Live data from Hacker News

Web Security is Too Hard

textslashplain.com

1–10 of 127 posts

Re: Web Security is Too Hard

#3
Another entry in "Marketing department starts a promotion campaign for the new product that's indistinguishable from a phishing attack" list. Starting with not using a subdomain on your own, very well-known domain but instead using a completely different one, then not having it shown with the rest of your services on your main web site, et cetera.

Re: Web Security is Too Hard

#4
I guess it's easy to judge from the sidelines but was the screenshot of the site, if not the first tweet, not an obvious scam? And you can say it's from context but I only read the title before my eyes jumped to the screenshot

Re: Web Security is Too Hard

#5
post #4

I guess it's easy to judge from the sidelines but was the screenshot of the site, if not the first tweet, not an obvious scam? And you can say it's from context but I only read the title before my eyes jumped to the screenshot

I just read the rest of the article and I'm back with my tail between my legs. I guess I made the author's point.

Re: Web Security is Too Hard

#6
At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no.

> There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt.

What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?

Re: Web Security is Too Hard

#7
post #3

Another entry in "Marketing department starts a promotion campaign for the new product that's indistinguishable from a phishing attack" list. Starting with not using a subdomain on your own, very well-known domain but instead using a completely different one, then not having it shown with the rest of your services on your main web site, et cetera.

this is the correct take

Re: Web Security is Too Hard

#8
post #3

Another entry in "Marketing department starts a promotion campaign for the new product that's indistinguishable from a phishing attack" list. Starting with not using a subdomain on your own, very well-known domain but instead using a completely different one, then not having it shown with the rest of your services on your main web site, et cetera.

You really would think that at least in theory a company like Cloudflare would make it very easy for internal teams to automatically request new subdomains

Re: Web Security is Too Hard

#10
post #5
post #4

I guess it's easy to judge from the sidelines but was the screenshot of the site, if not the first tweet, not an obvious scam? And you can say it's from context but I only read the title before my eyes jumped to the screenshot

I just read the rest of the article and I'm back with my tail between my legs. I guess I made the author's point.

Don't worry, I think everyone probably went on the same roller coaster with this one
Post reply on HN