News: 1716490872

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Google guru roasts useless phishing tests, calls for fire drill-style overhaul

(2024/05/23)


A Google security bigwig has had enough of federally mandated phishing tests, saying they make colleagues hate IT teams for no added benefit.

Matt Linton leads Google's security response and incident management division. Tasked with rolling out phishing exercises every year, he believes tests should be replaced by the cybersecurity equivalent of a fire drill.

Today's phishing tests more closely resemble the fire drills of the early days, which were more like fire evacuation drills – sprung upon a building's residents with no warning and later blaming them as individuals for their failures.

[1]

Since then, more security features have been fitted to buildings. Linton cited wider doors and their push-bar exit designs, as well as fire sprinklers as examples of innovations that improved a building's fire safety. None of these were implemented to improve individual residents' response to drills, but together they increased survival rates and now fire drills are better planned, well-announced procedures.

[2]

[3]

Readers, you can probably see where he's going with this. Parallels between these early fire tests and modern-day phishing exercises are clear – in both cases the burden of responsibility is applied more to the individual rather than the infrastructure around them.

Google Spectre whiz kicked out of DEF CON hotel over misunderstood tweet [4]FROM 2018

Despite anti-phishing controls being baked into security products and email clients, research points to phishing attacks increasing. Zscaler's latest annual [5]phishing report found the past 12 months saw a 58 percent increase in phishing, and the [6]wider adoption of AI by cybercriminals has driven that surge.

The Federal Risk and Authorization Management Program (FedRAMP) is one of the US organizations that promotes cybersecurity standards. Google maintains FedRAMP compliance and does so, in part, by running phishing tests that follow its guidance, which still claims users "are the last line of defense and should be tested."

Linton argues that there is value in providing staff phishing training, but achieving a 100 percent success rate "is a likely impossible task."

[7]

"Phishing and Social Engineering aren't going away as attack techniques," he [8]blogged . "As long as humans are fallible and social creatures, attackers will have ways to manipulate the human factor.

"The more effective approach to both risks is a focused pursuit of secure-by-default systems in the long term, and a focus on investment in engineering defenses such as unphishable credentials – like [9]passkeys – and implementing multi-party approval for sensitive security contexts throughout production systems. It's because of investments in architectural defenses like these that, we're told, Google hasn't had to seriously worry about [10]password phishing in nearly a decade."

The problem with current tests, and possible alternatives

The main argument against current phishing tests is "there is no evidence that the tests result in fewer incidences of successful phishing campaigns," said Linton.

Some tests like those mandated by FedRAMP require organizations to reduce or eliminate existing controls to maximize the perceived impact of a failed test. This opens up a litany of issues, such as giving test subjects a false sense of the real risks and the allowlists implemented during exercises not being removed after, leaving them open for abuse by attackers.

There's also the increased load placed on incident responders and those tasked with triaging reports sent to threat detection teams, all while staff are left feeling unnecessarily deceived, Linton said, and he's not alone.

[11]

The [12]guidance from the UK's NCSC, for example, concurs with many of the points raised by the Googler, saying they erode trust between staff and security teams, and that there are a host of reasons why a user may click on a link in a phishing test.

[13]'China-aligned' spyware slingers operating since 2018 unmasked at last

[14]With ransomware whales becoming so dominant, would-be challengers ask 'what's the point?'

[15]Crims abusing Microsoft Quick Assist to deploy Black Basta ransomware

[16]Uncle Sam urges action after Black Basta ransomware infects Ascension

Factors such as certain personality traits of a given individual may compel them to click a link and situational variables including a particularly stressful workload being managed at the time a test is issued may unfavorably skew results.

"Employees should instead create a positive cybersecurity culture so employees feel comfortable reporting [17]phishing incidents, and in this sense, they can be a valuable early warning system," the NCSC says.

Linton's idea of how these tests could be improved goes back to the notion of fire drills evolving into what they are today.

Rather than them being delivered with deception, the fact they're a test should be clear as day, in the same way that apartment and office blocks have posters plastered around every corner weeks before a test is carried out. They should point to a test and inform the recipient of the benefits.

Linton's idea of a possible alternative is considerably different compared to the tests office workers have become accustomed to over the years.

Hello! I am a Phishing Email.

This is a drill - this is only a drill!

