News: 1613076158

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Phishing awareness gone wrong: Facebook tries to seize websites set up for staff security training

(2021/02/11)


Security biz Proofpoint and its subsidiary Wombat Security Technologies have sued Facebook and its Instagram subsidiary to prevent the seizure of internet domain names used for security testing.

Proofpoint conducts cybersecurity training for organizations, part of which includes phishing awareness testing. This involves sending participating employees simulated phishing messages with deceptive domain names to entice them to click on links or visit web pages that in a real threat scenario would be trying to trick visitors into submitting sensitive personal information like login credentials.

[1]

To do so, the firm follows the cybercrime playbook. It sets up domain names that incorporate trademarked terms, like Facebook and Instagram, or fragments of those terms that have similar looking domain names. In the context of this case, th security biz registered: facbook-login.com , facbook-login.net , instagrarn.ai , instagrarn.net , and instagrarn.org .

The company's [2]complaint [PDF], filed in US District Court in Arizona on Tuesday, explains its rationale for doing so: "By using domain names similar to those of well-known companies, Proofpoint is able to execute a more effective training program because the workforce is more likely to learn to distinguish typo-squatted domains, which are commonly abused by bad actors to trick workers, from legitimate domain names."

[3]

Proofpoint claims such tests help protect both the employer providing the training and the owners of legitimate domain names, like Facebook and Instagram.

Nope, ICANN rules

Facebook however isn't on-board with that line of reasoning. Last November, the social ad biz filed a complaint under the Uniform Domain Name Dispute Resolution Policy (UDRP), a set of rules established by internet overseer ICANN to help resolve domain name disagreements without sending every dispute to court.

Facebook objected to Proofpoint's domains as confusingly similar to its own, which happens to be the sort of the trademark policing that trademark law requires. As the US Trademark Office puts it

[4]PDF

, "Throughout the life of the registration, you must police and enforce your rights."

Facebook's anti-trademark bot torpedoes .org website that just so happened to criticize Zuck's sucky ethics board [5]READ MORE

Though the domains at issue, when visited, state "This web site belongs to Proofpoint Security Awareness Training," the UDRP arbitrator nonetheless sided with Facebook last month and directed the registrar handling those names, Arizona-based Namecheap, to turn control over to the social media giant.

Proofpoint is seeking a declaration from the court to prevent the domain transfer and to affirm that the company's use of the lookalike domains is lawful. In its complaint, the company contends that Facebook's UDRP arguments – that Proofpoint was not making legitimate use of those domains and acted in bad faith by registering them – are inaccurate.

And the security biz maintains that no one is likely to confuse its similarly named domains to Facebook.com or Instagram.com .

Confusion is unlikely among program participants, the company argues, because links to the domains at issue include a disclaimer: "This phishing simulation was provided by your employer to help teach you to recognize commonly-used phishing risks. To appear as realistic as possible, it may contain the name, brand or logo of unaffiliated third parties."

[6]

Facebook did not immediately respond to a request for comment. ®

Get our [7]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YCW3BqErvEW6mhDpfr@w@QAAANM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://regmedia.co.uk/2021/02/11/proofpoint_v_facebook.pdf

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YCW3BqErvEW6mhDpfr@w@QAAANM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.uspto.gov/sites/default/files/documents/BasicFacts.pdf

[5] https://www.theregister.com/2020/10/09/facebook_ethics_takedown/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YCW3BqErvEW6mhDpfr@w@QAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://whitepapers.theregister.com/

Is proofpoint being malicious

alain williams

or deceptive* in its use of these domain names ? If not it seems as if their use is reasonable. To provide good training it has to use domains that have to be good enough to fool those being trained. The UDRP arbitrator is wrong and facebook is being an ass (nothing new there).

* Other than trying to deceive those being trained.

Re: Is proofpoint being malicious

NoneSuch

Maybe Facebook should be grabbing the similar domains NOT in responsible hands as a first step.

