Jump to content

Recommended Posts

Posted

Hello All,

 

We are using Trello as a helpdesk / task management platform - we use the SendBoard plugin to enable emails to be sent to a specified address to be turned into tickets, and the ability to sort and fiddle around with the ticket order is really useful.

 

In common with other similar platforms, Trello does "URL Unfurling" where, if it spots a URL in a bit of text in a ticket description or in an incoming email, ratherthan just display that URL as a string it tries to visit the URL in question and get a page title / Favicon to display instead (this forum does the same thing).

 

We've recently found this means that if a user forwards us what they think might be a spam / phishing email, Trello tries to visit the dodgy URL(s) given in the email. This came up with a recent phishing test where a provider sent out a bunch of emails to our staff, some of those staff forwarded the emails to the helpdesk without following any of the links themselves, then found they were getting "Hey, you clicked on a phishing test email, you need more training!" email, which they understandably got annoyed about. From an IT support point of view, it means that any time a user forwards us an email with a questionable URL in, that URL might be getting followed - if nothing else, it'll confirm at the spammer's end that the email address is live. From the user's point of view it means they might be more reluctant to report issues - really, we would prefer them to use the "report spam / phishing" feature in GMail, but they should feel confident that they won't be penalised just for reporting something to the helpdesk.

 

Has anyone else found this issue with Trello or any other platform - are there any solutions? A quick Google search suggests some people recommend using a browser plugin to stop the URL Unfurling feature, which might be worth a try. Interestingly, that implies that the unfurling happens at the client-side, so is probably happening at the Trello user's side of things rather than on Trello's servers (and a look at our web access logs seems to confirm the same thing).

 

Phishing simulation providers (@boxphish ?) - is this something you've come accross / have features to deal with?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...