Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

http://knowbe4.com has a pretty good training platform for creating more security awareness and for testing your users with generated phishing emails.


Which ends up being darkly hilarious when they're whitelisted, leading to a situation where literally every "phishing attempt" an employee ever sees is a fake crafted to conform to the stereotypes given in the training.


My employer uses PhishMe. Every "phishing attempt" I see is from my own employer. It is not adaptive. They don't scale up the apparent sophistication of the attack if previous attempt didn't work. So I am continually getting e-mails from "HR" asking me to update my contact info, or from "Expense Reports" asking me to verify some info to get reimbursed for my travel expenses.

It's annoying.


Indeed. I setup a rule in outlook to look for knowbe4 in the header to dump those. Although, to be fair, I doubt it is the devs they are worried about.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: