4 ms·
Compare this site to the base domain. https://www.irs.gov/ https://www.irs.gov/ Do you think it looks official? Or does it look like someone spent $10 on a 3r
by tekla 5mo ago
Compare this site to the base domain.
https://www.irs.gov/ https://www.irs.gov/
Do you think it looks official? Or does it look like someone spent $10 on a 3rd world rando to make a site on Wordpress and a spoofed URL and didn't even bother to make it part of the official site.
- deleted 5mo ago[deleted]
- DANmode 5mo ago> Do you think it looks official? I check the address bar for that.
- tekla 5mo agoYou mean the thing that has been the source of many cybersecurity issues for years because fonts w/ ambiguous characters and varying levels of "how closely are you actually reading the URL"? The very thing where sites like gmai1.com that look exactly like the real site phish creds? Or things that even Google has issues with subdomains? https://hoxhunt.com/blog/advanced-phishing-attack-using-google-subdomain-could-trick-anyone https://hoxhunt.com/blog/advanced-phishing-attack-using-goog... The IRS site does use lots of subdomains like https://sa.www4.irs.gov https://sa.www4.irs.gov, but even it looks like its using the same design language as the normal site.
- DANmode 5mo ago> You mean the thing that has been the source of many cybersecurity issues for years because fonts w/ ambiguous characters and varying levels of "how closely are you actually reading the URL"? The very thing where sites like gmai1.com that look exactly like the real site phish creds? Yes, that’s the one. If I’m really paranoid, I’ll: 1.) avoid providing data to that page 2.) cross-reference host IP 3.) find the page on the original URL via search index