[unisog] Fake Redhat update

J. Oquendo sil at infiltrated.net
Tue Nov 23 16:19:19 GMT 2004

On Tue, 23 Nov 2004, STeve Andre' wrote:

> The only defense for this is to teach people a little paranoid, and to
> repeatedly pound into them the fact that *any* "notice" to do something
> to their computer other than through official channels is bad.
> But doesn't common sense ever come into play here?  The url isn't from
> a company.  I would hope that most folks would key on that, but likely
> not...
> Educating your users, over and over again seems to be the only way
> to deal with this.  Thats what I do.

Even people in "the know" can be fooled. Education comes in handy when
people actually pay attention. I feel sorry for the poor guy who didn't
check his PGP sigs (note the FreeBSD advisory below)... Sure, education
you say?


I say, competent admins across the board, on the home level, its not as
catastrophic (to an extent) of having say, Yahoo! or eBay or some other
business falling for this junk. And yes, even the big guys sometimes slip.