If I were an actual phishing email, I might ask you to log into a malicious site with your actual username or password, or I might ask you to run a suspicious command.

You can learn more about recognizing phishing emails at and even [18]test yourself to see how good you are at spotting them . Regardless of the form a phishing email takes, you can quickly report them to the security team when you notice they're not what they seem.

To complete the annual phishing drill, please report me.

Thanks for doing your part to keep

A. Tricky. Phish, Ph.D

In addition, the NCSC says a multi-layered approach should be taken to mitigating phishing attacks in a workplace:

Make it difficult for attackers to reach your users

Help users identify and report suspected phishing emails

Protect your organization from the effects of 'successful' phishing emails

Respond quickly to incidents

"Educating employees about alerting security teams of attacks in progress remains a valuable and essential addition to a holistic security posture," Linton said. "However, there's no need to make this adversarial, and we don't gain anything by 'catching' people 'failing' at the task.

"Let's stop engaging in the same old failed protections and follow the lead of more mature industries, such as fire protection, which has faced these problems before and already settled on a balanced approach." ®

Get our [19]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zk@8jCCb46g3C5QIpmCxvwAAANM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zk@8jCCb46g3C5QIpmCxvwAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zk@8jCCb46g3C5QIpmCxvwAAANM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2018/08/10/google_matt_linton_caesars_def_con/

[5] https://www.zscaler.com/blogs/security-research/phishing-attacks-rise-58-year-ai-threatlabz-2024-phishing-report

[6] https://www.theregister.com/2023/01/11/gpt3_phishing_emails/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zk@8jCCb46g3C5QIpmCxvwAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://security.googleblog.com/2024/05/on-fire-drills-and-phishing-tests.html

[9] https://www.theregister.com/2024/05/02/microsoft_google_passkeys/

[10] https://www.theregister.com/2024/04/29/uk_lays_password_legislation/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zk@8jCCb46g3C5QIpmCxvwAAANM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://www.ncsc.gov.uk/guidance/phishing

[13] https://www.theregister.com/2024/05/23/china_hacking_group/

[14] https://www.theregister.com/2024/05/21/with_ransomware_whales_becoming_so/

[15] https://www.theregister.com/2024/05/16/microsoft_quick_assist_crime/

[16] https://www.theregister.com/2024/05/13/cisa_ascension_ransomware/

[17] https://www.theregister.com/2024/04/10/x_fixes_url_blunder/

[18] https://phishingquiz.withgoogle.com/

[19] https://whitepapers.theregister.com/



Social and fallible

Throatwarbler Mangrove

"As long as humans are fallible and social creatures"

So the ideal defense is to be like the typical Register reader: antisocial and infallible.

Still useful

froggreatest

You need to be able to monitor if your phishing awareness training is effective. In my megacorp we do mandatory training and we also get phishing emails. The training says “if you get X then report it in Y” so the regular phishing campaigns gives a measure of a variety of things. You see how many people reported, ignored and clicked after taking up training.

I do not know what happens to people who click the links though.

usbac

Wow, the reality distortion field in slly-con valley must be strong!

So, according to Google, the best way to stay safe is:

1. Use un-phishable credentials (they don't exist).

2. Make sure to use systems and software without any security vulnerabilities (good luck).

I didn't know that defending against phishing was so simple...

Not sure if it's possible

IGotOut

....but can't it be forced that the hyperlink is always displayed as the actual URL it's going to?

I know in Protonmail, it pops up a warning with the full URL before you can proceed, but can corporate mail take it one further?

It will have the added bonus of making tracking footers and icons etc look like crap.

Re: Not sure if it's possible

usbac

The most commonly used corporate email client, MS Outlook goes out of it's way to hide the real URL. It's almost like Microsoft is trying to encourage phishing.

What should I expect from a company that doesn't even support checking SPF records between their O365 tenants!

Re: Not sure if it's possible

Sandtitz

"MS Outlook goes out of it's way to hide the real URL"

You are lying. The URL is shown as a tool tip when you hover mouse pointer over it.

Re: Not sure if it's possible

mhoulden

You can tell which ones are phishing tests because they're the only ones that don't go through the Safelinks thing. I'm not sure what happens if that ever gets compromised.

