logoalt Hacker News

throwaway290today at 10:32 AM3 repliesview on HN

That's just for support. Legit password resets for example come from more random top level domains with "microsoft" in it, like microsoftonline.com

Another fun one is facebook, they use facebookmail.com or whatever else for serious security stuff


Replies

CraigRoodtoday at 10:50 AM

Is this because at one point <username>@facebook.com was a valid communication method? Great concept to be fair, but once you pull back the first layer you can immediately see its problems.

Metacelsustoday at 11:15 AM

>Legit password resets for example come from more random top level domains with "microsoft" in it, like microsoftonline.com

Or aka.ms

e40today at 10:47 AM

The number of redirects while using ms properties is just insane. It makes white listing them in uBO impossible because they redirect so fast, through multiple domains. The White listing is needed to sometimes make them work.

show 1 reply