5 ms·
To verify that this is a legit site: Go to: https://usa.visa.com/legal/global-privacy-notice/additional-privacy-information.html https://usa.visa.com/legal/glo
by eyeareque 6y ago
To verify that this is a legit site:
Go to: https://usa.visa.com/legal/global-privacy-notice/additional-privacy-information.html https://usa.visa.com/legal/global-privacy-notice/additional-...
Then click on: “Visa Products & Services: How does Visa use personal information to benefit consumers and businesses?”
Then scroll to the bottom of that section and you’ll see the VAS link: ”U.S. cardholders can opt out of Visa using their card transaction data for VAS.” where you can opt out.
iPhones will auto capitalize text in the capatcha box, so make sure the text is all lowercase.
- iamtedd 6y agoThe site is already marketingreportoptout.visa.com. How would your random link add anything?
- wpietri 6y agoThe "random link" is on a domain that the Wayback machine has back to 2001. Whereas the marketingreportoptout subdomain doesn't appear to be there at all. I could certainly imagine a compromise where somebody who doesn't have access to the main sites still manages to sneak in a plausible-sounding subdomain.
- ianlevesque 6y agoThat's not how any of this works.
- wpietri 6y agoOh? https://www.hackerone.com/blog/Guide-Subdomain-Takeovers https://www.hackerone.com/blog/Guide-Subdomain-Takeovers
- foepys 6y agoPlus the site uses a certificate that is not only issued by but also owned by Cloudflare according to its metadata. It's undistinguishable from a free tier Cloudflare cert unless you know what exactly you need to look for.
- durpkingOP 6y agoThis is not realistic or even probable.
- stevehawk 6y agohttps://www.securitynewspaper.com/2018/05/04/make-subdomain-takeover-attack/ https://www.securitynewspaper.com/2018/05/04/make-subdomain-...
- miked85 6y agoDoes that mean that you don't trust subdomains by default? That seems a bit extreme/unnecessary.
- wpietri 6y agoI don't know that I trust anything by default. It's always a risk assessment. When I saw a kinda basic-looking site asking for my credit card number, I definitely looked at the domain, and alongcomplicatedthingineverheardof.visa.com was definitely more concerning than, say, www.visa.com.
- twosdai 6y agoCan't even trust myself these days, its really awful. /s
- durpkingOP 6y agoYou are suggesting people do something that is completely unnecessary. It's a subdomain of visa.com. If your concern was valid, you could put your comment disclaimer on every single link ever posted on hackernews.
- eyeareque 6y agoIt can be hard to clearly identity website urls on a mobile browser, but also as others pointed out here there is a common attack called sub domain takeover. I don’t personally like typing my credit cards into websites without making sure it is legit.
- bombcar 6y agoIt astounds me how many of these official sites look like bad phishing attempts.
- globular-toast 6y agoThat's on purpose. They don't want people opting out.