaster (National Guard, or in extreme cases, the standing military). If the conflict or disaster gets to the point where they are pulling people out in the middle of class, school for everybody will pretty much be irrelevent to the issues occuring. However, they can keep you deployed for a certain amount of extended time, provided you are already deployed.
I know it's easy to trash the military, being all high on your horse and born with a silver spoon in your mouth, but until you can actually say you've EARNED your right to free speech, rather than using it because you were born with it, pull your head out of your ass and stop abusing it. Unlike you, obviously, those of us in the military have the guts, balls, discipline, and bravery to fight for our rights at the expense and derision of little pussies like you who talk trash about us while sipping a Starbucks latte in your comfy office. Someone should strap you to the side of a Humvee and use you for armor. Weak armor.
Parent