Hacker News new | ask | show | jobs
by jsiepkes 2178 days ago
When I received a DMCA takedown request it didn't come from a "github.com" mail address but from "support@githubsupport.com". At first I thought I was being phissed but after some digging I found out it was actually an address they use.

By doing this your basically training your users to just accept mail from any address that vaguely resembles GitHub. So I can't say I'm really surprised about this. They don't seem to have given a lot of thought about issues like these.

1 comments

Always fun when my company sends out phishing tests and I have to figure out if it's real, then turns out we have a ton of legit domains mail can come from.