1 hour ago · Tech · hide · 0 comments

It started innocently enough. I saw a tweet about a new product offering from one of my favorite companies, Cloudflare. Neat! I clicked through to the site and there it is: And huzzah!, my preferred handle, @ericlaw is still available. I’d better hurry to claim it before someone else gets it! Since I’m already a long-time Cloudflare user, I just need to sign in. That makes sense, how else will they bind the handle to my account? Easy peasy. I’m in. Looks like there’s just one more step, I gotta authorize the new feature: But wait a sec! This looks exactly like one of those Consent Phishing attacks that have been so popular over the last few years. And wait, why is the entry point on cloudflare.pay, a site that doesn’t have my credentials, rather than something within the cloudflare.com domain which does? There is no inherent technical relationship between a .com domain and a .pay domain. The .pay TLD is available for anybody with $20 to their name (unlike, e.g. .bank which requires…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.