3 ms·
Yeah I gotta agree with you. How is this any different from the other 10s of thousands of variations of phishing attempts? If it's not signed and it's not from
by johnghanks 7y ago
Yeah I gotta agree with you. How is this any different from the other 10s of thousands of variations of phishing attempts?
If it's not signed and it's not from github.com or a registered subdomain, or if the URL of the action isn't _explicitly_ github.com... it's not legit. It doesn't matter if it slipped through GMail's filter or not...
- meowface 7y agoI don't mean to shame people for falling for phishing. I fell for a convincing Steam phish once when I was a young teenager after a friend's account was compromised and messaged me with a link to a perfect clone of the login page and a similar domain. But as far as phishes go, this one just seems not too convincing.
- justinhj 7y agoIn the case of the github phishing it does have a valid certificate and the host name is something that looks legit enough it will probably fool a lot of people