Remix.run Logo
ddtaylor 3 hours ago

I'm not convinced that would help.

The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain.

Its just attempting to work around incompetence, which always just shows up again somewhere else.

walrus01 2 hours ago | parent | next [-]

> The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain.

I think this might have some parallels with the 'shadow IT' problem in large corporations and organizations. Some work group or department or project within a very large entity decides it needs to implement something (like shipment tax payment notifications, as in the linked example) and decides to DIY it rather than going through the full process to do it with their own domain.

Reminds me a bit of large businesses where some sales or CRM-related department goes out and starts buying email-blasting/email-list features from some mailchimp-type company and only later on realizes they need to talk to whoever controls the domain to get approval for proper outbound DKIM in the DNS records, etc.

SoftTalker 2 hours ago | parent [-]

Or more likely IMO, FedEx HQ said "you can't use our domain to collect foreign tax payments" and so it got outsourced to a service in Australia. And a lot of these "collect payments as a service" sites just look and feel like something that was developed in 1995 and never updated. I run into them everywhere, from local governments to medical and legal offices, small utility companies, etc. I have no idea how they pass PCI audits.

reaperducer 2 hours ago | parent | prev [-]

The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain.

Just today I saw an e-mail from "onmicrosoft.com" that was completely legit.

I wonder how many domains MS is running these days. It seems like each department and project gets its own.

walrus01 2 hours ago | parent | next [-]

At least they're not sending from contoso.com ?

Yokolos an hour ago | parent | prev [-]

Every time I see a new Microsoft domain I've never seen before, I have to double check that it's actually legit. Every time I realize anew why people still fall for phishing attempts, because all these legit domains look like phishing attempts.