logoalt Hacker News

sleepyguytoday at 2:16 PM1 replyview on HN

If an email was authenticated with DKIM, you cannot really blame Revolut. The attacker would have had to compromise the government email server, making it the government's fault.

However, if the email relied solely on SPF, the situation is less clear. An attacker could potentially spoof SPF by compromising any service on a server sharing the same public IP address via NAT.


Replies

f33d5173today at 2:18 PM

Why did you copy paste a comment from 4chan? Is this a pasta I'm not aware of?