{"id":1608,"date":"2016-11-08T10:16:42","date_gmt":"2016-11-08T15:16:42","guid":{"rendered":"http:\/\/osric.com\/chris\/accidental-developer\/?p=1608"},"modified":"2016-11-08T10:16:42","modified_gmt":"2016-11-08T15:16:42","slug":"social-engineering-through-surveys","status":"publish","type":"post","link":"https:\/\/osric.com\/chris\/accidental-developer\/2016\/11\/social-engineering-through-surveys\/","title":{"rendered":"Social Engineering through Surveys"},"content":{"rendered":"<p>I received an invitation to a survey today. I was selected as an alumnus of the University of Michigan, an enormous university. The e-mail implies that the survey is possibly on behalf of the university. It includes the well-recognized &#8220;Block M&#8221; logo.<\/p>\n<p>However:<\/p>\n<ul>\n<li>The &#8220;From&#8221; address is alumnisurvey@lrwonlinesurvey.com.<\/li>\n<li>Links to unsubscribe go to click.skem1.com.<\/li>\n<li>The survey itself is at survey.bz.<\/li>\n<\/ul>\n<p>It all looks pretty fishy\/phishy.<\/p>\n<p>Nowhere are there any links to umich.edu.<\/p>\n<p>Also, I happen to know that the University of Michigan tends to use Qualtrics for surveys. Why wouldn&#8217;t the university send out a Qualtrics survey from a umich.edu e-mail address with umich.edu unsubscribe links instead of a survey.bz survey from a lrwonlinesurvey.com address with click.skem1.com unsubscribe links?<\/p>\n<p>The survey is likely legitimate. The alumni department probably contracted with a research firm, that research firm probably uses a third-party survey software, and they probably use a different third-party service to handle mailing lists.<\/p>\n<p>But I will not be filling out such a survey. You shouldn&#8217;t either. And, if you&#8217;re in the business of creating surveys or hiring companies to create surveys, you should think about these factors. Why create something that looks this suspicious?<\/p>\n<p>I&#8217;ve always said that survey results automatically exclude those who don&#8217;t have time to waste on surveys (this one suggested it would take 18 minutes to complete!), but now it seems they also exclude anyone with a mind for security and privacy.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I received an invitation to a survey today. I was selected as an alumnus of the University of Michigan, an enormous university. The e-mail implies that the survey is possibly on behalf of the university. It includes the well-recognized &#8220;Block M&#8221; logo. However: The &#8220;From&#8221; address is alumnisurvey@lrwonlinesurvey.com. Links to unsubscribe go to click.skem1.com. The &hellip; <a href=\"https:\/\/osric.com\/chris\/accidental-developer\/2016\/11\/social-engineering-through-surveys\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Social Engineering through Surveys<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[48],"tags":[412,356,413,411],"class_list":["post-1608","post","type-post","status-publish","format-standard","hentry","category-security","tag-phishing","tag-security","tag-social-engineering","tag-surveys"],"_links":{"self":[{"href":"https:\/\/osric.com\/chris\/accidental-developer\/wp-json\/wp\/v2\/posts\/1608","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/osric.com\/chris\/accidental-developer\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/osric.com\/chris\/accidental-developer\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/osric.com\/chris\/accidental-developer\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/osric.com\/chris\/accidental-developer\/wp-json\/wp\/v2\/comments?post=1608"}],"version-history":[{"count":3,"href":"https:\/\/osric.com\/chris\/accidental-developer\/wp-json\/wp\/v2\/posts\/1608\/revisions"}],"predecessor-version":[{"id":1619,"href":"https:\/\/osric.com\/chris\/accidental-developer\/wp-json\/wp\/v2\/posts\/1608\/revisions\/1619"}],"wp:attachment":[{"href":"https:\/\/osric.com\/chris\/accidental-developer\/wp-json\/wp\/v2\/media?parent=1608"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/osric.com\/chris\/accidental-developer\/wp-json\/wp\/v2\/categories?post=1608"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/osric.com\/chris\/accidental-developer\/wp-json\/wp\/v2\/tags?post=1608"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}