logoalt Hacker News

varun_chyesterday at 9:49 PM1 replyview on HN

https://news.ycombinator.com/item?id=47614038


Replies

TZubiriyesterday at 10:55 PM

in github's defense. This is a bit more nuanced, less objectively wrong domain posture issue. It will only matter if one security mechanism (subdomain control) fails.

The quoted microsoft examples are way worse. I see this with outbound email systems a lot, which is especially dangerous because email is a major surface of attack.