I almost typed that without cracking a smile. Almost...

Re: Is proofpoint being malicious

The commentard formerly known as Mister_C

Or perhaps proofpoint should allow the relevant domains to be transferred because trademark. On the understanding that the big boys lease the names back gratis so that the training company has a valid, above board training resource. Because pro bono.

And preferably rinse repeat with other web giants for other training and/or security companies.

Re: Is proofpoint being malicious

JimboSmith

A mate who works for a firm who uses Wombat got creative. He reverse searched all the domain names Wombat have registered that he could find. Then added them to his spam list and hosts file so he wasn't bothered by the emails. He had to remove their main domain from both those though. This was because the emails telling him he had training to complete were being dumped directly into spam.

Re: Is proofpoint being malicious

Grease Monkey

Are they begin malicious? No.

Are they being deceptive? Quite clearly yes, otherwise there would be no point in the whole exercise.

I think the question here is not whether the rules are broken, but whether the rules are correctly drafted in the first place.

Where is human decision making?

Terry 6

In another thread* Google's use of automated decision making is covered.

In this one we must assume a human chose to pursue this matter against a valid security training company.

But the outcome is broadly the same- a bloody stupid decision is made without any sense of human common-sense, case-by-case, judgement.

I had joked in that thread that maybe there weren't any humans and they were really being run by computer.

But I'm starting to think it wasn't a joke.

----------------------------------------------------------------------------------------------------------------------------

* https://www.theregister.com/2021/02/08/terraria_developer_cancels_stadia_port/

Re: Where is human decision making?

Doctor Syntax

Common sense will probably be above the pay grade of those responsible.

Clickable links

Foxglove

Where I work we get fairly regular phishing test emails from seemingly legitimate sources with seemingly legitimate links, no problem with that.

If you are caught you then get an email with a link directing you to take a training course.

That email comes from a seemingly legitimate source with a seemingly legitimate link.

I report those emails to the phishing team and don't click on the link.

It has been like this for years.

Why they can't email me saying something like 'log in to your personal training portal on the intranet where a course link will be available'?

That would seem sensible to me.

Just a personal rant I know, but as I can't go to the pub El Reg is my new best mate ever.

Re: Clickable links

JimboSmith

I've had at least one phishing test email sent to my work address. I've probably had more but I ignore anything I think is spam, which is quite often. I've deleted a few legitimate emails and just blamed the spam filter.

The one phishing one I bothered to look at had a link and an attachment. I reported it and told IT support I thought others may have received it too. When their response was glacial that time, I cottoned on to the fact it was a test. As I don't do LinkedIn or use my work email for any social media mails with those as a link won't work for me. I don't do internet banking either so those would be another massive red flag. The address I've given work as my personal email is unique to them. If a test one is sent to that address it'll be obvious.

Re: Clickable links

Terry 6

This is another issue. Banks' marketing depts have a history of sending emails with clickable links of the "Click here to log in and see our latest rates" variety. One month I got one such email from them within days of receiving one from their security dept, warning all customers never to click links in emails to log in!

Why is there no icon for despair?

(Which, to be fair, was also the response of their customer service person when I phoned to complain about this- a sense of despair, but knowing that the most they could do was pass this up the line).

Version 1.0

Every few days I get emails stating that my AmericannExpress account has been locked - so I guess I can't post about this this on Farcebook?

Sorry that handle is already taken.

"By using domain names similar to those of well-known companies, Proofpoint is able to execute a more effective training program because the workforce is more likely to learn to distinguish typo-squatted domains, which are commonly abused by bad actors to trick workers, from legitimate domain names." and yet

the security biz maintains that no one is likely to confuse its similarly named domains to Facebook.com or Instagram.com

It's fair to say it's difficult to reconcile these two statements.

I'm sitting on my SPEED QUEEN ... To me, it's ENJOYABLE ... I'm WARM
... I'm VIBRATORY ...