Identity is hard y'all.
Web Security is Too Hard
11–20 of 127 posts
Re: Web Security is Too Hard
#12At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no. > There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt. What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?
Re: Web Security is Too Hard
#13Re: Web Security is Too Hard
#14At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no. > There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt. What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?
What’s the point? To save money paying a human to man a support email. That human would have also been hopelessly uninformed for all the same reasons.
Re: Web Security is Too Hard
#15Re: Web Security is Too Hard
#16Another entry in "Marketing department starts a promotion campaign for the new product that's indistinguishable from a phishing attack" list. Starting with not using a subdomain on your own, very well-known domain but instead using a completely different one, then not having it shown with the rest of your services on your main web site, et cetera.
Re: Web Security is Too Hard
#17Re: Web Security is Too Hard
#18My main takeaway from this is not that "security is hard" but that cloudflare is pretty incompetent.
GitHub for ages had something like githubnext.com where they would make you do this same OAuth dance (except IIRC it was worse - it explicitly said that it WASNT GitHub). Apple has/had an apple.tv microsite or something they hosted content on.
Your bank will send you “legitimate” surveys or communication from some third party domain like qualtropics.com.
Re: Web Security is Too Hard
#19Another entry in "Marketing department starts a promotion campaign for the new product that's indistinguishable from a phishing attack" list. Starting with not using a subdomain on your own, very well-known domain but instead using a completely different one, then not having it shown with the rest of your services on your main web site, et cetera.
Same Story as it ever was. The first time I encountered what I thought was a phishing attack at the bank I worked at 25 years ago , it turned out to be a marketing campaign, with URLs that put our company name as a user before the domain name (back in the day when creds could go in the URL).