▲ | anonymars 9 days ago | |||||||
The email is coming from the legitimate service, it's a man-in-the-middle attack. How does this scheme stop you from putting a legitimate code from a legitimate sender into an illegitimate website? | ||||||||
▲ | esjeon 6 days ago | parent [-] | |||||||
Ah, sorry, I did get that part, and my idea goes a little bit further, but somehow I thought I wrote enough. One thing is that this problem occurs because we have two independent channels that we must independently verify. I’m pretty sure this is a whack-a-mole game, and will never be possible to fix. Another thing is that, since we don’t trust emails, we hesitate sending links over email. However, the problem here is easy to avoid if services send login links directly to user, and those emails are automatically authenticated by the system. | ||||||||
|