Remix.run Logo
reaperducer 2 hours ago

The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain.

Just today I saw an e-mail from "onmicrosoft.com" that was completely legit.

I wonder how many domains MS is running these days. It seems like each department and project gets its own.

walrus01 2 hours ago | parent | next [-]

At least they're not sending from contoso.com ?

Yokolos 2 hours ago | parent | prev [-]

Every time I see a new Microsoft domain I've never seen before, I have to double check that it's actually legit. Every time I realize anew why people still fall for phishing attempts, because all these legit domains look like phishing attempts.