The Honey Stick Project


Funny, I’ve never received a password protected PDF from payroll before…

Posted in Privacy, Understanding the Risks, tips by Administrator on the May 7th, 2008

Here’s a simple tip that can save you a lot of trouble.

DON”T ENTER PASSWORDS WHERE YOU AREN’T EXPECTING THEM!!!

I recently came across a suspicious email in my spam folder. It appeared to be from a payroll service I’ve actually dealt with.  There was almost no way to tell for sure if it was from them.

The subject line included a recent date and the word “Paystub”. There was a PDF attachment and even with image loading turned off, there was a label that said “This PDF is password protected”. It had a single field with the word “Password” beside it.

I have yet to determine if this email was authentic or a real phishing attack, aimed at gathering passwords. But if this is a phishing attack, here’s what could happen if I entered a password:

  1. The password gets collected, and an error message is produced saying “Invalid password, please try again”.  Knowing that we should all be using different passwords for each site or program “to be secure”, I may simply think I should have used one of my other dozen passwords (don’t we all use that many password variations?!)
  2. Hitting “Enter” or clicking on a button causes the password to be sent back to a mothership, including enough information for them to identify my email address as being valid.
  3. No only do they now know that this email address is valid, but they have at least one version of my password. If I tried several different ones, they could have them all.

This is dangerous because people think they “NEED TO SEE WHAT’S INSIDE” then encrypted email. It’s like arriving at your office with a wrapped package that has lots of heavy tape sealing it up. The more tape there is protecting it, the more you want to open it to see what it is that could be so sensitive.

To make things worse, there aren’t a lot of easy ways to automatically check for the authenticity of such a package. It can have a digital signature on it, which you could verify. But there are a lot of usability issues yet to be solved in verifying digital signatures in the wild. Enterprises that use Public Key Infrastructure regularly would have an easier time letting people ensure the authenticity of emails and attachments. But most people won’t have that luxury.

So, if you aren’t expecting to be asked for a password (even on a website - which can effectively trick you the same way) you should call up somebody in the originating organization to verify that it is valid, and that it is important. I would also notify them that they should not present password protected information without an easy way to securely verify that it is real.
I am actually surprised that I haven’t seen more evidence of this type of phishing, but I’m sure we will in the future.

Leave a Reply

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Funny, I’ve never received a password protected PDF from payroll before…

Posted in Privacy, Understanding the Risks, tips by Administrator on the May 7th, 2008

Here’s a simple tip that can save you a lot of trouble.

DON”T ENTER PASSWORDS WHERE YOU AREN’T EXPECTING THEM!!!

I recently came across a suspicious email in my spam folder. It appeared to be from a payroll service I’ve actually dealt with.  There was almost no way to tell for sure if it was from them.

The subject line included a recent date and the word “Paystub”. There was a PDF attachment and even with image loading turned off, there was a label that said “This PDF is password protected”. It had a single field with the word “Password” beside it.

I have yet to determine if this email was authentic or a real phishing attack, aimed at gathering passwords. But if this is a phishing attack, here’s what could happen if I entered a password:

  1. The password gets collected, and an error message is produced saying “Invalid password, please try again”.  Knowing that we should all be using different passwords for each site or program “to be secure”, I may simply think I should have used one of my other dozen passwords (don’t we all use that many password variations?!)
  2. Hitting “Enter” or clicking on a button causes the password to be sent back to a mothership, including enough information for them to identify my email address as being valid.
  3. No only do they now know that this email address is valid, but they have at least one version of my password. If I tried several different ones, they could have them all.

This is dangerous because people think they “NEED TO SEE WHAT’S INSIDE” then encrypted email. It’s like arriving at your office with a wrapped package that has lots of heavy tape sealing it up. The more tape there is protecting it, the more you want to open it to see what it is that could be so sensitive.

To make things worse, there aren’t a lot of easy ways to automatically check for the authenticity of such a package. It can have a digital signature on it, which you could verify. But there are a lot of usability issues yet to be solved in verifying digital signatures in the wild. Enterprises that use Public Key Infrastructure regularly would have an easier time letting people ensure the authenticity of emails and attachments. But most people won’t have that luxury.

So, if you aren’t expecting to be asked for a password (even on a website - which can effectively trick you the same way) you should call up somebody in the originating organization to verify that it is valid, and that it is important. I would also notify them that they should not present password protected information without an easy way to securely verify that it is real.
I am actually surprised that I haven’t seen more evidence of this type of phishing, but I’m sure we will in the future.

Leave a Reply

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word