November 14th, 2008


BOFH guilt

It's 5pm on a Friday, I'm about to leave. One of our automated systems catches a phishing scam coming from another university, and can be 95% certain it's a compromised account.

I phone up one of their SysAdmins, I feel sorry for the poor guy, I've just caused him a significant fraction of an hours work, last thing on a Friday. But on the other hand, they're still going to be able to send email come Monday morning when they get back to work, not having to spend several hours getting them selves off blacklists.

I have to credit the phishers, they've spotted a lucrative target, academics may be good in their field, but half of them don't have the common sense to just ignore phishing emails, and universities tend to have a rather large bandwidth to abuse. That doesn't mean I don't have a desire to apply a significant quantity of explosives to their nether regions, but they are at least showing some intelligence.