5 ms·
what a convenient post, I am getting some similar scam/spam straight from youtube https://imgur.com/1wD3bSP https://imgur.com/1wD3bSP. why youtube allow people
by criloz2 9y ago
what a convenient post, I am getting some similar scam/spam straight from youtube https://imgur.com/1wD3bSP https://imgur.com/1wD3bSP. why youtube allow people send external links using their email address and logo.
- cmurf 9y agoApple allows the same thing: email appears to come from apple.com, has Apple and iTunes logos, and arrives in an icloud.com account. Why? It happens to my dad all too often and he's even clicked on the linked. He only became suspicious when it asked for his social security number. This is not about being gullible. This is about phishing emails being just convincing enough, and the email and web browser eco system not taking the problem seriously enough. Apple certainly has the engineering expertise to prevent this particular instance on their end, but no one's ready to throw in the towel and embargo any email containing a user facing URL that differs from the underlying HTML link for that URL.
- kuschku 9y agoAnd remember, Phishing can be entirely prevented. Just verify SPF, DKIM and DMARC headers and DNS records.
- SCHiM 9y agoThis will not save you unfortunately. Sure, it will prevent the attacker from using realname.tld. But it won't stop an attacker from using real-name.tld, or realname.othertld. Or real.name.tld. Non technical people won't see, or don't know, the difference between the urls. I've seen it hundreds of times, you tell people don't open the e-mail unless you're sure it's from name.tld. But people don't know the difference.
- kuschku 9y agoThat's correct — but this way, you can ensure that if the email is from the real TLD, it is real. And that's a massive advantage over previous systems. Sure, only cautious people, or tech people will take advantage, but it's better than nothing.
- cmurf 9y agoActually I think it's worse, because it's just a variation on classism, but applied to the internet. Some people are being left behind to fend for themselves, the technology is in fact not egalitarian, it does not treat everyone equally (or neutrally if you will). And that is simply turning the internet into more of the "finders keepers losers weepers" we already have.
- kuschku 9y agoClassicism is something entirely different. This is "people who have more knowledge will know more". Just like someone who learnt math in high and middle school will be able to budget better, and even improve their tax returns. This isn't classicism.
- toast0 9y agoThe screenshoted email in this thread may actually be really from YouTube. I'm not familiar with YouTube community features though, but it looks like a spammy channel invited the receiver to do something through the YouTube UI. If Google had a good way to prevent that, they probably wouldn't have spammy channels. That said, even with dmarc and all, most email programs these days don't even show the domain name if there's a friendly name in the From field. Anyway, some people don't seem to notice that webmaster@johns-plumbing-blog.biz is sending them YouTube/eBay/whatever phishing links (even if the site in question never sends email like that), they just click through.
- cmurf 9y agoSo if Apple applies those things to authentic emails from the iTunes store (receipts are the context in my dad's case), then how in the living goddamn fuck are Apple permitting obvious forgeries through to an icloud.com account? I find it really hard to believe they're either malicious or incompetent, so what's the alternative explanation?