| ▲ | hrpnk 4 hours ago | |
Even if the trigger was spoofed, how come there is no secure channel that the govt provides to receive the data? Was this one also compromised? | ||
| ▲ | edelbitter an hour ago | parent | next [-] | |
That may not matter that much, as even if you run a relatively strict policy about where you send the reply, you can still easily get bitten by external mistakes there: Because of the huge number of individually administered departments that might each become authorized recipient of such data, a malicious party only needs to find one suitably dangling DNS delegation to score a "…@attacker-controlled-subdomain.legitimate.example" mailbox. The sender would not be able to prevent this.. unless its regulatory oversight body is very patient about repeatedly delaying legitimate requests for seemingly-minuscule formal defects. (Mentioning just for context. Probably not the mechanism at play here, Revolut would have tried to shift blame in the press release if it was.) | ||
| ▲ | ang_cire 2 hours ago | parent | prev [-] | |
If people actually knew how much of a wild west this stuff is, a lot more would be cautious with their personal info. | ||