Hacker News new | ask | show | jobs
by felixhuttmann 1230 days ago
They could force the invoice sender to verify an email address, and then include this email address in the invoice email. This way, nobody can pose as "coinbase" -- maybe as invoice@coinbase.fakedomain.com, but not as invoice@coinbase.com.