I’ve wanted to do this too, but I’m worried a website will have different domain names that I didn’t know about. Say I subscribe to lemmy.com. Then I find out a month later that lemmy.com sends me important alerts from from lemmyalerts.com. If I had only whitelisted lemmy.com, I would have missed those alerts.
Has this ever happened to you? Do you have a strategy for these?
If someone emails from different domains like that, then they’ve missed one of the biggest security lessons in how to use the internet: only trust domains that you trust/can-verify. If you get an email from YourBank.kp or YourBankOfficialReallyIPromiseBro.com then don’t trust it.
The burden of proof lies with the sender to convince you they are who they say they are, by providing verifiable info and not using a domain you have to go whois.
I think PayPal sends emails from PayPalMail.com or something like that, so when a friend asked me if it was real, I said probably not, but when I investigated it further I found the morons from PayPal did actually (sometimes?) email from another domain. It makes sense however that a company like PayPal, so closely connected to psychotic conman Musk, would do something that idiotic.
Must be nice living in Canada. When I was there I heard you guys bitching about your administrations a lot, but at least the administrative stuff was pretty straightforward (I almost experience culture shock when I went to do some administrative stuff to regularize my social security situation, and student visa a few years letters, and got all the correct answers from talking to a single person, who didn’t even try to backhandedly redirect me to some other service.
Over here in France, we get official, sometimes of crucial importance, communications that look like textbook phishing (strange wording, embedding links to shady-ass looking domain names).
Hell, with the latest gov data breach (which is like, the 5th one this year or something?) they sent us mails with anti-phishing good practices telling stuff like “never click on a link from a mail, go to the official website by yourself and find the thing from there” then follow up with a link…
Sometimes they’ll use extremely shady links too (sorry, my dear Republic, but I ain’t clicking a link to something that doesn’t end in .gouv.fr from you)
Cherry on top : they recently passed a law exposing private companies to huge fines for not respecting stuff like breaches disclosures etc, then they (the government and/or related institutions) admitted to no wrongdoings after getting caught burying the evidence and not respecting basic security best practices. The only one that got some traction is the latest one because the hacker allegedly managed to extract all the financial data of the country’s top tax evaders
I’ve wanted to do this too, but I’m worried a website will have different domain names that I didn’t know about. Say I subscribe to lemmy.com. Then I find out a month later that lemmy.com sends me important alerts from from lemmyalerts.com. If I had only whitelisted lemmy.com, I would have missed those alerts.
Has this ever happened to you? Do you have a strategy for these?
If someone emails from different domains like that, then they’ve missed one of the biggest security lessons in how to use the internet: only trust domains that you trust/can-verify. If you get an email from YourBank.kp or YourBankOfficialReallyIPromiseBro.com then don’t trust it.
The burden of proof lies with the sender to convince you they are who they say they are, by providing verifiable info and not using a domain you have to go whois.
I think PayPal sends emails from PayPalMail.com or something like that, so when a friend asked me if it was real, I said probably not, but when I investigated it further I found the morons from PayPal did actually (sometimes?) email from another domain. It makes sense however that a company like PayPal, so closely connected to psychotic conman Musk, would do something that idiotic.
Must be nice living in Canada. When I was there I heard you guys bitching about your administrations a lot, but at least the administrative stuff was pretty straightforward (I almost experience culture shock when I went to do some administrative stuff to regularize my social security situation, and student visa a few years letters, and got all the correct answers from talking to a single person, who didn’t even try to backhandedly redirect me to some other service.
Over here in France, we get official, sometimes of crucial importance, communications that look like textbook phishing (strange wording, embedding links to shady-ass looking domain names).
Hell, with the latest gov data breach (which is like, the 5th one this year or something?) they sent us mails with anti-phishing good practices telling stuff like “never click on a link from a mail, go to the official website by yourself and find the thing from there” then follow up with a link…
Sometimes they’ll use extremely shady links too (sorry, my dear Republic, but I ain’t clicking a link to something that doesn’t end in .gouv.fr from you)
Cherry on top : they recently passed a law exposing private companies to huge fines for not respecting stuff like breaches disclosures etc, then they (the government and/or related institutions) admitted to no wrongdoings after getting caught burying the evidence and not respecting basic security best practices. The only one that got some traction is the latest one because the hacker allegedly managed to extract all the financial data of the country’s top tax evaders