Re: Not sure if it's possible

Doctor Syntax

I know some email systems add a warning to any external mail as I've seen them when my messages has been quoted in a reply. Whether that would be enough to stop some recipients clicking on links is another matter.

Meanwhile the public don't receive any training not to be phished. Far from it organisations which should know a lot better persist in training them to respond by sending emails with invitations to click, including invitations to click to log in. I remain convinced that those responsible for sending such emails would click on a link in an inbound email with the subject "This is a fraudulent phishing email" and a link labelled "This link is dangerous to click".

By all means keep running phishing tests and restrict those who fail from using any technology more advanced than a mechanical typewriter and an abacus.

Re: Not sure if it's possible

doublelayer

They definitely could in a variety of ways. Rewriting the email is easy. Configuring the clients to show links is usually an option depending on whether they let you choose the client. One company I have worked let me do this which was nice because I don't like GMail webmail and that's what everyone else was using, but it also didn't give me any integration with their systems. The capability to do that is available to them.

Why not test the IT teams reaction to a credential leak?

kurtseifried

Here's an idea: Reverse phishing test. You post a username and password online and see how long it takes to be used and for IT to notice.

Shouldn't your IT dept be able to handle this? They have practiced it, right?

Doctor Syntax

"fire drills of the early days, which were more like fire evacuation drills – sprung upon a building's residents with no warning.

...

now fire drills are better planned, well-announced procedures"

Oddly enough it's the old style drills that more closely resemble actual fire alarms (and bomb alerts).

The comparisons is, actually, a false one. An evacuation drill is an exercise is responding to an alert raised by others. Phishing testing is more akin to testing response to encountering al fire outbreak or recognising a suspicious object and taking appropriate action including raising an alert.

Cav

Nonsense.

""there is no evidence that the tests result in fewer incidences of successful phishing campaigns,"". Where I work, phishing tests initially had high failure rates. Those decreased over time.

"secure-by-default systems in the long term"

We don't all have Google's resources. Legacy systems hang around for decades.

"later blaming them as individuals for their failures"

They are to blame. if you tell someone, over and over and over again that they should never click links in unexpected emails, and certainly never enter credentials, and they do it anyway then they are to blame. Personality and workload are irrelevant.

Announcing that an incoming phishing email is a test makes it pointless. If you know you are being tested then of course you are not going to click. You have to know not to click EVER.

Suggested solution is insufficient

doublelayer

The problem with the four suggested points is that none of them replace what phishing testing is supposed to do. That's not to say that any of the suggestions are wrong, and some of them are required along with phishing testing, but if you don't test and do these instead, you'll still have a gap. Going through them:

"Make it difficult for attackers to reach your users"

Great idea, but you can never count on that. Sure, authenticate the servers sending mail to you and reject it, but phishers can put DKIM on their sending server too. There is only so much you can do to prevent someone who needs to receive emails from the public from receiving emails from dangerous parts of the public.

"Help users identify and report suspected phishing emails"

Everyone has training. The phishing tests are there to check whether the training worked, and where it didn't, provide more training. Someone who clicked a link has not learned some lesson that should either be taught to them directly or put in the training for more general consumption. The tests are there to improve this goal. Not having them means your training probably has holes, but you don't know where they are until it causes a problem.

"Protect your organization from the effects of 'successful' phishing emails"

Of course, but this is now cure rather than prevention, and we all know the saying that links those. You'll have to spend less time cleaning up if you can minimize the number of messes that are created.

"Respond quickly to incidents"

Not much different from the third point, and a point where prevention is more important. If, for some reason, you don't have the ability to respond as quickly to incidents as you would want to, for example the main security person is busy cleaning up from a successful phishing attack that happened yesterday, the second security person is off sick, and the third security person doesn't exist because this isn't Google with probably a couple buildings full of them, then it would be best to have fewer incidents. Phishing training and testing is designed to make that happen so that the security teams can respond quickly when ones do happen. By the way, having a Google-sized IT security team doesn't necessarily make this easier if the number of incidents scales with that, because a hundred people chasing ten thousand incidents is still going to be slow, even if they acknowledge the alarm quickly. I've worked with large incident response teams who look speedy and efficient, but the incident load can make that productivity theater if you're not careful.

A young girl, Carmen Cohen, was called by her last name by her father,
and her first name by her mother. By the time she was ten, didn't know if she
was Carmen or Cohen.